Privacy Digest

News that can impact your privacy.
Login/Register
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
  • FAQ
  • Wishlists
  • Contact
  • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

RSS Feed + Site Map

Syndicate content
more

Advertisements

GPS Tracking
Search By Phone Number
Hosting
Home Security Systems Toronto
Mercedes-Benz Luxury Cars News
Disk Encryption
spy camera

Popular content

Last viewed:

  • NebuAd shuts up shop, web users rejoice
  • Several Facts about Google and HTTPS
  • Video: Diebold Acknowledging Audit Log Flaws
  • Do Not Call... Forever and Ever and Ever
  • ModSecurity Console: Purpose and Deployment
  • QDN: Do they teach political appointees about the Hatch Act anymore?
  • Symantec CEO Says Web Tracking Files, or Cookies, Make Companies Into Digital Peeping Toms

tags in Topics

Activists Alert Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Software Spin Zone Surveillance Telecommunications Tracking
more tags

Performancing Metrics Blog Statistics
EatonWeb Blog Directory
Listed on BlogShares
View blog authority
Congressional Research
Broadcast Flag

Zombie Computers Decried As Imminent National Threat

Submitted by MacRonin on April 9, 2008 - 1:38pm.
  • Bot- Nets
  • Editorial
  • Exploits
  • Government
  • Hmmm
  • Infrastructure
  • ISP - Internet Service Providers
  • Law Enforcement
  • Privacy
  • Proposed Laws
  • Remember
  • Rights
  • Security
  • Spin Zone

Zombie Computers Decried As Imminent National Threat - Via Threat Level:

SAN FRANCISCO -- Across the world, thousands of home computers have been conscripted into zombie computer gangs that cyber criminals use to spam, attack and defraud others on the net and causing considerable consternation to law enforcement and security professionals alike, who count the so-called botnets as the most vexing net threat today.

Today's botnet herders have hundreds of thousands of computers at their command and use technically sophisticated ways to hide their headquarters, making it easy for them to make millions from spam and credit card theft. They can also be used to direct floods of fake traffic at a targeted website in order to bring down a rival, extract protection money or less frequently, used to make a political point in the case of attacks on Estonia and the Church of Scientology,

Security pros and government officials are now describing the latter attacks, known as Distributed Denial of Service attacks, as serious threats to national security -- despite the fact that's its very clear that DDOS attacks on a public website are just the latest craze in "cyberwar" hysteria.

Hence, the appearance Tuesday of a panel at the RSA 2008 security conference of a panel discussion entitled "Protecting the Homeland: Winning the Botnet Battle," which was marked by a mix of resignation, indignation and post-9/11 rhetoric.

Ronald Teixeira, the executive director of the non-profit National Cyber Security Alliance and the panel's moderator, began the discussion by describing botnets as "one of the largest threats we face on the internet today and they can be used to attack critical infrastructure."

The Department of Homeland Security's representative Jordana Siegel, who works on public awareness at the National Cyber Security Division, echoed the line that botnets were a imminent threat to the nation's security.

Citing on the attacks on Estonia last year by Russian nationalist hackers, Siegel said botnets can "disrupt an internet reliant society," saying that the temporary takedown of Estonian newspaper and government websites "nearly crippled the country's cyber infrastructure." Earlier in the day, Homeland Security chief Michael Chertoff leaned on Estonia as evidence of the need for a federal government "Manhattan Project" for computer security.

Siegel said the DHS is working at fighting the problem, citing the annual October National Cyber Security Awareness month, which she said was helping Americans learn that "all users need to practice safe online behavior."

McAfee's Joe Telafici, a vice president in their security lab, lamented the ease with which botnet herders can abuse domain registration services and the low cost of email, which make the economics of online crime very attractive.

"We are seeing a model that is so economically viable that trying to tell the kids it is a bad thing to do is boiund to fail," Telafici said, suggesting that botnet herders outnumber the 15,000 or so attendees at RSA. "Even if you don't have a computer,you are paying money to someone for the price of cost of dealing with the security ramifications."

FBI agent Matthew Fine cited two recent takedowns of U.S.-based botnets, operations dubbed Bot Roast, as an example of how the FBI is dealing with botnets. Fine declined to speculate, however, on whether the arrests actually put a dent in overall online criminality.

"I get paid to put bad guys in jail," the flat-topped Fine said, but he noted that as soon as one botnet herder was prosecuted another takes his place.  

"It is a boulder coming down the hill and I am trying to keep it from getting to the bottom," Fine said.

Fine hopes Congress will step in with tougher criminal penalties for botnet runners, but noted that judges were now handing out substantial sentences of four to five years in cases brought to them by the feds.

Ira Winkler, a security consultant known for his outspoken ways, countered that this was all just cauterwalling and that if the country really thought that botnets were a real problem, ISPs and individual users would be held responsible for zombie machines.

"The problem is no one is doing anything," Winkler said, proposing that users be fined or blocked if their computer is infected.. 

"Guess what? If your system has a bot, on it you don't get on the internet," Winkler said. 

"We need to hold people responsible when they present an imminent threat to other people," Winkler said to wide applause from the audience.. He contrasted the lack of computer regulation to those preventing unsafe cars from being on the roads.

 Sparing no target, Winkler went on to ridicule DHS's awareness efforts as useless and argued that the highest levels of government don't care about computer crime, citing the ability of a Russian cyber-criminal group known as the Russian Business Network to remain free.

"When they start putting the RBN in jail, then I will be impressed," Winkler said, noting that would require the feds to put pressure on the Russian government to stop protecting the gang, not an easy task. 

Still, Winkler argues, that's doable with political will.

"When the U.S. government wants to get things done, they know how to put people in jail."

So what really is the threat to the so-called Homeland from zombie computer armies?

When asked by this reporter, the panel came to a split decision.

"Terrorism with botnets is overrated," McAfee's Telafici said. "But if you are looking at the economic burden of botnets, we could probably do without it."

Winkler suggests that botnets could be used in tactical small attacks, including perhaps some minor power outages.

DHS's Siegel defended the use of overheated rhetoric, saying that temporarily unavailable government or financial websites would erode public confidence.

Missing from the panel discussion was any in depth talk about real solutions.

For instance, ISPs can easily learn or be told which of their customers has an infected computer, but due to the customer support costs of cutting off a customerr for running a dirty machine, they tend to do little.

Also not talked about are changes in internet governance that punish known domain sellers and ISPs that favored by onlne criminals for their lax policies. 

See Also:

  • US To Pitch 'Phase One' of Net Monitoring Plan at RSA
  • Report: Cybercrime Stormed the Net in 2007
  • Russian Hosting Firm Denies Criminal Ties, Says It May Sue Blacklister
  • FBI Cracks Down (Again) on Zombie Computer Armies
  • DDoS Packets are Two Percent of Net Traffic, Report Says
  • US Has Launched a Cyber Security 'Manhattan Project,' Homeland ...
  • Estonia's lesson for "cyberwar" fighters: Learn digital crowd control
  • 'Cyberwar' and Estonia's Panic Attack
  • Estonia 'Cyberwar' Wasn't
  • Massive Wave of Estonia Cybarmageddon Debunking Begins
  • ISP Seen Breaking Internet Protocol to Fight Zombie Computers ...

(Read Original Article - Via Threat Level.)


Bookmark/Search this post with:
  • Delicious Delicious
  • Digg Digg
  • Reddit Reddit
  • Google Google
  • Yahoo Yahoo
  • Technorati Technorati
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • A Remedy for Every Wrong? Why We Need a Consistent Privacy Act
  • Give Me My Health Data!
  • CDT, EFF and PK File Brief in Ringtones Case
  • Pirate Bay 2.0: Pay Pirates to Become Consumers
  • Judge Acquits Lori Drew in Cyberbullying Case, Overrules Jury
  • Apple patching serious SMS vulnerability on iPhone
  • Enter the Advertisers - self-regulatory principles ?
  • Out of business, Clear may sell customer data
  • TSA asked to ensure safety of customer data after Clear closing
  • Several Facts about Google and HTTPS
more
Compilation © Copyright 1997-2009 Paul Hardwick, with Web Hosting provided by MacRonin.com.