Storm Dismantled at USENIX LEET Workshop
An anonymous reader writes "The USENIX LEET workshop held earlier this week in San Francisco offered neat insights into the Storm botnet, including two papers showing the difficulty of accurately measuring the botnet's size, and one on the way it conducts its spamming campaigns (down to the template language used). There was a bunch of other cool work too, so check out the papers."
It should be http://www.usenix.org/event/leet08/tech/
Test your net with Netalyzr
Is "dismantled" really the right word? Shouldn't it be "vivisected", since the botnet is still running?
Dismantled implies that it's shut down. Last I heard, it was still running, and sub-botnets (tropical depressions?) were being sold. Botnet franchising, if you will.
According to the paper, the creators already make changes to obscure the botnet on a frequent basis. This paper won't make them any more paranoid than they already are.