unix and linux commands - unix shell scripting

Botnets? Not a problem...

 
Thread Tools Search this Thread
# 1  
Old 11-16-2009
Botnets? Not a problem...

An article in PC Pro by Asavin Wattanajantra quotes Dr Steve Marsh, who is deputy director at the Office of Cyber Security in the Cabinet Office, as saying (in respect of EU policy on protecting Europe from cyber attack, whatever you may understand by that term) that:
 "the main focus of botnets would be to target and extort money from private companies, rather than bring down public sector networks [and] .... in a sense [it is] not in their interest to bring down infrastructure which is earning them money."

This isn't a million miles away from something I was saying early in 2009, when there was a great deal of speculation in the media about what would happen when and if the Conficker worm went active on April 1st. Much of that speculation centred around the possibility that the Conficker botnet would launch a major attack on the Internet infrastructure. The point I made several times in blogs at ESETand elsewhere at that time was that it wouldn't make sense for the botmasters to switch straight into such an attack, since it would make it harder in the longer term to make use of the kind of concerted attack that botnets do so well (click fraud, DDoS and so on).

 

Nevertheless, Dr. Marsh's statement, if quoted correctly, is, at least in the context of that article, somewhat misleading. (As Gadi Evron pointed out at some length in a typically insightful article at Dark Reading.) Assaults on the infrastructure of the Internet are one thing. (They're by no means out of the question, by the way: my point about Conficker was that most known criminal botnets are about commercial gain, and it wouldn't be in the interests of the botmaster to compromise the effectiveness of his network. However, the same is by no means necessarily true of other groups.)

 

Attacks on government infrastructures are another matter. I certainly don't wish to raise the spectre of (sigh...) cyberwarfare and all that FUD (Fear, Uncertainty, Doubt) unnecessarily, but I can think of many hypothetical scenarios where a concerted attack on a national infrastructure might be made by another government or a terrorist organization, with dramatic consequences. (In the UK, it's common to see refer ences to the Critical National Infrastructure, which I believe includes not only the Corridors of Power, but more peripheral areas such as parts of the National Health Service, and sectors like banking which many people wouldn't necessarily think of in a governmental context). The "Government Secure Internet" (GSI) is indeed a pretty effective layer of protection, but it does not, I think,  cover all the sectors that might sustain serious impact from such an attack, and might in turn seriously damage the wellbeing of the nation as a whole.

 

I spend most of my working life saying "Don't panic!" in one context or another, and right now, we aren't seeing huge botnets used for (sigh...) cyberwarfare. Nevertheless, I don't believe that the UK government or the European Community (or anyone else) should be complacent about potential risks to national security from botnet-like activity, just because most of the bots we know of right now have a commercial agenda. Anyone with the resources and incentive can build, buy or rent a botnet (should I mention the BBC?), and it's not a good idea to make too many presumptions about what motivation might drive the individual or organization behind future botnet attacks.

 

David Harley FBCS CITP CISSP
Director of Malware Intelligence, ESET


Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. What is on Your Mind?

Spotting Aggressive Clandestine BotNets

Spotting Aggressive Clandestine BotNets "Yesterday was making a typical “evening run” in cyberspace and noticed a strange pattern, zoomed in, and found a aggressive clandestine “indexing” botnet operating out of a dedicated hosting provider’s datacenter. The feature image in this post shows a... (0 Replies)
Discussion started by: Neo
0 Replies

2. UNIX for Dummies Questions & Answers

sed Or Grep Problem OR Terminal Problem?

I don't know if you guys get this problem sometimes at Terminal but I had been having this problem since yesterday :( Maybe I overdid the Terminal. Even the codes that used to work doesn't work anymore. Here is what 's happening: * I wanted to remove lines containing digits so I used this... (25 Replies)
Discussion started by: Nexeu
25 Replies

3. IP Networking

Problem with forwarding emails (SPF problem)

Hi, This is rather a question from a "user" than from a sys admin, but I think this forum is apropriate for the question. I have an adress with automatic email forwarding and for some senders (two hietherto), emails are bouncing. This has really created a lot of problems those two time so I... (0 Replies)
Discussion started by: carwe
0 Replies

4. AIX

AIX OS problem? network problem?

Dear ALL. I installed AIX OS on customer sites. but Only one site is too slow when I connected telnet, ftp.. Ping is too fast. but telnet and FTP is not connected.. of course i check the configuration file on aix but it's normal. Do any Idea?? thanks in advance. - Jun - (3 Replies)
Discussion started by: Jeon Jun Seok
3 Replies

5. UNIX for Dummies Questions & Answers

DHCP problem and eth1 problem

At work I am trying to get this one Linux machine (let's call it ctesgm07) to behave like another Linux machine that we have (let's call it test007). test007 returns the following version info: cat /etc/debian_version: lenny/sid uname -a: Linux test007 2.6.27-7-generic #1 SMP Tue Nov 4... (0 Replies)
Discussion started by: sllinux
0 Replies

6. Red Hat

Mail Problem. Maybe, it is a DNS Problem!

Hi, i've a redhat linux 9 upadated by redhat from 7 version to 9 version. A couple of days ago i was a problem with my mail, in other words i'm not able to get any email nor to send any email. I've a proxy configuration and i tried to set iptables in order to verify the port. The 110,255 and 995... (1 Reply)
Discussion started by: pintalgi
1 Replies

7. AIX

user login problem & Files listing problem.

1) when user login to the server the session got colosed. How will resolve? 2) While firing the command ls -l we are not able to see the any files in the director. but over all view the file system using the command df -g it is showing 91% used. what will be the problem? Thanks in advance. (1 Reply)
Discussion started by: pernasivam
1 Replies

8. Shell Programming and Scripting

ssh script problem problem

Hi Please help me with the following problem with my script. The following block of code is not repeating in the while loop and exiting after searching for first message. input_file ========== host001-01 host001-02 2008-07-23 13:02:04,651 ConnectionFactory - Setting session state... (2 Replies)
Discussion started by: pcjandyala
2 Replies

9. Shell Programming and Scripting

problem with dd command or maybe AFS problem

Hi, folks. Sorry for bothering, but maybe someone could help me please. The problem is the following: there is some script that copies files from local file system to AFS. The copying is performed with dd command. The script copies data into some AFS volumes. The problem appeared with one... (0 Replies)
Discussion started by: Anta
0 Replies

10. UNIX for Advanced & Expert Users

SSH Problem auth problem

Hi, Just recently we seem to be getting the following error message relating to SSH when we run the UNIX script in background mode: warning: You have no controlling tty. Cannot read confirmation.^M warning: Authentication failed.^M Disconnected; key exchange or algorithm negotiation... (1 Reply)
Discussion started by: budrito
1 Replies
Login or Register to Ask a Question