rpclogo

 

A telescope that sets its sights on cyber-crime

A TELESCOPE that can peer into the depths of the net to spot the gathering threat of a botnet could help combat cyber-attacks.

Botnets - networks of compromised computers that are controlled by someone with malicious intent - are an increasingly common feature of the internet. They can be used to flood a target website with useless data to bring it down, launch spam, or spy on computer users by looking for their banking logins and passwords.

To combat this threat, Endgame Systems of Atlanta, Georgia, has come up with a system, called the internet telescope, that can map the physical location of computers infected with the malicious software, or malware, used to run botnets. It can even identify the type of malware on the machine and pre-empt its next moves.

Cyber-criminals use the internet to plant malicious code on computers that lack up-to-date security patches. Thousands of such machines, known as bots, can then be controlled by the botnet operator without the owner realising their computer has been recruited into a botnet. Endgame passively tracks these compromised PCs from the botnet traffic they disgorge, geotagging the data to create a global threat map.

It then dissects the malware to work out the web addresses of the next few domain name servers each bot is programmed to seek instructions from once the current control domain expires - a trick they play to evade detection. Once these domains are known, Endgame buys them up before the person controlling the botnet, or "botmaster", does, ensuring that it seizes control of the entire botnet when it switches to its new control address.

Endgame can then either kill the botnet - by ordering all bots to cease activity - or try to catch the botmaster by interfering with the botnet's activity in such a way as to blow their cover. The botmaster might, for example, contact their domain registrar to find out what's wrong with their domain. This would provide the registrar with contact information which could be passed onto law enforcers.

Endgame's CEO, Chris Rouland, presented his company's work at the Cyber Warfare conference in London last week. The firm's customers include government agencies and companies who want to know if the organisations they plan to do business with could infect their computers.

In his presentation, Rouland gave the example of a company that wanted to know whether an energy firm it was planning to work with was a cyber-security risk. Using the internet telescope, it zoomed in on the geotagged data to determine that some of the proposed partner company's computers had indeed been compromised by a botnet.

UK government officials told the conference that more real-world countermeasures like Endgame's are needed - and fast. Without them, today's attacks on crucial infrastructure, such as banking networks, may encourage nation-on-nation cyber-warfare in future.

"We underestimate the skill set of organised cyber crime. It is persistent, very well organised and focused," says Amit Yoran of cyber-forensics firm NetWitness based in Herndon, Virginia.

It is also increasingly successful. Over $1 trillion was stolen online in 2008, according to computer security firm McAfee. "That's because we are using technology designed to fight the cyber-threats of 1995," Yoran says.

Most security software impedes known threats, but the most skilful botnet operators don't use known malware. A survey by communications company Verizon, based in New York City, found that 59 per cent of cyber-attacks involve custom-written programs that bypass existing security systems.

Some excellent programmers are behind these attacks, says Jim Butterworth, a director at computer forensics firm Guidance Software of Pasadena, California. "Some malware code has been through far more quality assurance than a lot of commercial software."

Developing countermeasures is being made tougher by the speed of online developments, says Yoran. The shift to mobile computing platforms and social networks such as Twitter helps malware to spread in milliseconds, he says.

The speed of cyber-attacks has also had an effect. In the US, the newly established 24th Air Force heads up the military's cyber security operation. Charles Shugg, the 24th's second in command, says his "hunter" teams, who fend off online attacks or pre-emptively seek out online vulnerabilities, often have no time to develop countermeasures. "Things happen so quickly in the cyber-domain that the hunter teams' offence and defence are often one and the same thing."

Tools such as Endgame's internet telescope may have a role to play in providing the intelligence needed to combat botnets as this type of location-aware technology may slash the number of bots available to launch cyber-attacks.

Without action, says Gerard Vernez, a cyber-security expert with the Swiss army, the networks we depend on will be vulnerable. "What are we doing now? I call it plug and pray," he says.

Courtesy Computer Crime

 

 

  HOW DOES THIS WORK ?
call1 Call our agents at 209-642-4483 and log your issues to us
age Our agent gets connected to your system remotely
che Sit back and relax or watch out our service
kno Once the issues are solved, the agent feeds you the knowledge transfer and disconnects from your computer
comm You can send your feedback / comments / expereince to support@remotepccure.org

 

Virus Removal Tool Names
Vcleaner
Removes the following viruses:
I-Worm/Stration, Worm/Generic.FX, Agent.A-AN, BackDoor.Agent.A-Z, BackDoor.Agent.AA-BG, Downloader.Agent.AS, I-Worm/Atak.A-I, Bagle.DA-IU, I-Worm/Bagle.A-Z, I-Worm/Bagle.AA-JD, I-Worm/Bugbear.D, I-Worm/Mytob.A-GC, I-Worm/Netsky.A-Z, Worm/Netsky.AA-AD, I-Worm/Sasser.A-F, I-Worm/Zafi.A-E, PSW.Bispy.A-E, Win32/Gaelicum, Win32/Hidrag
Worm/Downadup (Worm/Conficker)
Removes the following viruses:
Worm/Downadup (Worm/Conficker)
Downloader.Stubby.A
Removes the following viruses:
Downloader.Stubby.A
I-Worm/Bugbear.C
Removes the following viruses:
I-Worm/Bugbear.C )
I-Worm/Ganda
Removes the following viruses:
I-Worm/Ganda, papaDog Download remover:
rmganda.exe
Win32/Expiro
Removes the following viruses:
Win32/Expiro
I-Worm/Happy99
Removes the following viruses:
I-Worm/Happy99
I-Worm/Lovgate.C
Removes the following viruses:
I-Worm/Lovgate.C
I-Worm/Luder
Removes the following viruses:
I-Worm/Luder
Win32/Dundun
Removes the following viruses:
Win32/Dundun
I-Worm/Mydoom.A and B
Removes the following viruses:
I-Worm/Mydoom.A and I-Worm/Mydoom.B
I-Worm/Mydoom.F
Removes the following viruses:
I-Worm/Mydoom.F
I-Worm/Navidad
Removes the following viruses:
I-Worm/Navidad
I-Worm/Nimda
Removes the following viruses:
I-Worm/Nimda
I-Worm/Pretty_Park
Removes the following viruses:
I-Worm/Pretty_Park
I-Worm/Sircam.A
Removes the following viruses:
I-Worm/Sircam.A
I-Worm/Sober.A
Removes the following viruses:
I-Worm/Sober.A
I-Worm/Swen
Removes the following viruses:
I-Worm/Swen
I-Worm/Verona.B
Removes the following viruses:
I-Worm/Verona.B
LOP.AH/Backdoor.Generic3.SVX
Removes the following viruses:
LOP.AH/Backdoor.Generic3.SVX
Packed.Protector.C
Removes the following viruses:
Packed.Protector.C
Win32/Vampiro
Removes the following viruses:
Win32/Vampiro
VBS/Iloveyou
Removes the following viruses:
VBS/Iloveyou
Win32/Alman
Removes the following viruses:
Win32/Alman
Win32/Delf.2.B
Removes the following viruses:
Win32/Delf.2.B
Win32/Dupator
Removes the following viruses:
Win32/Dupator
Win32/Elkern, variants A, B and C
Removes the following viruses:
Win32/Elkern.A, Win32/Elkern.B, Win32/Elkern.C
Win32/Gaelicum
Removes the following viruses:
Win32/Gaelicum
Win32/Kriz
Removes the following viruses:
Win32/Kriz
Win32/Mabezat
Removes the following viruses:
Win32/Mabezat
Win32/Magistr, variants A and B
Removes the following viruses:
Win32/Magistr.A, Win32/Magistr.B
Win32/Parite
Removes the following viruses:
Win32/Parite
Win32/Prepender
Removes the following viruses:
Win32/Prepender
Win32/Sality
Removes the following viruses:
Win32/Sality
Win32/Tanatos, variants A, H, I and M
Removes the following viruses:
Win32/Tanatos A, Win32/Tanatos H, Win32/Tanatos I, Win32/Tanatos M
Win32/Valla.2048
Removes the following viruses:
Win32/Valla.2048
Win32/Virut
Removes the following viruses:
Win32/Virut
Worm/Lovsan
Removes the following viruses:
Worm/Lovsan

 

 

SERVICES FROM RPC

Antivirus Software

Computer Troubleshooting

Dell Computer Support

Toshiba Computer Support

Other Articles