Home > Storm Botnet Ebbing, Says UC San Diego Analyst

News

Storm Botnet Ebbing, Says UC San Diego Analyst

11/8/2007

An Oct. 20 presentation at the ToorCon hacker conference by Brandon Enright, a computer security researcher at the University of California, San Diego, struck a nerve in the CS community by concluding that the notorious Storm Worm could be losing steam.

"The size of the network has been falling pretty rapidly and pretty consistently," Enright told the conference during his presentation, which was titled, "Exposing Storm."

The Storm worm emerged in January as one of the first pieces of malware to use a P2P network for command and control, Enright said in his presentation, "making it one of the most resilient bots ever." The lack of a centralized command and control has made it highly resistant to countermeasures, he said.

Enright said the extent of the Storm network has been unscientifically reported by media outlets as between 1 million and 50 million bots. "Fortunately, most of these estimates are inaccurate or completely wrong," according to his presentation.

Since July, when a a concerted e-mail attack infected an estimated 1.5 million PCs, Storm has ebbed somewhat.

Enright ascribed this to aggressive work by anti-virus vendors. In particular, Microsoft Corp.'s addition of  Storm detection in September to its Malicious Software Removal Tool put a "measurable dent" in the network, Enright reported.

Read More:


Paul McCloskey is a contributing editor for the Campus Technology group of publications.

Cite this Site

Paul McCloskey, "Storm Botnet Ebbing, Says UC San Diego Analyst," Campus Technology, 11/8/2007, http://www.campustechnology.com/article.aspx?aid=52729

copy text (above) for proper citation



Recommended Reading
  • Sun, Stanford Working To Archive History

    In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.

  • The Quilt Coalition Rolls Out XO Communications for High-Capacity Network Services

    The Quilt, a coalition of 28 regional network organizations, has added XO Communications Services to its authorized vendor list. The Quilt represents 200 universities and thousands of other educational institutions across the United States. With this new relationship, Quilt members can purchase XO's high-speed IP transit and network transport services at competitive rates.

  • Wimba Classroom 5.2 Expands Classroom Capture Support, Adds MP3 Downloads

    At the NECC 2008 conference in Texas this week, Wimba launched a new version of Wimba Classroom, the virtual classroom component of the company's Collaboration Suite. The new 5.2 release expands options for classroom capture and adds a variety of other functional and ease of use features.

  • Automation Chimera: Education Is Not Management

    The lure of automating workflow online so human intervention is minimized is continually reinforced in the minds of higher education administrators by examples of automated campus systems such as financials, student information systems, and other enterprise systems. But what's good for management is not always good for learning.

  • Cognos Releases BI Software for Linux-based IBM System z Mainframe

    Cognos, which IBM acquired in January, has released an update to its business intelligence software that will run on the Linux operating system on IBM System z mainframes. IBM Cognos 8 BI was being developed by the two companies prior to the acquisition, but assimilation of Cognos into IBM accelerated development.

  • Facebook and Collegiality: A Serendipitous Social Niche

    Facebook is a way to greet a colleague as if she or he is on your own campus: a wave at a distance, a hello at the corner burrito place, a honk as you both leave the campus parking lot. Informal collegiality has been extended over the miles.