Enterprise Security-Fast Flux Bot Nets

Oakenfold

Diamond Member
Feb 8, 2001
5,740
0
76
Has anyone had to deal with one of these yet? I was not aware of this technique until I read this article.

"Traditional bot nets have used Internet relay chat (IRC) servers to control each of the compromised PCs, or bots, but the central IRC server is also a weakness, giving defenders a single server to target and take down. An increasingly popular technique, known as fast-flux domain name service (DNS), allows bot nets to use a multitude of servers to hide a key host or to create a highly-available control network. The result: No single point of weakness on which defenders can focus their efforts."

Security Focus Full Article by Robert Lemos

After reading the article it sounds like the domain has to be taken down, any other thoughts on how to deal with this?
 

Zugzwang152

Lifer
Oct 30, 2001
12,134
1
0
The last paragraph had it down: for the immediate future the focus has to be on preventing infections. Unfortunately, you can put as many layers of defense within your own network and still be smacked by someone else's lack of preparation.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: n0cmonkey
With the advent of p2p bots I'm not too worried about it.

There still needs to be a mechaism for the bots to find peers. In the example given, going after the dns is the right solution. Going for the server behind the dns has always been the wrong approach (albeit, it was simpler).
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: bsobel
Originally posted by: n0cmonkey
With the advent of p2p bots I'm not too worried about it.

There still needs to be a mechaism for the bots to find peers. In the example given, going after the dns is the right solution. Going for the server behind the dns has always been the wrong approach (albeit, it was simpler).

Good point.

I'm waiting for the bots to pass along peer information after infection. No DNS required.
 

Oakenfold

Diamond Member
Feb 8, 2001
5,740
0
76
Originally posted by: Zugzwang152
The last paragraph had it down: for the immediate future the focus has to be on preventing infections. Unfortunately, you can put as many layers of defense within your own network and still be smacked by someone else's lack of preparation.

That's the part that I have trouble with seeing as being realistic. Relying on others to prepare, perhaps a better way to sell this approach would be to raise business and consumer education on why having adequate controls in place on a computer are important.

In addition this doesn't resolve problems that have to be dealt with today.


Originally posted by: n0cmonkey
With the advent of p2p bots I'm not too worried about it.

Care to expand on that?
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Originally posted by: Oakenfold
Originally posted by: Zugzwang152
The last paragraph had it down: for the immediate future the focus has to be on preventing infections. Unfortunately, you can put as many layers of defense within your own network and still be smacked by someone else's lack of preparation.

That's the part that I have trouble with seeing as being realistic. Relying on others to prepare, perhaps a better way to sell this approach would be to raise business and consumer education on why having adequate controls in place on a computer are important.

In addition this doesn't resolve problems that have to be dealt with today.


Originally posted by: n0cmonkey
With the advent of p2p bots I'm not too worried about it.

Care to expand on that?

Botnets seem to be moving to a p2p/decentralized model. There is no single C&C. Often times the connections are encrypted too. Waste has actually been seen in the wild as the communication method, which I thought was pretty neat.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |