August 7, 2008 9:44 AM PDT

Looking inside the Storm worm botnet

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

LAS VEGAS--On Wednesday, Joe Stewart, director of malware research for SecureWorks, presented his work on protocols and encryption used by the Storm worm botnet at Black Hat 2008.

He said as far as botnets go, Storm is not particularly sophisticated, nor is it our No. 1 threat. Yet while other botnets come and go, Storm remains amazingly resilient, in part because the Trojan horse it uses to infect systems changes its packing code every 10 minutes, and, once installed, the bot uses fast flux to change the IP addresses for its command and control servers.

None of this surprising, it's just handled well.

In explaining Storm worm's resiliency compared to newer and sleeker botnets, Stewart looked at the encryption used within the commands sent from the command and control server. He said the compression or packing code changes so often in order to thwart antivirus signature files.

Storm uses P2P to communicate with its various nodes and supernodes throughout the Internet. He said because of that, it has to contend with bogus media files being sent via P2P and researchers such as himself attempting man-in-the-middle attacks to see what the commands might be. To handle that, Storm has started using 64-bit RSA encryption based, in part, on the date.

Joe Stewart talks about what botnet code is available and what can be found within it.

Click here for full coverage of Black Hat 2008.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Security
So, is it safe to tweet now?
Twitter hijacked by 'Iranian Cyber Army'
Firefox, Adobe top buggiest-software list
Predator drones hacked in Iraq operations
Adobe to patch zero-day Reader, Acrobat hole
Firefox 3.5.6 patches critical security holes
Facebook sues men for allegedly phishing, spamming
Scammers exploit Google Doodle to spread malware
Add a Comment (Log in or register)
by jamalystic August 7, 2008 12:41 PM PDT
How botnets spread and create damage is no secret, but it is preventable. Not taking basic precautions is absurd. There are numerous reports stating how most computers are not satisfactorily protected and this is the underlying reason why such attacks persist: Ignore the Storm Worm Threat at Your Own Peril(http://www.internetevolution.com/author.asp?section_id=515&doc_id=145897&F_src=flftwo)
Reply to this comment
by benjaminstraight August 8, 2008 3:13 AM PDT
Interesting info on botnets.
Reply to this comment
advertisement

Behind the scenes: NORAD's Santa tracker

For decades, the defense group has let you follow the Christmas Eve travels of the jolly old elf. These days, technology is playing a bigger role than ever.

Intel redesigns Atom chip for Netbooks

The chipmaker officially announces the next generation of its popular Atom CPUs for Netbooks, the N450, weeks before the CES trade show.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right