Slashdot Mirror


The Coming Botnet Stock Exchange

Trailrunner7 writes "Robert Hansen, a security researcher and CEO of SecTheory, has been gleaning intelligence from professional attackers in recent months, having a series of off-the-record conversations with spammers and malicious hackers in an effort to gain insight into their tactics, mindset and motivation. 'He's not the type to hack randomly, he's only interested in targeted attacks with big payouts. Well, the more I thought about it the more I thought that this is a very solvable problem for bad guys. There are already other types of bad guys who do things like spam, steal credentials and DDoS. For that to work they need a botnet with thousands or millions of machines. The chances of a million machine botnet having compromised at least one machine within a target of interest is relatively high.' Hansen's solution to the hacker's problem provides a glimpse into a business model we might see in the not-too-distant future. It's an evolutionary version of the botnet-for-hire or malware-as-a-service model that's taken off in recent years. In Hansen's model, an attacker looking to infiltrate a specific network would not spend weeks throwing resources against machines in that network, looking for a weak spot and potentially raising the suspicion of the company's security team. Instead, he would contact a botmaster and give him a laundry list of the machines or IP addresses he's interested in compromising. If the botmaster already has his hooks into the network, the customer could then buy access directly into the network rather than spending his own time and resources trying to get in."

4 of 105 comments (clear)

  1. Honeypot? by dhanson865 · · Score: 4, Insightful

    Yeah, interesting concept but the fear would be that the botnet owner would respond by saying knock, knock, the FBI is here (substitute the agency you think applies if the FBI isn't your cup of tea).

    If you do something yourself you know all the players. If you pay someone to do it you don't know if you are walking into a trap.

    disclaimer: I'm not too worried about this as I don't plan on taking either route.

    1. Re:Honeypot? by fuzzyfuzzyfungus · · Score: 5, Insightful

      There is a notable risk for the botnet owner, as well.

      If I am a security guy for some entity that I fear may contain compromised systems, and potentially be the target of more focused attacks, I can use this hypothetical "botnet stock exchange" to verify my suspicions. "So, I'm interested in buying access to hosts within OWN_IP_BLOCK, anybody have some?" If no, breath slightly easier. If yes, I now know which of my hosts need serious inspection and rebuilding.

      Depending on exactly how the exchange is run, basic checks(ie. botnet or no botnet, not necessarily specific hosts) might well be cheap or even free. You don't have much of a market if people can't ask "Is anybody selling X?" and receive a useful answer. More specific answers would probably cost you, as would the services of the sorts of grey hats who work for white hats but can talk to black hats; but there are certainly circumstances where it could be cost effective.

  2. Bad title by Galestar · · Score: 5, Insightful

    How is this a "stock exchange"?

    --
    AccountKiller
  3. Re:I can't believe we are still discussing this .. by Galestar · · Score: 5, Insightful

    You have oversimplified the issue. The root causes are;
    1. Windows / [insert other exploitable program here (ie. Flash/Adobe PDF reader)]
    2. Stupid users

    If your user downloads and runs malware, there's almost nothing your OS can do to stop it. The only way to stop it is to force application signing... but who really wants that?

    So tell me, which OS would you choose that could stop all malware even with stupid users?

    --
    AccountKiller