On GameFAQs: The top 10 strangest game bosses
BNET Business Network:
BNET
TechRepublic
ZDNet

July 30th, 2007

Can Trend Micro's botnet identification service make a difference?

Posted by Ryan Naraine @ 9:37 am

Categories: Botnets, Browsers, Data theft, Exploit code, Firefox, Google, Hackers, McAfee, Metasploit, Microsoft, Passwords, Patch Watch, Pen testing, Punditocracy, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Symantec, Viruses and Worms, Vulnerability research

Tags: Network, Internet Service Provider, Bot, Ryan Naraine

Trend Micro rolls out botnet identification serviceTrend Micro today rolled out its SecureCloud software-as-a-service platform with a new Botnet Identification Service (BIS) to help find botnet command-and-control servers and block communications between them and the zombie PCs they control.

Geared towards ISPs and enterprise customers, the botnet ID service can be used to block communication to/from command-and-control servers; prevent bots from launching spam and crime-related attacks; deliver real-time updates directly to routers and network systems; and allow bot-infected PCs to continue to access other Web sites.

The approach by Trend Micro to deliver this as a service — pricing for 500,000 users is 9 cents per user — is hardly unique (Cloudmark, Arbor Networks and others are already delivering botnet mitigation products).

[ SEE: ‘Operation Bot Roast’ nets million-strong botnet operation ]

While it does help businesses, and particularly ISPs, to deal with the out-of-control botnet scourge, there’s a feeling that many service providers can’t be bothered to spend money on botnet mitigation for end users.

Last October, while writing a cover piece for eWEEK on the battle to cope with botnet-related crime, I got the feeling from talking to those in the trenches that this battle is already lost — mostly because the smaller ISPs see no ROI associated with mitigating bot-infected machines.

Worse, even if an end user machine is cleaned of bots or removed from a particular botnet, they are routinely reinfected or moved to join a different zombie army.

[SEE: Botnet herders pounce on Windows DNS RPC flaw ]

Take a look at these botnet command-and-control statistics from the Internet Security Operations Task Force (ISOTF) to get a sense of how the mitigation effort struggles with network operator bureaucracy.

Amidst the stagnation and bureaucracy, botnet herders are becoming smarter about avoiding command-and-control takedowns. The recent appearance of fast-flux DNS in botnets points to a new layer of sophistication in these crime networks and confirms ongoing fears that the botnet battle has been lost for good.

Trend Micro’s new service may provide some respite for those willing to pay but don’t look for it to make a serious difference in the larger battle.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Talkback

Add your opinion

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
The more you simplify, the more you save
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
Learn more >>
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here