August 7, 2008 9:44 AM PDT

Looking inside the Storm worm botnet

LAS VEGAS--On Wednesday, Joe Stewart, director of malware research for SecureWorks, presented his work on protocols and encryption used by the Storm worm botnet at Black Hat 2008.

He said as far as botnets go, Storm is not particularly sophisticated, nor is it our No. 1 threat. Yet while other botnets come and go, Storm remains amazingly resilient, in part because the Trojan horse it uses to infect systems changes its packing code every 10 minutes, and, once installed, the bot uses fast flux to change the IP addresses for its command and control servers.

None of this surprising, it's just handled well.

In explaining Storm worm's resiliency compared to newer and sleeker botnets, Stewart looked at the encryption used within the commands sent from the command and control server. He said the compression or packing code changes so often in order to thwart antivirus signature files.

Storm uses P2P to communicate with its various nodes and supernodes throughout the Internet. He said because of that, it has to contend with bogus media files being sent via P2P and researchers such as himself attempting man-in-the-middle attacks to see what the commands might be. To handle that, Storm has started using 64-bit RSA encryption based, in part, on the date.

Joe Stewart talks about what botnet code is available and what can be found within it.

Click here for full coverage of Black Hat 2008.

Recent posts from News - Security
Security expert: DNS attacks are happening
Malicious Flash ads attack, spread via clipboard
Hacker exposes alleged Olympics age fraud
Ireland investigating fake credit card reader scam
Android security team appeals to bug hunters
Add a Comment (Log in or register) 2 comments (Page 1 of 1)
by jamalystic August 7, 2008 12:41 PM PDT
How botnets spread and create damage is no secret, but it is preventable. Not taking basic precautions is absurd. There are numerous reports stating how most computers are not satisfactorily protected and this is the underlying reason why such attacks persist: Ignore the Storm Worm Threat at Your Own Peril(http://www.internetevolution.com/author.asp?section_id=515&doc_id=145897&F_src=flftwo)
Reply to this comment
by benjaminstraight August 8, 2008 3:13 AM PDT
Interesting info on botnets.
Reply to this comment
Powered by Jive Software
  • About News - Security

  • Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Google's search secret: It gets rid of you

  2. Developer creates copy-paste tech for iPhone

  3. Palm Treo Pro: Not digging it

  4. Will Wright on the origins of 'Spore'

  5. Intel says it has 'first silicon' for next mobile chip

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

advertisement
On TechRepublic: Why IT pros hate Microsoft Access
Advanced
search
Advanced
search
Visit other CBS Interactive sites