Behind the Scenes of Recent Botnet Takedown Operations

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

David Watson has been a member of the Shadowserver Foundation since 2008, is one of their Directors, and leads their Special Projects Team in support of international Law Enforcement operations. David regularly presents and teaches hands on training classes at information security events, and is passionate about helping network owners and cybercrime victims to defend themselves using tools and information sources that do not necessarily come with strings attached, or huge price tags. David was the Chief Research Officer and a Director of the Honeynet Project from 2006-2016, helping to co-ordinate and promote the development and deployment of honeynet related security tools worldwide.Taking down botnets is a challenging and complex process, requiring not just long-term technical analysis of the threat faced but also cross-border and cross-jurisdiction cooperation and coordination, involving many different (types of) players and legal systems. A successful operation culminates in a quick shutdown of cybercriminal operations, sinkholing of botnet command and control infrastructure and lots of media attention. But what happens behind the scenes to make all of that possible? The talk will describe The Shadowserver Foundation's first-hand experiences in assisting recent law enforcement botnet takedown operations, for example Avalanche (2016/2017), Mirai (Botnet#14) and Kelihos - as well as newer operations relevant by the time of the conference. The talk will identify the main organizational, legal and technical challenges facing the takedown teams, which approaches worked and which did not, and what could be improved in the future. How is the infected victim remediation data shared with the security community? What roles should CSIRTs play in such operations?