Watchdogs set up 'honey pots' to trap hackers


Recommended Posts

WASHINGTON: The number of zombies out there lurking on desktops is growing. And to fight them, a band of internet security experts is using a ‘neighbourhood watch’ approach and every honey pot it can muster.

The Shadowserver Foundation’s world-wide daily count of zombie computers, which are infected with viruses and bent to malevolent purposes, doubled this month to 3,00,000 from 1,50,000 a year earlier. The spurt comes from more hackers linking machines to form botnets, networks they use to steal identities, attack Web sites and sell pilfered email addresses to spammers.

Internet crimes cost consumers and businesses $239 million in 2007, up 20% from the year before, according to US government data. Botnets are growing in popularity and sophistication as tools for hackers, and Shadowserver’s research helps law enforcement and security companies such as McAfee identify emerging threats.

“It’s becoming an increasingly common mechanism the bad guys are using,” said John Pescatore, an analyst at researcher Gartner in Ashton, Maryland, who used to build secure computer systems for the US Secret Service. Shadowserver is “like neighbourhood watch groups that are a great help to local police.”

Working in shifts around the clock, Shadowserver’s 10 members set up ‘honey pot’ computers designed to attract malicious software.

They monitor zombie machines and hackers, and report their findings to law enforcement and internet-service providers such as Philadelphia-based Comcast. In the weeks leading up to Georgia’s military conflict with Russia in August, Shadowserver was among the first to report that hackers attacked Georgian president Mikheil Saakashvili’s website, taking it down for 24 hours. The hackers used a botnet to swamp the site with requests.

“We see dozens of such attacks on a daily basis,” Shadowserver director Andr? DiMino, who co-founded the group almost four years ago, said in an interview.

Such zombie-computer armies began as the work of lone hackers and evolved into sophisticated tools used by organised crime groups, said DiMino, who goes by the online name SemperSecurus. Dealing with bot-infected computers cost organisations an average of almost $350,000 this year, according a survey by the Computer Security Institute, an industry group that promotes computer-security education.

“Botnets pose a significant risk because they’re the Swiss Army knife of malicious code,” said Nicholas Ianelli, an analyst at the CERT Coordination Center, which studies internet security as part of Carnegie Mellon University’s Software Engineering Institute. “They can do so many things with one compromised host.”

As of August 26, Shadowserver had detected more than 157,000 botnet attacks on websites in 105 countries this year. DiMino said the group is probably finding only a small fraction of botnet activities.

The average daily number of active bot-infected computers rose 17% to 61,940 from the first half of 2007 to the second, according to Symantec, the biggest maker of security software. Arbor Networks, which often works with Shadowserver, detected more than 1,800 active botnets per day in September, up as much as 20% from a year ago, said senior security researcher Jose Nazario.

“We’ve been tracking botnets for years and we’re seeing a dramatic rise,” Nazario

said. Lexington, Massachusetts-based Arbor provides securit

y for more than 300

companies including Yahoo! and Verizon Communications’ business unit.

A year ago, the Federal Bureau of Investigation said an investigation of botnets, dubbed Operation Bot Roast, uncovered more than 1 million infected computers and more than $20 million in economic losses from crimes related to botnets.

Shadowserver’s members spend anywhere from 5 to 40 hours a week tracking internet-security threats. DiMino, a native of New York who now lives in New Jersey, said Shadowserver’s members are not vigilantes and don’t ‘hack the hackers,’ as some other volunteers do.

“It gets us pretty jazzed when we can see that things we’ve worked on have had a tangible result in internet safety,” he said. “That’s really a key motivator for all of us.”

In February, the group said it uncovered an attack on 32 gambling sites, including one run by PartyGaming, the owner of the PartyPoker.com website.

Organisations such as Shadowserver are ‘another weapon in our armoury’ against hackers, supplementing PartyGaming’s own investment in internet security, spokesman John Shepherd said. Shadowserver appears to be “very good at what they do,” he said, declining to comment on the February report.

While Shadowserver wants to publicise its findings, group members keep low profiles — and not just because of the potential for retaliation from hackers who don’t want their botnets exposed, DiMino said.

Source

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Save 66% on a MagTag Ultra Slim Tracker Card for Apple or Android by Steven Parker Never Lose Anything Again with MagTag Today's highlighted deal comes via our Gear + Gadgets section of the Neowin Deals store where you can save 66% on this MagTag Ultra Slim Tracker Card - Works with Apple Find My App. Keep track of your world with MagTag, a sleek, ultra-slim, reliable tracker that’s built to help you safeguard your most important items. In the size of a credit card, just 1.5mm thick, you can slip MagTag easily into your wallet, backpack, passport pouch luggage…etc. Integrated seamlessly with Apple’s FindMy app, MagTag offers precise real-time global tracking, instant left-behind alerts, loud location beeping, and a long-lasting rechargeable battery. Whether you’re heading to work, on vacation, or simply running errands, MagTag ensures you never lose what matters most. No item left behind Precision Global Tracking: Works seamlessly with the Apple FindMy app, providing real-time tracking anywhere in the world, powered by the vast Apple network. Ultra Slim Design: At just 1.5mm thick and the size of a credit card, MagTag slips easily into your wallet, passport pouch, backpack, or luggage. Instant Alerts: Receive notifications the moment you leave behind your valuables, and locate them easily with a loud beeping sound. Versatile Attachment Options: With a built-in keyring hole, attach MagTag to keys, ID lanyards, kids’ bags, or name tags for easy access and protection. Long Battery Life & Wireless Charging: Lasts up to 5 months on a single charge and can be easily recharged with any Qi wireless charger. Durable & Waterproof: IP68 waterproof and dustproof built to withstand your adventures, perfect for vacations and everyday use, no matter where life takes you. Specs Color: Black Materials: ABS Dimensions: 0.05" x 3.35" x 2.13" (1.5mm x 85mm x 54mm) Ultra-slim Apple FindMy App Built-in keyring hole Battery life: up to 5 months Charging: Qi wireless IP68 rating (waterproof, dustproof) Manufacturer's 90-day warranty Good to know Ships to US Expected Delivery: Expected Delivery: Jun 23 - Jul 2 All sales final. This item is excluded from coupons. Here's the deal: This MagTag Ultra Slim Tracker Card (for Apple or Android) normally costs $59.99, but you can pick it up for just $19.99 for a limited time - that represents a saving of $19. For a full description, specs, and shipping info, click the link below. MagTag Ultra Slim Tracker Card now just $19.99 (was $59.99) Get the two-pack and save 70% Ships only to Contiguous US Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I cannot believe this is a news post from Neowin. This should be embarassing, coming from a "senior editor". Is it your first day using Windows?! Maybe it's time to find a new Windows news site.
    • It's from having Core Isolation enabled in Windows security settings, which is a good thing!  It's letting you know it's not loading the Bonjour module as it's not signed in a way it would prefer. Bonjour was most likely installed along with iTunes. Feel free to disable that message using the checkbox.
    • I'm looking forward to starting over online. I have no reason to keep all the money, cars, rank after 13 years. Now if I can just move my character itself and nothing else. I would be fine with that. But I doubt they would do a setup that way.
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      586
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      73
    4. 4
      Michael Scrip
      66
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!