Wednesday | 15 October, 2008
Computerworld
Researchers infiltrate Kraken botnet, could clean it out
But they won't disinfect remotely, citing 'pretty big can of worms' as reason
Gregg Keizer 01/05/2008 08:30:47

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

A group of security researchers Wednesday said they have infiltrated one of the world's biggest botnets and can snatch control of compromised machines from the hackers.

But while 3Com's TippingPoint researchers say they have the ability to disinfect the systems by eradicating the malware installed on the hijacked PCs, the company has decided against the move, citing liability issues.

Pedram Amini, who leads TippingPoint's security research group, and Cody Pierce, a security researcher who is also part of that team, collaborated on a weeklong project that started with the idea of verifying the size of the "Kraken" botnet but ended with an ethical quandary.

Pierce created a fake Kraken command-and-control server by reverse engineering the list of domain names found in a captured sample of the bot, and then registered some of the sub-domains Kraken looks for. The server essentially acted as a command-and-control honeypot that waited for connections from PCs infected with the bot.

"Stated simply, Kraken infected systems worldwide start to connect to a server we control," Amini said in a post to a company blog.

The two researchers monitored the incoming communications from Kraken bots for seven days, Pierce said. "We listened and collected statistics for a week, and filtered out [for] the IP addresses and then the systems," he said on the telephone Wednesday." He was able to identify each infected machine by using the malware's encryption key, which was unique across the entire botnet.

The total count for the week: about 25,000 infected machines.

Others have estimated Kraken's size at between 185,000 and 600,000 compromised PCs. SecureWorks' Joe Stewart, who uses the moniker "Bobax" rather than Kraken for the botnet, pegged it at the lower number earlier this month based on an in-depth traffic analysis and bot-fingerprinting project.

In other words, TippingPoint had identified between 4 per cent and 14 per cent of the total Kraken botnet.

But the company's research didn't stop there. Pierce wrote code that would let him redirect infected PCs, or better yet, use the bot's built-in update mechanism -- something most malware includes -- to remove Kraken.

There, however, things got sticky. "This is where we got into the ethical discussion," Pierce said. He and Amini wanted to use that capability to clean out Kraken-infected systems. Their boss, David Endler, the director of TippingPoint's DVLabs, disagreed.

"From our point of view, if someone doesn't do something about bots, they'll just continue on and on," Pierce said. "If you have the opportunity to do something, take it."

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Solve Exchange Mailbox Storage Issues Once and for All

Join industry expert Bob Spurzem and Chuck Arconi of Fox Hollow to discover how to reduce Exchange total storage and keep it at a manageable level. Learn how Exchange storage growth can be contained without sacrificing security and accessibility.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links