Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 08, 2008

What If You Could Take Down a Botnet?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints

Last week, Cody Pierce and Pedram Amini (members of TippingPoint's security research group) released a detailed analysis of the Kraken botnet. The purpose of the analysis was to see whether the bot network could be infiltrated.

In order to test that possibility, Pierce and Amini had to take a very close look at the inner workings of the botnet code. With a sample in hand, they disassembled the code and dove into its inner workings to find an inroad into the botnet. The idea wasn't to become a bot in the network but to become a command and control server for the actual bots.

Amini explained, "The key to overtaking the botnet is understanding how the overall client-server architecture works. Kraken infected systems attempt to 'phone home' to a master command and control server by systematically generating sub-domains from various dynamic DNS resolver services such as dyndns.com. By reverse engineering the list of names and successfully registering some of the sub-domains Kraken is looking for, we can emulate a server and begin to infiltrate the network zombie by zombie. Stated simply, Kraken infected systems world wide start to connect to a server we control."

After reverse-engineering the bot, which of course included its encryption algorithm, Pierce and Amini were successful with their infiltration. After one week of running their rogue command and control server, they discovered that about 25,000 systems were infected with the Kraken bot. That is to say, about 25,000 unique computers connected to their rogue command and control server.

Apparently there's some debate about how big the Kraken botnet really is. The estimates range from roughly 185,000 bots to as many as 650,000 bots. Pierce and Amini said that since they were able to communicate with 25,000 bots, they effectively had control over anywhere from 4 to 14 percent of the entire botnet.

Then came the question of what to do with such control: sit back and watch, or on the other hand, possibly take action to remove the bot software from infected systems. That's an interesting question with no easy answer, although cleaning up the infected systems is very tempting.

First, there are issues that center around legalities. For example, is it legal to remove malware from people's systems without their permission? I'd guess that it's not. Even so, would authorities or individuals seek to press charges if unauthorized removal took place?

Then there are issues that center around potential damage to an infected system. Pierce and Amini point out that Dave Endler, who also works at TippingPoint, is against removal for these relatively solid reasons: What if a computer is damaged or crashes in the process of removal? And what if such a computer were in some way partially responsible for someone's life, as might be the case if a computer were located in a hospital, clinic, or doctor's office?

Clearly the only safe way to handle this kind of dilemma is to gather the IP addresses of infected computers, find out which companies manage those IP addresses, and contact those companies to let them know about the infected systems. Hopefully those companies would take steps to clean up the botnets and help the end users of those addresses get some adequate protection installed on their systems.

Of course, because cleaning up the infected systems through the use of a command and control server is incredibly tempting, there are those who would take such action regardless of the risks involved.

If you're interested in the details of the analysis or in sharing your perspective on how you think such an issue should be handled, head over to TippingPoint's Digital Vaccine Labs blog at the URL below. There you'll find detailed technical explanations of the analysis (including disassembled code snippets), links to related information regarding Kraken, and plenty of comments from readers who've commented on how they think the moral issue should be handled.
dvlabs.tippingpoint.com/blog/2008/04/28/kraken-botnet-infiltration

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

How can I uninstall the Microsoft Java Virtual Machine (JVM) from Windows XP?

...


Security Whitepapers St. Bernard Managed Protection Services

How to Evaluate and Choose a Messaging Archiving Solution

An IT Investment That Pays Real Dividends: Building ROI with your Email System

Related Events Black Hat USA, August 2-7

ChicagoCon 2008s

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Order Windows IT Pro VIP and SAVE!!
Get it all with Windows IT Pro VIP A $500+ value foir only $279!

Monthly Online Pass - Only $5.95!
Get instant access to 9,000+ articles from Windows IT Pro Magazine!!

Buy One Get One!
Order Windows IT Pro & Get SQL Server Magazine FREE!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.




ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

EXCHANGE 2007 Mastery Series – May 29, 2008
3 Info-packed eLearning seminars for only $99! Learn the pros and cons of your mailbox high availability options, see real-world examples of Transport Rules, and get started with basic PowerShell commands with Mark Arnold, MCSE+M and Microsoft MVP.

Windows IT Pro Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the Windows IT Pro Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

SQL Server Magazine Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the SQL Server Magazine Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes. And add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Become a fan of Windows IT Pro on Facebook
Join the Windows IT Pro fan club on Facebook. Chat with other IT Pros, upload your pictures, check out what's up n' coming in the next issue and more!

Tech·Ed 2008 Developer and IT Conferences
Don't miss out on the biggest event of the year. Be a part of the Microsoft Tech·Ed North America 2008 experience, starting June 3, 2008



Become a Response Point Specialist
Earn more with the small biz phone solution from Microsoft.

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford.

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!
Windows IT Pro Home Register About Us Affiliates / Licensing Press Room Media Kit Contact Us/Customer Service  
SQL Connected Home IT Library SuperSite FAQ Wininfo News
Europe Edition Office & SharePoint Pro Windows Dev Pro Windows Excavator 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing