News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Data Security
Average Rating:
Rate this article:  
Honeynet Offers Tools To Detect and Contain Conficker Honeynet Offers Tools To Detect and Contain Conficker
By Jennifer LeClaire
March 31, 2009 1:50PM

    Bookmark and Share
As the Conficker hysteria builds, the Honeynet Project has outlined methods to contain and remove Conficker, using the way it patches Microsoft Windows. Honeynet has also developed a scanning tool to detect Conficker in coordination with Dan Kaminsky. Andrew Storms of nCircle said the public has finally realized the threat posed by botnets.
 



As the clock counts down to April 1, the Conficker hysteria is only growing worse. CBS's perennial 60 Minutes television broadcast ran with the headline The Internet is Infected on Sunday night.

Lesley Stahl went on to report to millions of viewers that malicious computer hackers have been creating more weapons that they plant on the Internet -- and the problem is growing. She called Conficker one of the most dangerous threats ever, infecting about 10 million computers worldwide.

Conficker earned its reputation. The worm, also known as Downadup, first appeared in late November, exploiting a vulnerability in Microsoft Relevant Products/Services Windows Relevant Products/Services to spread unhindered on local area networks. Its goal so far has been to install rogue software on infected computers.

Microsoft issued a patch for the vulnerability, but users who haven't installed it are open to infection as the worm spreads through portable USB flash drives. Malware authors are expected to set the wheels in motion to launch the next variant of Conficker on Wednesday.

Honeynet Project Responds

"As you know, bad things are going to happen on April 1st: People will be sending out e-mails to their friends, telling silly jokes and putting MTAs (mail transfer agents) under a higher load," said Lance Spitzer, CEO of the Honeynet Project, an international nonprofit research organization that aims to improve Internet security.

"Besides that (but not quite that bad), Conficker will activate its domain-name-generation routine to contact command-and-control servers," he said. "We have been researching this piece of malware recently, with a focus on how to detect Conficker-infected machines."

The Honeynet Pot Project has just released a paper called Know Your Enemy: Containing Conficker. The paper presents several potential methods to contain Conficker, taking advantage of the way the worm patches infected systems, which the group said could be used to remotely detect a compromised system Relevant Products/Services. The paper also demonstrates several methods to detect and remove Conficker locally, and a potential vaccination tool is presented.

The Honeynet Project has also released a new scanning tool for detecting Conficker. The tool was developed in coordination with Dan Kaminsky, a security researcher well known for his work on DNS cache snooping. It was Kaminsky who discovered a fundamental flaw in the DNS protocol last July.

Raising Public Awareness

"This is not the first really big worm," said Andrew Storms, director of security operations for nCircle. "The reason for the hysteria and panic around this worm is because the public has finally realized that worms are connected to botnets."

Storms said this is the most technically interesting worm he's seen because of the way it spreads, as well as the connections mechanism, its encryption types, and the methods it uses to contact its command-and-control servers. As he sees it, this sophistication is definitely contributing to the overall level of public fear.

"While the work the Honeynet Project and Dan Kaminsky have done is helpful to security teams, most enterprises are already using a patch-management process and following industry best practices," Storms said. "They are likely already patched and protected from a Conficker infection."
 

Tell Us What You Think
Your Comment:



Advertisement


 Data Security
1.   China Busted Hacker-Training Site
2.   FBI Tackles Haiti-Relief Scams
3.   Patch Tuesday Will Tie MS Record
4.   Google Apps Controls Mobile Devices
5.   Torrent Traps Used To Harvest Logins


advertisement
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Google Attack Highlights Black MarketGoogle Attack Highlights Black Market
Paying for bug info is hotly debated.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.