Difference between revisions of "Botnet"

From Conservapedia
Jump to navigation Jump to search
m (Reverted edits by TruthAndFreedom (talk) to last revision by DerekE)
Line 1: Line 1:
−
{{Use dmy dates|date=November 2013}}
+
A '''Botnet''' is a network of compromised computers; while not a form of [[malware]], a botnet can be the consequence of a malware attack.  Often created by a ''Trojan horse'' or a worm, a botnet can be used to send [[spam]] or to attack [[computer]]s.  For example, security researchers at [[Intego]] discovered a ''Trojan horse'' responsible for a [[Apple|Mac]] botnet in January, 2009, hidden inside pirated copies of popular Mac [[software]].<ref>Intego Security Alert. [http://www.intego.com/news/ism0901.asp Mac Trojan Horse OSX.Trojan.iServices.A Found in Pirated Apple iWork 09], intego.com, January 22, 2009.</ref><ref>[http://blog.intego.com/2009/01/26/new-variant-of-mac-trojan-horse-iservices-found-in-pirated-adobe-photoshop-cs4/ New Variant of Mac Trojan Horse iServices Found in Pirated Adobe Photoshop CS4], ''The Mac Security Blog'', January 26, 2009.
−
{{multiple issues|
+
* [http://www.intego.com/news/ism0902.asp Intego Security Alert]</ref>
−
{{refimprove|date=February 2008}}
 
−
{{expert-subject |computer science |date=May 2011}}
 
−
}}
 
  
−
A '''botnet''' is a number of [[Internet]]-connected computers communicating with other similar machines in an effort to complete repetitive tasks and objectives. This can be as mundane as keeping control of an [[Internet Relay Chat]] (IRC) channel, or it could be used to send spam email or participate in [[distributed denial-of-service attack]]s. The word botnet is a combination of the words [[robot]] and [[Computer network|network]]. The term is usually used with a negative or malicious connotation.
+
==References==
 +
<references/>
  
−
==Types of botnets==
+
[[category:computers]]
−
 
+
[[category:software]]
−
===Legal botnets===
 
−
The term '''botnet''' is widely used when several IRC bots have been linked and may possibly set channel modes on other bots and users while keeping IRC channels free from unwanted users. This is where the term is originally from, since the first illegal botnets were similar to legal botnets. A common bot used to set up botnets on IRC is  [[eggdrop]].
 
−
 
 
−
===Illegal botnets===
 
−
Botnets sometimes compromise computers whose security defenses have been breached and control conceded to a third party. Each such compromised device, known as a "[[Internet bot|bot]]", is created when a computer is penetrated by software from a ''malware'' ([[malicious software]])  distribution. The controller of a botnet is able to direct the activities of these compromised computers through communication channels formed by standards-based [[network protocol]]s such as IRC and [[Hypertext Transfer Protocol]] (HTTP).<ref>{{cite web |url=http://www.sans.org/reading-room/whitepapers/malicious/bots-botnet-overview-1299 |title=Bots &; Botnet: An Overview |last=Ramneek |first=Puri |date=2003-08-08 |format=PDF |publisher=[[SANS Institute]] |deadurl=no |accessdate=12 November 2013}}</ref>
 
−
 
 
−
Botnets are increasingly [[Cyber-arms industry#Online|rented out]] by [[Computer crime|cyber criminals]] as commodities for a variety of purposes.<ref>{{cite news|last1=Danchev|first1=Dancho|title=Novice cyberciminals offer commercial access to five mini botnets|url=http://www.webroot.com/blog/2013/10/11/novice-cyberciminals-offer-commercial-access-5-mini-botnets/|accessdate=28 June 2015|date=11 October 2013}}</ref>
 
−
 
 
−
==Recruitment==
 
−
Computers can be co-opted into a botnet when they execute malicious software. This can be accomplished by luring users into making a [[drive-by download]], exploiting [[browser exploit|web browser vulnerabilities]], or by tricking the user into running a [[Trojan horse (computing)|Trojan horse]] program, which may come from an email attachment. This malware will typically install modules that allow the computer to be [[command-and-control|commanded and controlled]] by the botnet's operator. Many computer users are unaware that their computer is infected with bots.<ref>{{cite web |author=Teresa Dixon Murray |title=Banks can't prevent cyber attacks like those hitting PNC, Key, U.S. Bank this week|url=http://www.cleveland.com/business/index.ssf/2012/09/banks_cant_prevent_cyber_attac.html|publisher=Cleveland.com |accessdate=2 September 2014}}</ref>  Depending on how it is written, a Trojan may then delete itself, or may remain present to update and maintain the modules.{{citation needed|date=June 2012}}
 
−
 
 
−
The first botnet was first acknowledged and exposed by [[Earthlink]] during a lawsuit with notorious spammer Khan C. Smith<ref>{{cite web|last=Credeur|first=Mary|title=Atlanta Business Chronicle, Staff Writer|url=http://www.bizjournals.com/atlanta/stories/2002/07/22/story4.html?page=all|publisher=bizjournals.com|accessdate=22 July 2002}}</ref> in 2001 for the purpose of bulk spam accounting for nearly 25% of all spam at the time.
 
−
 
 
−
==Organization==
 
−
While botnets are often named after the malware that created them, multiple botnets typically use the same malware, but are operated by different entities.<ref>[https://www.damballa.com/downloads/d_pubs/WP%20Many-to-Many%20Botnet%20Relationships%20%282009-05-21%29.pdf Many-to-Many Botnet Relationships], ''Damballa'', 8 June 2009.</ref>
 
−
 
 
−
A botnet's originator (known as a "[[bot herder]]" or "bot master") can control the group remotely, usually through [[IRC]], and often for criminal purposes. This server is known as the '''command-and-control (C&C) server'''. Though rare, more experienced botnet operators program command protocols from scratch. These protocols include a server program, a client program for operation, and the program that embeds the client on the victim's machine. These communicate over a network, using a unique [[encryption scheme]] for stealth and protection against detection or intrusion into the botnet.{{Citation needed|date=June 2012}}
 
−
 
 
−
A bot typically runs hidden and uses a [[covert channel]] (e.g. the RFC 1459 (IRC) standard, Twitter, or IM) to communicate with its C&C server. Generally, the perpetrator has compromised multiple systems using various tools ([[Exploit (computer security)|exploits]], [[buffer overflows]], as well as others; see also [[Remote procedure call|RPC]]). Newer bots can automatically scan their environment and propagate themselves using vulnerabilities and weak passwords. Generally, the more vulnerabilities a bot can scan and propagate through, the more valuable it becomes to a botnet controller community. The process of stealing computing resources as a result of a system being joined to a "botnet" is sometimes referred to as "scrumping."
 
−
 
 
−
Botnet servers are typically redundant, linked for greater redundancy so as to reduce the threat of a takedown. Actual botnet communities usually consist of one or several controllers that rarely have highly developed command hierarchies; they rely on individual peer-to-peer relationships.<ref>{{cite web|title=what is a Botnet trojan?|url=http://www.dslreports.com/faq/14158|publisher=DSL Reports|accessdate=7 April 2011}}</ref>
 
−
 
 
−
Botnet architecture evolved over time, and not all botnets exhibit the same [[topology (computing)|topology]] for command and control. Advanced topology is more resilient to shutdown, enumeration or discovery. However, some topologies limit the marketability of the botnet to third parties.<ref>[https://www.damballa.com/downloads/r_pubs/WP%20Botnet%20Communications%20Primer%20%282009-06-04%29.pdf Botnet Communication Topologies], ''Damballa'', 10 June 2009.</ref> Typical botnet topologies are star, multi-server, hierarchical and random.
 
−
 
 
−
To thwart detection, some botnets are scaling back in size. {{as of|2006}}, the average size of a network was estimated at 20,000 computers.<ref>{{Cite journal |url=http://www.computer.org/csdl/mags/co/2006/04/r4017.pdf |format=PDF|title=Hackers Strengthen Malicious Botnets by Shrinking Them|journal=Computer; News Briefs |publisher=IEEE Computer Society |date=April 2006 |deadurl=no |accessdate=12 November 2013 |doi=10.1109/MC.2006.136|quote=The size of bot networks peaked in mid-2004, with many using more than 100,000 infected machines, according to Mark Sunner, chief technology officer at MessageLabs.The average botnet size is now about 20,000 computers, he said.}}</ref>
 
−
 
 
−
== Formation ==
 
−
This example illustrates how a botnet is created and used to send [[email spam]].
 
−
 
 
−
[[File:Botnet.svg|right|350px|thumb|How a botnet works]]
 
−
 
 
−
# A botnet operator sends out [[Computer virus|viruses]] or [[Computer worm|worms]], infecting ordinary users' computers, whose payload is a malicious application—the ''bot''.
 
−
# The ''bot'' on the infected PC logs into a particular C&C server.
 
−
# A spammer purchases the services of the botnet from the operator.
 
−
# The spammer provides the spam messages to the operator, who instructs the compromised machines via the control panel on the web server, causing them to send out spam messages.
 
−
 
 
−
Botnets can be exploited for various other purposes, including [[denial-of-service attack]]s, creation or misuse of [[SMTP|SMTP mail relays]] for spam (see [[Spambot]]), [[click fraud]], mining [[bitcoins]], [[spamdexing]], and the theft of application serial numbers, [[Login|login IDs]], and financial information such as [[Bank card number|credit card numbers]].
 
−
 
 
−
The botnet controller community features a constant and continuous struggle over who has the most bots, the highest overall bandwidth, and the most "high-quality" infected machines, like university, corporate, and even government machines.<ref>{{cite web|title=Trojan horse, and Virus FAQ|url=http://www.dslreports.com/faq/trojans/1.0_Trojan_horses|publisher=DSLReports|accessdate=7 April 2011}}</ref>
 
−
 
 
−
== Types of attacks ==
 
−
* In [[distributed denial-of-service attack]]s, multiple systems submit as many requests as possible to a single Internet computer or service, overloading it and preventing it from servicing legitimate requests. An example is an attack on a victim's phone number. The victim is bombarded with phone calls by the bots, attempting to connect to the Internet.
 
−
* [[Adware]] advertises a commercial offering actively and without the user's permission or awareness, for example by replacing banner ads on web pages with those of another advertiser.
 
−
* [[Spyware]] is software which sends information to its creators about a user's activities&nbsp;– typically passwords, credit card numbers and other information that can be sold on the black market. Compromised machines that are located within a corporate network can be worth more to the bot herder, as they can often gain access to confidential corporate information. Several targeted attacks on large corporations aimed to steal sensitive information, such as the Aurora botnet.<ref>{{cite web|url=http://www.damballa.com/research/aurora/ |title=Operation Aurora&nbsp;— The Command Structure |publisher=Damballa.com |date= |accessdate=30 July 2010}}{{dead link|date=April 2014}}</ref>
 
−
* [[E-mail spam]] are e-mail messages disguised as messages from people, but are either advertising, annoying, or malicious.
 
−
* [[Click fraud]] occurs when the user's computer visits websites without the user's awareness to create false web traffic for personal or commercial gain.
 
−
* [[Fast flux]] is a DNS technique used by botnets to hide [[phishing]] and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies.
 
−
*Brute-forcing remote machines services such as [[FTP]], [[SMTP]] and [[Secure Shell|SSH]].
 
−
*Worms. The botnet focuses on recruiting other hosts.
 
−
*[[Scareware]] is software that is marketed by creating fear in users. Once installed, it can install malware and recruit the host into a botnet. For example users can be induced to buy a rogue anti-virus to regain access to their computer.<ref>{{cite web|last=Larkin |first=Erik |url=http://www.pcworld.com/article/159316/fake_warnings.html |title=Fake Infection Warnings Can Be Real Trouble |publisher=PCWorld |date=2009-02-10 |accessdate=10 November 2011}}</ref>
 
−
*Exploiting systems by observing users playing online games such as poker and see the players' cards.<ref>{{cite web|author=8 Jul 2010 |url=http://poker.gamingsupermarket.com/news/4660/korean-poker-hackers-arrested |title=Korean Poker Hackers Arrested |publisher=Poker.gamingsupermarket.com |date=2010-07-08 |accessdate=10 November 2011}}</ref>
 
−
 
 
−
== Countermeasures ==
 
−
The geographic dispersal of botnets means that each recruit must be individually identified/corralled/repaired and limits the benefits of [[firewall (networking)|filtering]]. Some botnets use free [[Domain Name System|DNS]] hosting services such as DynDns.org, No-IP.com, and Afraid.org to point a [[subdomain]] towards an IRC server that harbors the bots. While these free DNS services do not themselves host attacks, they provide reference points (often hard-coded into the botnet executable). Removing such services can cripple an entire botnet. Some botnets implement custom versions of well-known protocols. The implementation differences can be used for detection of botnets. For example, [[Mega-D]] features a slightly modified [[SMTP]] protocol implementation for testing spam capability. Bringing down the [[Mega-D]]'s [[SMTP]] server disables the entire pool of bots that rely upon the same [[SMTP]] server.<ref>C.Y. Cho, D. Babic, R. Shin, and D. Song. [http://www.domagoj-babic.com/index.php/Pubs/CCS10botnets Inference and Analysis of Formal Models of Botnet Command and Control Protocols], 2010 ACM Conference on Computer and Communications Security.</ref>
 
−
 
 
−
The botnet server structure mentioned above has inherent vulnerabilities and problems. For example, finding one server with one botnet channel can often reveal the other servers, as well as their bots. A botnet server structure that lacks [[redundancy (engineering)|redundancy]] is vulnerable to at least the temporary disconnection of that server. However, recent [[IRC server]] software includes features to mask other connected servers and bots, eliminating that approach.{{citation needed|date=February 2015}}
 
−
 
 
−
Computer and network security companies have released software to counter botnets. [[Norton AntiBot]] was aimed at consumers, but most target enterprises and/or ISPs. Host-based techniques use heuristics to identify bot behavior that has bypassed conventional [[anti-virus software]]. Network-based approaches tend to use the techniques described above; shutting down C&C servers, nullrouting DNS entries, or completely shutting down IRC servers.  [[BotHunter]] is software, developed with support from the [[U.S. Army Research Office]], that detects botnet activity within a network by analysing network traffic and comparing it to patterns characteristic of malicious processes.
 
−
 
 
−
Some newer botnets are almost entirely [[Peer-to-peer|P2P]]. Command and control is embedded into the botnet rather than relying on external servers, thus avoiding any single point of failure and evading many countermeasures.<ref>{{cite book|authors=Wang, Ping et al|chapter=Peer-to-peer botnets|editors=Stamp, Mark & Stavroulakis, Peter|title=Handbook of Information and Communication Security|publisher=Springer|year=2010|isbn=9783642041174|url=http://books.google.com/books?id=I-9P1EkTkigC&pg=PA335}}</ref> Commanders can be identified just through secure keys, and all data except the binary itself can be encrypted. For example, a spyware program may encrypt all suspected passwords with a public key that is hard-coded into it, or distributed with the bot software. Only with the private key (known only by the botnet operators) can the data captured by the bot be read.
 
−
 
 
−
Some botnets are capable of detecting and reacting to attempts to investigate them{{citation needed|date=September 2014}}, reacting perhaps with a [[DDoS#Distributed attack|DDoS attack]] on the IP address of the investigator.
 
−
 
 
−
Researchers at [[Sandia National Laboratories]] are analyzing botnets' behavior by simultaneously running one million Linux kernels—a similar scale to a botnet—as [[virtual machines]] on a 4,480-node high-performance [[computer cluster]] to emulate a very large network, allowing them to watch how botnets work and experiment with ways to stop them.<ref>{{cite web|url=http://www.eweek.com/c/a/Security/Researchers-Boot-Million-Linux-Kernels-to-Help-Botnet-Research-550216/?kc=EWKNLLIN08182009STR2 |title=Researchers Boot Million Linux Kernels to Help Botnet Research |publisher=IT Security & Network Security News |date=2009-08-12 |accessdate=23 April 2011}}</ref>
 
−
 
 
−
== Historical list of botnets ==
 
−
{| class="wikitable sortable"
 
−
|-
 
−
! Date created
 
−
! Date dismantled
 
−
! Name
 
−
! data-sort-type="number" | Estimated no. of bots
 
−
! data-sort-type="number" |  Spam capacity (bn/day)
 
−
! Aliases
 
−
|- style="display:none;"
 
−
|1999||!a||999,999,999||100000||!a
 
−
|-
 
−
| 2011 or earlier
 
−
| 2015-02
 
−
| [[Ramnit]]
 
−
| 3,000,000<ref name="phys.org">http://phys.org/news/2015-02-eu-police-malicious-network.html</ref>
 
−
|
 
−
|
 
−
|-
 
−
| 2009 (May)
 
−
| [[BredoLab botnet#Dismantling and aftermath|2010-Oct (partial)]]
 
−
| [[BredoLab botnet|BredoLab]]
 
−
| 30,000,000<ref>{{cite web|url=http://www2.canada.com/topics/technology/story.html?id=3333655 |title=Infosecurity (UK) - BredoLab downed botnet linked with Spamit.com |publisher=.canada.com |date= |accessdate=10 November 2011}}</ref>
 
−
| 3.6
 
−
| Oficla
 
−
|-
 
−
| 2008 (around)
 
−
| [[Mariposa botnet#Dismantling|2009-Dec]]
 
−
| [[Mariposa botnet|Mariposa]]
 
−
| 12,000,000<ref>{{cite web|url=http://www.theregister.co.uk/2010/03/03/mariposa_botnet_bust_analysis/ |title=How FBI, police busted massive botnet |publisher=theregister.co.uk |date= |accessdate=3 March 2010}}</ref>
 
−
|
 
−
|
 
−
|-
 
−
| 2008 (November)
 
−
|
 
−
| | [[Conficker]]
 
−
| 10,500,000+<ref>{{cite web|url=http://www.f-secure.com/weblog/archives/00001584.html |title=Calculating the Size of the Downadup Outbreak&nbsp;— F-Secure Weblog : News from the Lab |publisher=F-secure.com |date=2009-01-16 |accessdate=24 April 2010}}</ref>
 
−
| 10
 
−
| DownUp, DownAndUp, DownAdUp, Kido
 
−
|-
 
−
| 2011 or earlier
 
−
| 2015-02
 
−
| [[Ramnit]]
 
−
| 3,000,000<ref name="phys.org"/>
 
−
|
 
−
|-
 
−
| 2010 (around)
 
−
|
 
−
| [[TDL4 botnet|TDL4]]
 
−
| 4,500,000<ref>{{cite web|url=http://infoaleph.wordpress.com/2011/07/03/como-detectar-y-borrar-el-rootkit-tdl4-tdssalureon/ |title=Cómo detectar y borrar el rootkit TDL4 (TDSS/Alureon) |publisher=kasperskytienda.es |date=2011-07-03 |accessdate=11 July 2011}}</ref>
 
−
| 
 
−
| TDSS, Alureon
 
−
|-
 
−
|
 
−
|
 
−
| [[Zeus (Trojan horse)|Zeus]]
 
−
| 3,600,000 (US only)<ref>{{cite web|url=http://www.networkworld.com/article/2260410/network-security/america-s-10-most-wanted-botnets.html |title=America's 10 most wanted botnets |publisher=Networkworld.com |date=2009-07-22 |accessdate=10 November 2011}}</ref>
 
−
| 
 
−
| Zbot, PRG, Wsnpoem, Gorhax, Kneber
 
−
|-
 
−
| 2007 (Around)
 
−
|
 
−
| [[Cutwail botnet|Cutwail]]
 
−
| 1,500,000<ref>{{cite web|url=http://msmvps.com/blogs/harrywaldron/archive/2010/02/02/pushdo-botnet-new-ddos-attacks-on-major-web-sites.aspx |title=Pushdo Botnet&nbsp;— New DDOS attacks on major web sites&nbsp;— Harry Waldron&nbsp;— IT Security |publisher=Msmvps.com |date=2010-02-02 |accessdate=30 July 2010}}</ref>
 
−
| 74
 
−
| Pandex, Mutant (related to: Wigon, Pushdo)
 
−
|-
 
−
| 2008 (Around)
 
−
|
 
−
| [[Sality]]
 
−
| 1,000,000<ref>{{cite web|url=http://www.symantec.com/connect/sites/default/files/sality_peer_to_peer_viral_network.pdf |title=Sality: Story of a Peer-to-Peer Viral Network |publisher=Symantec |date=2011-08-03 |accessdate=12 January 2012}}</ref>
 
−
| 
 
−
| Sector, Kuku
 
−
|-
 
−
| 2009 (Around)
 
−
| 2012-07-19
 
−
| [[Grum botnet|Grum]]
 
−
| 560,000<ref>{{cite web|url=http://www.zdnet.com/blog/security/research-small-diy-botnets-prevalent-in-enterprise-networks/4485 |title=Research: Small DIY botnets prevalent in enterprise networks |publisher=ZDNet |date= |accessdate=30 July 2010}}</ref>
 
−
| 39.9
 
−
| Tedroo
 
−
|-
 
−
| 
 
−
|
 
−
| [[Mega-D botnet|Mega-D]]
 
−
| 509,000<ref name="CyberCrime-20101202">{{cite web|last=Warner|first=Gary|url=http://garwarner.blogspot.com/2010/12/oleg-nikolaenko-mega-d-botmaster-to.html|title=Oleg Nikolaenko, Mega-D Botmaster to Stand Trial|publisher=CyberCrime & Doing Time|date=2010-12-02|accessdate=6 December 2010}}</ref>
 
−
| 10
 
−
| Ozdok
 
−
|-
 
−
| 
 
−
|
 
−
| [[Kraken botnet|Kraken]]
 
−
| 495,000<ref>{{cite web|url=http://www.darkreading.com/attacks-breaches/new-massive-botnet-twice-the-size-of-storm/d/d-id/1129410? |title=New Massive Botnet Twice the Size of Storm&nbsp;— Security/Perimeter |publisher=DarkReading |date= |accessdate=30 July 2010}}</ref>
 
−
| 9
 
−
| Kracken
 
−
|-
 
−
| 2007 (March)
 
−
| 2008 (November)
 
−
| [[Srizbi botnet|Srizbi]]
 
−
| 450,000<ref>{{cite news|url=http://news.bbc.co.uk/2/hi/technology/7749835.stm |title=Technology &#124; Spam on rise after brief reprieve |publisher=BBC News |date=2008-11-26 |accessdate=24 April 2010}}</ref>
 
−
| 60
 
−
| Cbeplay, Exchanger
 
−
|-
 
−
| 
 
−
|
 
−
| [[Lethic botnet|Lethic]]
 
−
| 260,000<ref name=messagelabs>{{cite web|url=http://www.messagelabs.com/mlireport/MLI_2010_04_Apr_FINAL_EN.pdf |title=Symantec.cloud &#124; Email Security, Web Security, Endpoint Protection, Archiving, Continuity, Instant Messaging Security |publisher=Messagelabs.com |date= |accessdate=2014-01-30}}{{Dead link|date=June 2014}}</ref>
 
−
| 2
 
−
| none
 
−
|-
 
−
| 2004 (Early)
 
−
|
 
−
| [[Bagle botnet|Bagle]]
 
−
| 230,000<ref name=messagelabs/>
 
−
| 5.7
 
−
| Beagle, Mitglieder, Lodeight
 
−
|-
 
−
| 
 
−
|
 
−
| Marina Botnet
 
−
| 6,215,000<ref name=messagelabs/>
 
−
| 92
 
−
| Damon Briant, BOB.dc, Cotmonger, Hacktool.Spammer, Kraken
 
−
|-
 
−
| 
 
−
|
 
−
| [[Torpig]]
 
−
| 180,000<ref name=scmagazineus>{{cite web|author=Chuck Miller |url=http://www.scmagazine.com/researchers-hijack-control-of-torpig-botnet/article/136207/ |title=Researchers hijack control of Torpig botnet |publisher=SC Magazine US |date=2009-05-05 |accessdate=10 November 2011}}</ref>
 
−
| 
 
−
| Sinowal, Anserin
 
−
|-
 
−
| 
 
−
|
 
−
| [[Storm botnet|Storm]]
 
−
| 160,000<ref>{{cite web|url=http://tech.blorge.com/Structure:%20/2007/10/21/2483/ |title=Storm Worm network shrinks to about one-tenth of its former size |publisher=Tech.Blorge.Com |date=2007-10-21 |accessdate=30 July 2010}}</ref>
 
−
| 3
 
−
| Nuwar, Peacomm, Zhelatin
 
−
|-
 
−
| 2006 (Around)
 
−
| 2011 (March)
 
−
| [[Rustock botnet|Rustock]]
 
−
| 150,000<ref>{{cite web|author=Chuck Miller |url=http://www.scmagazine.com/the-rustock-botnet-spams-again/article/112940/ |title=The Rustock botnet spams again |publisher=SC Magazine US |date=2008-07-25 |accessdate=30 July 2010}}</ref>
 
−
| 30
 
−
| RKRustok, Costrat
 
−
|-
 
−
| 
 
−
|
 
−
| [[Donbot botnet|Donbot]]
 
−
| 125,000<ref>{{cite web|url=http://www.secureworks.com/cyber-threat-intelligence/threats/botnets2009/ |title=Spam Botnets to Watch in 2009 &#124; Dell SecureWorks |publisher=Secureworks.com |date= |accessdate=16 January 2012}}</ref>
 
−
| 0.8
 
−
| Buzus, Bachsoy
 
−
|-
 
−
| 2012 (Around)
 
−
|
 
−
| [[Chameleon botnet|Chameleon]]
 
−
| 120,000 <ref>{{cite web|url=http://www.spider.io/blog/2013/03/chameleon-botnet/ |title=Discovered: Botnet Costing Display Advertisers over Six Million Dollars per Month |publisher=Spider.io |date=2013-03-19 |accessdate=21 March 2013}}</ref>
 
−
| 
 
−
| None
 
−
|-
 
−
| 2008 (November)
 
−
| [[Waledac botnet#Operations|2010 (March)]]
 
−
| [[Waledac botnet|Waledac]]
 
−
| 80,000<ref name=theregister>{{cite web|url=http://www.theregister.co.uk/2010/03/16/waledac_takedown_success/ |title=Waledac botnet 'decimated' by MS takedown |publisher=The Register |date=2010-03-16 |accessdate=23 April 2011}}</ref>
 
−
| 1.5
 
−
| Waled, Waledpak
 
−
|-
 
−
| 
 
−
|
 
−
| Maazben
 
−
| 50,000<ref name=messagelabs/>
 
−
| 0.5
 
−
| None
 
−
|-
 
−
| 
 
−
|
 
−
| Onewordsub
 
−
| 40,000<ref name=computerworld>{{cite web|author=Gregg Keizer |url=http://www.computerworld.com/s/article/9076278/Top_botnets_control_1M_hijacked_computers |title=Top botnets control 1M hijacked computers |publisher=Computerworld |date=2008-04-09 |accessdate=23 April 2011}}</ref>
 
−
| 1.8
 
−
| 
 
−
|-
 
−
| 
 
−
|
 
−
| Gheg
 
−
| 30,000<ref name=messagelabs/>
 
−
| 0.24
 
−
| Tofsee, Mondera
 
−
|-
 
−
| 
 
−
|
 
−
|
 
−
| 20,000<ref name=computerworld/>
 
−
| 5
 
−
| Loosky, Locksky
 
−
|-
 
−
| 
 
−
|
 
−
| Wopla
 
−
| 20,000<ref name=computerworld/>
 
−
| 0.6
 
−
| Pokier, Slogger, Cryptic
 
−
|-
 
−
| 2008 (Around)
 
−
|
 
−
| [[Asprox botnet|Asprox]]
 
−
| 15,000<ref>{{cite web|url=http://www.theregister.co.uk/2008/05/14/asprox_attacks_websites/ |title=Botnet sics zombie soldiers on gimpy websites |publisher=The Register |date=2008-05-14 |accessdate=23 April 2011}}</ref>
 
−
| 
 
−
| Danmec, Hydraflux
 
−
|-
 
−
| <span style="display:none">0</span>
 
−
|
 
−
| Spamthru
 
−
| 12,000<ref name=computerworld/>
 
−
| 0.35
 
−
| Spam-DComServ, Covesmer, Xmiler
 
−
|-
 
−
| 2010 (January)
 
−
|
 
−
| LowSec
 
−
| 11,000+<ref name=messagelabs/>
 
−
| 0.5
 
−
| LowSecurity, FreeMoney, Ring0.Tools
 
−
|-
 
−
| 2007 (September)
 
−
|
 
−
| dBot
 
−
| 10,000+ (Europe)
 
−
|
 
−
| dentaoBot, d-net, SDBOT
 
−
|-
 
−
| 
 
−
|
 
−
| Xarvester
 
−
| 10,000<ref name=messagelabs/>
 
−
| 0.15
 
−
| Rlsloup, Pixoliz
 
−
|-
 
−
| 2009 (August)
 
−
|
 
−
| [[Festi botnet|Festi]]
 
−
| 
 
−
| 2.25
 
−
| Spamnost
 
−
|-
 
−
| 2008 (Around)
 
−
|
 
−
| [[Gumblar]]
 
−
|
 
−
|
 
−
|
 
−
|-
 
−
| 2007
 
−
|
 
−
| [[Akbot]]
 
−
| 1,300,000<ref>{{cite news|url=http://www.h-online.com/security/news/item/New-Zealand-teenager-accused-of-controlling-botnet-of-1-3-million-computers-734068.html |title=New Zealand teenager accused of controlling botnet of 1.3 million computers |publisher=The H security |date=2007-11-30 |accessdate=12 November 2011}}</ref>
 
−
| 
 
−
|
 
−
|-
 
−
| 2010
 
−
| (Several: 2011, 2012)
 
−
| [[Kelihos botnet|Kelihos]]
 
−
| 300,000+
 
−
| 4
 
−
| Hlux
 
−
|-
 
−
| 2013
 
−
| 2013
 
−
| Boatnet
 
−
| 500+ server computers
 
−
| 0.01
 
−
| YOLOBotnet
 
−
|-
 
−
| 2013
 
−
| 2013
 
−
| Zer0n3t
 
−
| 200+ server computers
 
−
| 4
 
−
| FiberOptck, OptckFiber, Fib3rl0g1c
 
−
|-
 
−
| 2014
 
−
|
 
−
| [[Semalt botnet|Semalt]]
 
−
| 300,000+
 
−
|
 
−
| Soundfrost
 
−
|}
 
−
*Researchers at the University of California, Santa Barbara took control of a botnet that was six times smaller than expected. In some countries, it is common that users change their IP address a few times in one day. Estimating the size of the botnet by the number of IP addresses is often used by researchers, possibly leading to inaccurate assessments.<ref>{{cite web|last=Espiner |first=Tom |url=http://www.zdnet.com/botnet-size-may-be-exaggerated-says-enisa-3040092062/ |title=Botnet size may be exaggerated, says Enisa &#124; Security Threats &#124; ZDNet UK |publisher=Zdnet.com |date=2011-03-08 |accessdate=10 November 2011}}</ref>
 
−
 
 
−
== See also ==
 
−
* [[Anti-spam techniques (e-mail)]]
 
−
* [[Command and control (malware)]]
 
−
* [[Computer worm]]
 
−
* [[DoSnet]]
 
−
* [[E-mail address harvesting]]
 
−
* [[E-mail spam]]
 
−
* [[List poisoning]]
 
−
* [[Spambot]]
 
−
* [[Spamtrap]]
 
−
* [[Timeline of notable computer viruses and worms]]
 
−
* [[Zombie computer]]
 
−
 
 
−
== References ==
 
−
{{Reflist|30em}}
 
−
 
 
−
== External links ==
 
−
* [http://howto.wired.com/wiki/Build_your_own_botnet_with_open_source_software Wired.com How-to: Build your own botnet with open source software]
 
−
* [http://www.honeynet.org/papers/bots/ The Honeynet Project & Research Alliance], "Know your Enemy: Tracking Botnets".
 
−
* [http://www.shadowserver.org/wiki/ The Shadowserver Foundation] - An all volunteer security watchdog group that gathers, tracks, and reports on malware, botnet activity, and electronic fraud.
 
−
* [http://www.nanog.org/meetings/nanog32/presentations/kristoff.pdf NANOG Abstract: Botnets] - John Kristoff's NANOG32 Botnets presentation.
 
−
* [http://web.archive.org/web/20070812163012/http://www.daemon.be/maarten/mobbot.html Mobile botnets] - An economic and technological assessment of mobile botnets.
 
−
* [http://lowkeysoft.com/proxy/ Lowkeysoft - Intrusive analysis of a web-based proxy botnet] (including administration screenshots).
 
−
* [http://www.eweek.com/c/a/Security/Is-the-Botnet-Battle-Already-Lost/ EWeek.com - Is the Botnet Battle Already Lost?].
 
−
* [http://archive.wired.com/wired/archive/14.11/botnet.html Attack of the Bots] at ''[[Wired (magazine)|Wired]]''
 
−
* [http://www.darkreading.com/attacks-breaches/botnets-battle-over-turf/d/d-id/1128726? Dark Reading - Botnets Battle Over Turf].
 
−
* [http://atlas.arbor.net/summary/botnets ATLAS Global Botnets Summary Report] - Real-time database of malicious botnet command and control servers.
 
−
* [http://losangeles.fbi.gov/dojpressrel/pressrel08/la041608usa.htm FBI LAX Press Release DOJ]{{dead link|date=April 2014}} - [[FBI]] April 16, 2008
 
−
* [http://wiki.milcord.com/wiki/Botnet_Defense Milcord Botnet Defense]{{dead link|date=April 2014}} - DHS-sponsored R&D project that uses machine learning to adaptively detect botnet behavior at the network-level
 
−
* [http://www.securityfocus.com/columnists/501 A Botnet by Any Other Name] - SecurityFocus column by Gunter Ollmann on botnet naming.
 
−
* [http://www.fbi.gov/news/stories/2014/january/spyeye-malware-mastermind-pleads-guilty Botnet Bust - SpyEye Malware Mastermind Pleads Guilty], [[FBI]]
 
−
 
 
−
{{Botnets}}
 
−
{{malware}}
 
−
 
 
−
[[Category:Computer network security]]
 
−
[[Category:Spamming]]
 
−
[[Category:Multi-agent systems]]
 
−
[[Category:Botnets| ]]
 
−
[[Category:Distributed computing]]
 

Revision as of 20:26, July 10, 2015

A Botnet is a network of compromised computers; while not a form of malware, a botnet can be the consequence of a malware attack. Often created by a Trojan horse or a worm, a botnet can be used to send spam or to attack computers. For example, security researchers at Intego discovered a Trojan horse responsible for a Mac botnet in January, 2009, hidden inside pirated copies of popular Mac software.[1][2]

References