The Coming Botnet Stock Exchange
Trailrunner7 writes "Robert Hansen, a security researcher and CEO of SecTheory, has been gleaning intelligence from professional attackers in recent months, having a series of off-the-record conversations with spammers and malicious hackers in an effort to gain insight into their tactics, mindset and motivation. 'He's not the type to hack randomly, he's only interested in targeted attacks with big payouts. Well, the more I thought about it the more I thought that this is a very solvable problem for bad guys. There are already other types of bad guys who do things like spam, steal credentials and DDoS. For that to work they need a botnet with thousands or millions of machines. The chances of a million machine botnet having compromised at least one machine within a target of interest is relatively high.' Hansen's solution to the hacker's problem provides a glimpse into a business model we might see in the not-too-distant future. It's an evolutionary version of the botnet-for-hire or malware-as-a-service model that's taken off in recent years. In Hansen's model, an attacker looking to infiltrate a specific network would not spend weeks throwing resources against machines in that network, looking for a weak spot and potentially raising the suspicion of the company's security team. Instead, he would contact a botmaster and give him a laundry list of the machines or IP addresses he's interested in compromising. If the botmaster already has his hooks into the network, the customer could then buy access directly into the network rather than spending his own time and resources trying to get in."
Yeah, interesting concept but the fear would be that the botnet owner would respond by saying knock, knock, the FBI is here (substitute the agency you think applies if the FBI isn't your cup of tea).
If you do something yourself you know all the players. If you pay someone to do it you don't know if you are walking into a trap.
disclaimer: I'm not too worried about this as I don't plan on taking either route.
How is this a "stock exchange"?
AccountKiller
So you have just hired a bot master. How do you pay them? You know they are dirty hackers, so it isn't like you would just give them your credit card number or Pay Pal account. Maybe the guy just wakes up and finds a crate of Jolt and Hot Pockets on his doorstep.
"I'm not a quack, I'm a mad scientist! There's a difference." - Dr. Cockroach
You have oversimplified the issue. The root causes are;
1. Windows / [insert other exploitable program here (ie. Flash/Adobe PDF reader)]
2. Stupid users
If your user downloads and runs malware, there's almost nothing your OS can do to stop it. The only way to stop it is to force application signing... but who really wants that?
So tell me, which OS would you choose that could stop all malware even with stupid users?
AccountKiller