Free Newsletter
Register for our Free Newsletters
Newsletter
Zones
Access Control
LeftNav
Alarms
LeftNav
Biometrics
LeftNav
Detection
LeftNav
Deutsche Zone (German Zone)
LeftNav
Education, Training and Professional Services
LeftNav
Government Programmes
LeftNav
Guarding, Equipment and Enforcement
LeftNav
Industrial Computing Security
LeftNav
IT Security
LeftNav
Physical Security
LeftNav
Surveillance
LeftNav
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
 
News

Imperva Looks Further Into Botnet Rental Implications

Imperva : 27 October, 2010  (Technical Article)
IT Security company Imperva delves deeper into the Iranian Cyber Army botnet rental intention and answers key questions on what this means in reality
The Iranian Cyber Army has been making news with its decision to sell access to its botnet, Imperva's Senior Security Strategist Noa Bar Yosef answers key questions on this issue below:

1) How much does it cost usually to rent a botnet? What are the factors involved in price?

Bots are used for a very large variety of purposes so its difficult to pinpoint a price. The growing and maintaining work of a Botnet has become just an additional profession in the hacker supply chain of the growing hacking industry. Similar to market competition of the real world, Botnet growers are competing to provide their service. Which means that prices are falling. There are different aspects which are taken into price account of the Botnet hiring: • Size of a Botnet • Type of attack (e.g. spam, DDoS, cred-fetching) • Target (military, private organisations, targeted or widespread) • Geo-location (targeted country, organisation and even language considerations) • Length of attack (one hour of spam, three-day DDoS attack or a monthly membership for phishing sites) • Although a rental is based on a multitude of factors, to give some ballpark figures for some of the more common 'services': : • A 24-hour DDoS attack can be anything from a mere $50 to several thousand dollars for a larger network attack. • Spamming a million emails, given a list, ranges between $150-$200. • A monthly membership for phishing sites is roughly $2,000.

2) Does this move by the ICA surprise you? How common is it for people to build botnets and then sell them off?

No, the move by the ICA is not surprising. Cyber-criminals, just like all criminals, seek different sources of revenue. Botnet growers are continuously advertising their services. What is interesting in the case of ICA is that they were the ones performing the attack. From their point of view, most of their attacks were politically motivated. But they seem to have asked themselves: Why can't we make extra on the side with our infrastructure? These so-called 'ideologists' could be re-investing proceeds from 'commercial' operations to their political objectives and proceed with other attacks as well as further develop other cyber attack resources.

3) From a security standpoint, does this activity make Botnet detection easier or harder? If people are selling groups of bots, doesn't that mean you can stop multiple groups by disrupting the group selling the bots?

A. In general, this activity doesn't impact the detection of botnets. Why? Many of the command and control servers use fast-flux technology, where the server constantly changes, so it is harder to find the 'brain' behind the zombies and take it down.

B. Advertising underground services carries risks of discovery. For example, a criminal in the real-world advertising fake Rolexes: that individual runs the risk of selling to an undercover cop. Similarly a criminal selling illegally obtained online credentials to some Facebook account runs the risk of the forum being tapped into by some authority. Yet these criminal acts proliferate since hackers are not stupid. They use different evasion techniques, secret forums and even a reputation-based system in order to avoid being detected.

4) Some say that smaller botnets are a bigger problem than the larger spamming botnets because the smaller ones tend to be targeted and seek to stay under the radar. Do you agree that that is the case, and is this related to the trend of people selling off portions of botnets?

It doesn't make a difference. Why? A Botnet grower has a large number of computers under his/her control (zombies). He/she rents a certain number of these zombies for different purposes. Each of these rentals together provide a botnet. So botnets range in size but ultimately they can be sourced to the grower. So criminals are not selling portions of their botnet, rather they are renting portions of the computers under their control according to the needs and requirements of the attack requestor.
Bookmark and Share
 
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
 
   © 2012 ProSecurityZone.com
Netgains Logo