427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet84/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   80   81   82   83   84   85   86   87   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Alternative Botnet C&Cs • Chapter 3
93
427_Botnet_03.qxd 1/8/07 11:56 AM Page 93


Solutions Fast Track
Historical C&C Technology as a Road Map
In the beginning, bots and botnets indeed were legitimate tools used
mainly for functional purposes, such as maintaining an IRC channel
open when no user is logged in or maintaining control of the IRC
channel.
As the technology advanced, control channels became more
sophisticated. As an example, a chat channel would be used but it
would be password protected (a key would be set on IRC).
As useful as IRC is to the people running botnets, there are some
inherent threats for them.
DNS and C&C Technology
IRC is built in a fashion that several servers can be inter-linked to
form a network of hubs, branches, and leaves.
Until 2002, DNS was manifested in two main uses: domain names
and multihoming. Both of them were as facilitators to finding the
botnet C&C as well as to keeping it alive on the Internet, before
connection to the actual C&C server.
Reporting, which results in a “takedown” for a DNS record, is often
more difficult than a compromised IP address. Several such RRs
could be put in place for the same IP address, or different ones,
making the C&Cs much more robust.
www.syngress.com
94
Chapter 3 • Alternative Botnet C&Cs
427_Botnet_03.qxd 1/8/07 11:56 AM Page 94


Q: 
What is an alternative botnet C&C?
A: 
A botnet C&C is the command and control server for a botnet. As such,
an alternative C&C would mean that a different control channel exists.
Q: 
How can these alternative C&Cs be of use?
A: 
An alternative control channel can either be used as the main C&C,
simply with a different technology than what is common today, or used as
a secondary one for if the main one fails. For the first option, using a dif-
ferent technology would refer to any technology other than what is
common and that would often mean IRC servers. For the second option,
a secondary C&C would often be necessary because the botnet relies on a
serious failure point, which is the C&C. If the C&C is no longer available
for any reason, the botnet is effectively lost.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   80   81   82   83   84   85   86   87   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish