Sunday | 23 November, 2008
Researchers infiltrate Kraken botnet, could clean it out
But they won't disinfect remotely, citing 'pretty big can of worms' as reason
Gregg Keizer 01/05/2008 08:30:47

A group of security researchers Wednesday said they have infiltrated one of the world's biggest botnets and can snatch control of compromised machines from the hackers.

But while 3Com's TippingPoint researchers say they have the ability to disinfect the systems by eradicating the malware installed on the hijacked PCs, the company has decided against the move, citing liability issues.

Pedram Amini, who leads TippingPoint's security research group, and Cody Pierce, a security researcher who is also part of that team, collaborated on a weeklong project that started with the idea of verifying the size of the "Kraken" botnet but ended with an ethical quandary.

Pierce created a fake Kraken command-and-control server by reverse engineering the list of domain names found in a captured sample of the bot, and then registered some of the sub-domains Kraken looks for. The server essentially acted as a command-and-control honeypot that waited for connections from PCs infected with the bot.

"Stated simply, Kraken infected systems worldwide start to connect to a server we control," Amini said in a post to a company blog.

The two researchers monitored the incoming communications from Kraken bots for seven days, Pierce said. "We listened and collected statistics for a week, and filtered out [for] the IP addresses and then the systems," he said on the telephone Wednesday." He was able to identify each infected machine by using the malware's encryption key, which was unique across the entire botnet.

The total count for the week: about 25,000 infected machines.

Others have estimated Kraken's size at between 185,000 and 600,000 compromised PCs. SecureWorks' Joe Stewart, who uses the moniker "Bobax" rather than Kraken for the botnet, pegged it at the lower number earlier this month based on an in-depth traffic analysis and bot-fingerprinting project.

In other words, TippingPoint had identified between 4 per cent and 14 per cent of the total Kraken botnet.

But the company's research didn't stop there. Pierce wrote code that would let him redirect infected PCs, or better yet, use the bot's built-in update mechanism -- something most malware includes -- to remove Kraken.

There, however, things got sticky. "This is where we got into the ethical discussion," Pierce said. He and Amini wanted to use that capability to clean out Kraken-infected systems. Their boss, David Endler, the director of TippingPoint's DVLabs, disagreed.

"From our point of view, if someone doesn't do something about bots, they'll just continue on and on," Pierce said. "If you have the opportunity to do something, take it."

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Know thy self: Reduce costs, secure data and ensure compliance with identity management

Midsize businesses cannot operate effectively without the ability to control access to their networks and business systems. A strong identity management platform can play the role of gatekeeper and guardian of business intelligence and information. Read on to discover how you can create a strong identity management plan to protect your business.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links