November 16, 2005 11:53 AM PST

Bots slim down to get tough

Malicious makers of bots are finding big is not always better when it comes to avoiding detection, according to a security expert.

Over the past two years, the average network of bots, or compromised PCs commandeered by remote attackers, has dropped from more than 100,000 to an average of 20,000, Mark Sunner, MessageLabs's chief technology officer, said during Tuesday's annual Security Roundtable Webcast.

A botnet is comprised of thousands of computers that have been surreptitiously transformed into zombie PCs without their owners' knowledge. The move to pint-size botnets helps malicious attackers have more success in delaying detection of their illicit zombie networks, Sunner said.

"When a larger botnet is spreading a virus, it lights up the switchboard of (antivirus) vendors, and they'll respond in a few hours with a signature to contain the outbreak," Sunner said.

"With a smaller botnet, it may take a day or so before it's discovered and a signature is written," he said.

Maksym Schipka, a senior antivirus researcher at MessageLabs, noted that two other issues have also contributed to the shrinking size of botnets.

First, an increase in the numbers of hackers hoping to put together networks has made the task of securing zombie computers more competitive, so it is harder for the "bot herder" to amass a larger number of drone computers.

Second, home users with high-bandwith connections, the primary targets of hackers, are taking more steps to secure their computers.

Often, hijacked bots have been infected with software that will connect to an Internet Relay Chat and await instructions from the malicious attacker. Botnets are used to send out e-mail messages for spam and phishing attacks. They can also be used to send out a flood of data to bring down a system in a denial-of-service attack.

When a malicious writer launches a phishing scam, antivirus companies will write so-called signatures that identify the attack for their protective products. These signatures are like taking fingerprints of malicious software. Each time the attack touches the doorknob to enter a system, the door locks.

The more quickly antivirus vendors distribute a signature for a virus and customers deploy it, the less effective that particular botnet can be, Sunner said.

"As botnets get used up, they are blacklisted and less useful for spamming or phishing attacks," Sunner said. "But they get mopped up and are used for DOS attacks."

As DOS attacks don't directly use e-mail or viruses, they won't be caught by blacklists or signature-based antivirus products. Last year, Sunner said his company began noticing old, wornout spambots were being resold as potential DOS bots on various sites and forums used by malicious attackers.

"People would advertise bots with 'fresh' machines, or ones that were mopped up," Sunner said.

See more CNET content tagged:
bot, signature, antivirus, denial of service, MessageLabs Ltd.

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    CFO Brian Gladden has said the company has "more work to be done" to improve profitability. Now The Wall Street Journal reports that Dell is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Negative Approach

    Online content and services via game consoles will generate $8 billion in revenue in 2013

    The revenue possibilities in gaming continue to grow, at least for the big console manufacturers.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • News - Politics and Law

    McCain talks up oil drilling, green energy

    Republican presidential candidate says we need to drill new wells now, while supporting innovative transportation technologies and "the use of wind, tide, solar and natural gas."