NETI@home Data Analyzed
An anonymous reader writes "The NETI@home Internet traffic statistics project (featured in Wired and Slashdot previously) has a quick analysis on the malicious traffic they observed. It's a rough world out there." Perhaps not suprising, but still disheartening, the researchers find among other things that a large portion of typical end-user traffic consists of malicious connection attempts.
That's what we need to know.
Linux - Because Mommy taught me to Share.
Considering these malicious programs aren't following any kind of 'standard' to reduce bandwidth utilization when checking over entire subnets of IPs that have been checked by 100000x other copies of the virus, it doesn't suprise me one bit.
It would be like setting up a massive feedback loop on a mail server. When user X gets message X, he passes message X to user Y, who upon receiving message X sends it back to user X.
Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
Does anything like this exist already? It would be nice if I could filter, say, ssh traffic coming from "known" naughty sites, and report sites that portscan me, though probably I should look at using smartcards or something more secure at this point. I can't just restrict the ssh port at the firewall, since people could be coming in from pretty much anywhere because of travel to remote sites. Aside from complaining to upstream providers (which so far has yielded zero responses) when I see people banging away at ssh, I don't see much else I can do.
I Am My Own Worst Enemy
Yeti@home has yet to yield conclusive results.
Ignoring all complaints about Windows, the root of the problem goes back to having access to the network in the first place. If ISPs would spent a few bucks on implementing passive traffic analyzers to search for the viral/trojan patterns and null route offenders, we'd clean things up pretty quick. Why do we have all these piracy probes going on to sue people and no infected probes going on to cut people's access?
Now, stepping back to the Windows complaints...wouldn't the ISP turning off your access motivate you to get a BASIC education in computing and maintain your PC?
To make an analogy, in most states you need to have your car inspected (and some require emissions inspection, too). PUBLIC roadways means you share it with other people...an unsafe car affects more than just you. When you're connected to the net, your PC affects everyone else. I'm not suggesting the ISPs make an inspection system or a law passes to force ISPs to monitor traffic, but the same logic applies....someone should be doing checkups and flagging the offenders.
...they will realize that there isn't anything more malicious than the traffic from Slashdot.
You can't impose a standard upon viruses. What will you do if a virus doesn't follow the standard? Find the author and punish them unless they fix it and release a new version that fully supports the standard?
The only way viruses will ever get standards is if the authors agree that they will get a considerable benefit by working together. I can't see that happening.
I'll probably be modded down for this...
Its insane the ammount of bandwidth this is sucking up (i remember a time when virus's and worms were relativly well programed, still as bad but less collaterol dammage).
I would like to see more ISP isntead of suplying basic DSL modems with those overpriced sign up deals but instead a proper firewall/router/Dsl modem.
This would save us all alot of pain in the long run .
The only things certain in war are Propaganda and Death. You can never be sure which is which though
I'm pretty sure internet connectivity is neither a privilege nor a right. It's just a service, plain and simple. You pay ISP, they provide internet connectivity. You don't pay, you don't get internet. No rights or privileges involved.
"Those willing to give up a little security by using a little obscurity deserve neither security nor root privileges".
-Benjamin Franklin
Sadly, while some customers might get motivated to learn something, others would just be motivated to switch ISPs. Which costs the ISPs money, which means that they won't do it.
At least such is their thought process as often presented. I suspect it's bad cost-benefit analysis; if your dumber customers leave, it's probably a net win for you. Smarter customers mean less bandwidth (at least, they don't act as spam zombies maxing out the bandwidth) and fewer tech support hours explaining how to fix the cup holder.
The big players (AOL, Comcast) are the best targets for this logic, but they live for those left-side-of-the-bell-curve customers. They're the "default" ISPs that people get because they're so readily available, so they get all the customers who don't know better. (Hell, I don't know better; I use Verizon for my DSL but I don't let them do anything but provide me bits.)
So AOL and Comcast are in a bit of a bind; they don't want these customers, but they don't want to lose them, either. I think that they're probably going to have to use gentle persuasion to say, "Hey, it looks like you've a spam zombie. Please call your cousin's best friend to clean the crap off your computer again and give you a stern talking-to. And please stop downloading Bonzi Buddy."
You really should be using RSA or DSA keys instead of passwords. Hardly a day goes by that my systems don't get at least one script-kiddie SSH password guessing scan. Since I'm requiring keys for authentication, they're wasting their effort; if someone manages to crack a public key, we have far worse problems than password guessing.
Oh, no! You have walked into the slavering fangs of a lurking grue!
The ISP KNOWS the physical addresses of the cable/dsl modem a home user has. It's not like the ISP has no idea which ip addresses are home user or account is using at any given time. How do you think they can reliably (for the most part) identify people for the likes of the RIAA when they ask. Likewise, with modern hardware and software its a pretty trivial task for an ISP to turn your internet access down to a crawl or off with the click of a button. They can do this, they just don't want to.
Maybe it would be a good idea to throttle the users down to a bare minimum and redirect all http traffic to a gateway page to tell them they have a problem with their computer they need to correct. It seems to work for wireless access points in hotels/airports/coffeeshops. Why can't big ISPs do the same thing?