North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: mitigating botnet C&Cs has become useless

  • From: Arjan Hulsebos
  • Date: Tue Aug 08 10:05:02 2006
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=IC/g/NgdiZZCW5HwTgffxx4yuHDzJ+w68CTxYYDv+s9ltP1KY/uXC2hjta2Z8Ru6+uhoTxvElNz92g2V/eR5SM4vLOJMfwYTpRaETB1LW9oVtcpGYpqGV5oyfonRoug/ujmOzts7WKrZ53str8M2D7ABFmjq+W2N7n6dEAoxRkM=


On Sat, 5 Aug 2006 17:17:27 -0400 (EDT), Sean Donelan typed:


Railroads have the railroad police. The Post Office has postal
inspectors.  Do we want to give ISP security the power to arrest
people?

We (ISPs) already do have that power, we can disconnect misbehaving subscribers. And in cases like this, we should keep them off the 'net until they've cleaned up their PC.

And besides doing that, we should educate our subs on how to properly
maintain their PC (installing and keeping up-to-date antivirus
software, patch the OS on a regular basis, you know the drill).

I don't think hunting down the botnet operator is going to solve the
problem. If I were to setup a botnet, I'd have many layers of machines
(in as many different countries as possible) and protocols between me
and the drones that do my dirty work.

So, yeah, it can be solved (OK, to a large extend) by manpower, but as
someone else already mentioned, it's a case of ROI. And, as usual,
security is only costing you money.....

Gr,

Arjan H