Skip the navigation
)
News

Microsoft: No botnet is indestructible

'Nothing is impossible,' says Microsoft attorney, countering claims that the TDL-4 botnet is untouchable

July 6, 2011 12:37 PM ET

Computerworld - No botnet is invulnerable, a Microsoft lawyer involved with the Rustock takedown said, countering claims that another botnet was "practically indestructible."

"If someone says that a botnet is indestructible, they are not being very creative legally or technically," Richard Boscovich, a senior attorney with Microsoft's Digital Crime Unit said Tuesday. "Nothing is impossible. That's a pretty high standard."

Instrumental in the effort that led to the seizure of Rustock's command-and-control servers in March, Boscovich said Microsoft's experience in takedowns of Waledac in early 2010 and of Coreflood and Rustock this year show that any botnet can be exterminated.

"To say that it can't be done underestimates the ability of the good guys," Boscovich said. "People seem to be saying that the bad guys are smarter, better. But the answer to that is 'no.'"

Last week, Moscow-based Kaspersky Labs called the TDL-4 botnet "the most sophisticated threat today," and argued that it was "practically indestructible" because of its advanced encryption and use of a public peer-to-peer (P2P) network as a fallback communications channel for the instructions issued to infected PCs.

Takedowns like those of Waledac, Rustock and Coreflood have relied on seizing the primary command-and-control (C&C) servers, then somehow blocking the botnet's compromised computers from accessing alternate C&C domains for new instructions.

By doing both, takedowns decapitate the botnet, let researchers or authorities hijack the botnet, and prevent hackers from updating their malware or giving the bots new orders. That also gives users time to use antivirus software to clean their systems of the infections.

Kaspersky senior malware researcher Roel Schouwenberg said that TDL-4's use of P2P made the botnet an extremely tough nut.

"Any attempt to take down the regular C&Cs can effectively be circumvented by the TDL group by updating the list of C&Cs through the P2P network," Schouwenberg said last week. "The fact that TDL has two separate channels for communications will make any takedown very, very tough."

Boscovich disagreed, noting that the February 2010 takedown of Waledac successfully suppressed that botnet's P2P command channel.

"[Waledac] was a proof of concept that showed we are able to poison the peer-to-peer table of a botnet," Boscovich said.

"Each takedown is different, each one is complicated in its own way," said Boscovich. "Each one is going to be different, but that doesn't mean that there cannot be a way to do this with any botnet."

Alex Lanstein, a senior engineer with FireEye who worked with Microsoft on the Rustock takedown, said that the relationships Microsoft has built with others in the security field, with Internet service providers, and with government legal agencies like the U.S. Department of Justice and law enforcement were the most important factors in its ability to take down botnets, any botnets.

"It's the trust relationships Microsoft has created" that have led to successful takedowns, said Lanstein. "And I think [the technique] speaks to any malware infrastructure where some kind of data feed exists. It really, really works."

Those who disagree with Boscovich and Lanstein include not only Kaspersky's Schouwenberg, but also Joe Stewart, director of malware research at Dell SecureWorks and an internationally known botnet expert.

"I wouldn't say it's perfectly indestructible, but it is pretty much indestructible," Stewart said in an interview last week about TDL-4. "It does a very good job of maintaining itself."

But SecureWorks also acknowledged Microsoft's takedown chops, saying that its own statistics show that Rustock attacks have dropped tenfold since March.

"Since mid-March 2011, Dell SecureWorks' CTU [Counter Threat Unit] research team has seen a significant decline in the number of attempted Rustock attacks, and we do attribute it to the comprehensive efforts of Microsoft," a SecureWorks spokeswoman said Tuesday.

"With the Rustock takedown, Microsoft has built the framework for others to do the same," Lanstein said. "This is definitely not the last botnet we're going to go after."

He declined to name the next likely target, saying that doing so would tip Microsoft and FireEye's hand.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, or subscribe to Gregg's RSS feed Keizer RSS. His email address is gkeizer@computerworld.com.

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs