Home > Windows Security All-in-One Guides > Microsoft Security Threats > Malware > Spyware, bots and Trojans > The bot invasion in Windows
All-in-One Guides: Microsoft Security Threats:
EMAIL THIS
 START   MALWARE   MALWARE REMOVAL   MALWARE PREVENTION   
Malware


Spyware, bots and Trojans
<< PREVIOUS | NEXT >>: Anatomy of the Blue Pill attack
 TIPS & NEWSLETTERS TOPICS 

VULNERABILITY/AUTHENTICATION TIPS FOR WINDOWS

The bot invasion in Windows


Tony Bradley, Contributor
07.19.2006
Rating: -4.67- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


It sounds like it could be an upcoming movie release -- maybe a knock-off of War of the Worlds. Unfortunately for home computer users and company security administrators alike, this bot invasion is real and the first wave has already landed.

In its original form, a bot is not malicious software. Bot code was created to automate the maintenance and administration of IRC (Internet Relay Chat) channels. Eventually though, more malicious developers figured out that bot code could also be used to quietly infiltrate unsuspecting computer systems and provide a means of hijacking or controlling those machines to perform other malicious tasks.

Bot code makes its way onto computer systems in a variety of ways. Users that visit IRC chat rooms or Web sites of a questionable nature are at a higher risk of becoming infected by bots. Some bots, such as the variants of Agobot (an IRC-controlled backdoor with network spreading capabilities), also spread themselves in the form of a network share and peer-to-peer file-sharing network worm.

The bot threat

Computer systems that become compromised by bot code typically initiate communication with an IRC channel to register themselves and announce to the IRC channel that the computer is available. At that point, the computer essentially lays dormant, awaiting commands from an attacker to tell it what to do next.

Hundreds of thousands, and possibly millions, of computers are compromised by bot code. These computers are also referred to as "Zombies" because of the way they sit in a dormant state until they receive a command to rise from the dead and attack.
Bots in Windows

Malware removal handbook

Beating back the bots

Botnets, or collections of bot-infected systems, are maintained on underground lists and are bought, sold and traded by malicious hackers. By activating the dormant zombies and issuing commands for them to execute certain actions, a zombie army encompassing thousands of machines can be used to initiate a denial-of-service (DoS) attack against a specific Web site, start spreading a new virus or worm threat or generate millions of spam email messages that can't be traced back to their true source.

Defeating the bots

Traditionally, bots have primarily compromised or impacted home computer users. However, bot code and botnets are a rising threat to corporate networks as well. For the Internet as a whole, bot incidents have spiked in the last three months to four times what they were the previous quarter, according to McAfee. To keep your computer from joining the ranks of the cyber-undead and protect your network from being taken over by a botnet, follow these steps:

  • Block unsolicited inbound traffic at your perimeter firewall: Even if computer systems inside the network are compromised, they can't be activated if the attacker can't communicate with them.
  • Run up-to-date antivirus software: Known bot threats are detected and removed by antivirus software products. Performing periodic scans with up-to-date antivirus software can locate and remove most bot infections.
  • Keep computer systems patched: Bots, like other malware, often exploit unpatched vulnerabilities in order to propagate and compromise vulnerable systems. Patched systems provide less opportunity for infection.
  • Use IDS or IPS monitoring: An intrusion detection or intrusion prevention system running on the internal network can identify suspicious activity and alert you or take action to halt it.
  • Block outbound traffic on port 25: Only known email servers should be allowed to distribute SMTP email traffic on your network. Blocking outbound SMTP traffic from unknown email sources can help stop the spread of many malware threats and prevent computers on the internal network from being used as spam distribution points.

These are certainly not unusual preventive measures, but the nature of bots and botnets requires specific awareness and attention from Windows security professionals. A bot could be lurking just under the surface, ready to spring into action at the request of a malicious hacker. Only an organized effort can help to mitigate the threat of bots.

About the author: Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. He is recognized by Microsoft as an MVP in Windows Security, and he is the About.com Guide for Internet / Network Security, providing a broad range of information security tips, advice, reviews and information. Bradley is co-author of Hacker's Challenge 3, McGraw-Hill Osborne Media, and author of Essential Computer Security, Syngress Publishing. He also contributes frequently to other industry publications. For a complete list of his freelance contributions, visit S3KUR3.com.

Rate this Tip
To rate tips, you must be a member of SearchWindowsSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>: Anatomy of the Blue Pill attack
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Virus/Worm Protection
Determining the proper Microsoft malware removal tool
Run third-party malware detection tools in Windows
How can I run third-party antivirus software?
Malware prevention and detection webcast series
Antivirus failing across multiple Windows XP accounts
A proper set of antivirus tools?
Unjoin a domain to avoid a virus
Free tools defend against malicious Web sites in the enterprise
Forefront beta secures SharePoint collaboration
Symantec fixes Backup Exec flaw

Spyware Protection
PatchGuard defends against rootkits in Windows Vista
How did a rootkit get on my Windows machine?
Determining the proper Microsoft malware removal tool
Malware prevention and detection webcast series
Rootkit and malware detection and removal guide
Preventing malware with tools, patches and education
A proper set of antivirus tools?
Free tools defend against malicious Web sites in the enterprise
Are two antispywares better than one?
Controlling Web surfing with Content Advisor
Spyware Protection Research

Intrusion Prevention Systems
Cross-site Scripting 102: How to defend against cross-site scripting
Buffer overflows can be prevented by GS cookies
Malware prevention and detection webcast series
Preventing malware with tools, patches and education
Can an antivirus program stop phishing attacks?
Wireless network security testing
Step 3: Application-level filters
Comparing rootkit detection tools
Checklist: 11 things to do after a hack
Social engineering tactics for Windows users

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts