Malware in Popular Networks Dmitry O. Gryaznov
The Big Change ► Mostly viruses, few trojans ► Obvious destructive or annoying payload ► Mischief and vandalism ► Nothing gained but “glory” ► Mostly non-replicating malware ► Trying to stay inconspicuous ► Theft and control ► Monetary gains ThenNow
Malware “Highways” ► ► Usenet ► Internet Relay Chat (IRC) ► Peer-to-peer (P2P) ► Instant Messaging (IM)
Usenet ► Since early 1980s ► Over 100,000 newsgroups ► Millions of users ► Over 2 Terabytes daily ► Mostly binaries – video, audio, software
Top Ten Malware Detections in Usenet in 2005 BackDoor-AZV46963 W32/Spybot.worm.gen.b 4876 BackDoor-CQZ1381 MultiDropper-DC183 W32/Kelvir.worm.gen75 BackDoor-ACH72 BackDoor-Sub7.svr44
Internet Relay Chat (IRC) ► Since early 1990s ► Dozens of networks (EFNet, DALnet, Undernet, etc.) ► Millions of users ► Direct file spamming (via DCC Send) ► URL spamming (via text messages) ► Used by numerous malwares even when no IRC software was ever installed by user
Top Ten Malware Detections in IRC in 2005 W32/Drefir.worm453 IRC/Flood319 IRC-Contact224 VBS/Gedza143 Downloader-TS107 BackDoor-JZ71 W32/Pate.b42 W32/Jeefo40 Nuke-Vai40
Peer-to-peer networks (P2P) ► File sharing: movies, music, software ► Numerous networks (Kazaa, eDonkey, BitTorrent, Gnutella, etc.) ► Millions of users ► “Bridging” between different networks
Top Ten Malware detections in Gnutella in 2005 Downloader-TS7540 W32/Tibick!p2p1764 W32/Generic.d!p2p1597 W32/Sndc.worm!p2p1438 VBS/Gedza1029 Exploit-MS W32/Pate.b649 W32/Sdbot.Worm.gen566
Protection ► Antivirus software ► Security patches ► Firewalls ► Strict policies – enforced ► Keep your fingers crossed…
Questions?