The future of Botnets

No ratings

Presented at AUScert 2008 by

Botnets used to be relatively simple. Their control mechanism was based on Internet Relay Chat and there were a number of ways to dismantle the criminals ability to control this zombie army. There were some easy ways to make money and many people got into the botherding scene but quickly found that law enforcement and their fellow botherders made life difficult. Over the last 5 years, law enforcement around the world became more technailly adept at analyzing malware, monitoring botnets and identifying these criminals. Investigators partnered with industry experts and together it looked like we were going to start to re- claim the internet from the zombies. What actually happened was that we forced the botherders to evolve away from IRC to new forms of command and control. There was so much money to be made from spamming, phishing, ddos attacks and harvesting of passwords that they refused to stop - they just got much smarter. We now have a number of new types of botnet that have been designed to be much harder to track and dismantle. Some of them are so well designed that there is currently no known legal way to stop them. These botnets are continuing to grow and make money for teams of unidentified criminals and there is no prospect of an end to the misery these new botnets cause. This presentation will include an overview of basic botnets and highlight some of the new methods being employed by the new breed of botnets, in particular peer to peer and web based controllers with some case studies.