Saturday, July 30, 2005

Malicious Bot attacks and Botnets

After virus, worms and trojans, the other malwares affecting most of the people and networks are Bots. Bots when they form a network among themselves by spreading on a range or network or comps are known as Botnets.

They are responsible for:
1) Heavy DDos attacks
2) Mass spamming mails
3) Installing key logging software for getting secret user information
4) Infecting computers to viruses and other malware.

How they spread
1) As email attachments
2) via IRC file transfer mechanisms
3) Attacking vunerable web servers and changing the scripts to execute "bot" scripts on client machines
4) using P2P connections and file sharing mechanisms
5) don’t replicate or spread on their own, but they can use the worms’ functionality to do so.

Statistics:
1) We see as many as 60,000 come on in a day,” said Alfred Huger, Symantec Security Response’s senior director of engineering.
2) “Security investigators have even found one botnet of 100,000 computers,” Ullrich chief technology officer for the Internet Storm Center, which detects, analyzes, and disseminates information about Internet-related security problems notified.
3) “In 2003, there were only 750 [malicious] bots reported. In 2004, there have already been over 2,300. There is a potential for a 400 percent increase in 2004 and 2005 over what we have seen. If that’s the case, we could see up to 12,000 variants of bots appear in 2005,” said iDefense's Dunham.

A detailed report about the future and their current existence has been published in IEEE magzine.

0 Comments:

Post a Comment

<< Home