Presentation is loading. Please wait.

Presentation is loading. Please wait.

Malware in Popular Networks Dmitry O. Gryaznov. The Big Change ► Mostly viruses, few trojans ► Obvious destructive or annoying payload ► Mischief and.

Similar presentations


Presentation on theme: "Malware in Popular Networks Dmitry O. Gryaznov. The Big Change ► Mostly viruses, few trojans ► Obvious destructive or annoying payload ► Mischief and."— Presentation transcript:

1 Malware in Popular Networks Dmitry O. Gryaznov

2 The Big Change ► Mostly viruses, few trojans ► Obvious destructive or annoying payload ► Mischief and vandalism ► Nothing gained but “glory” ► Mostly non-replicating malware ► Trying to stay inconspicuous ► Theft and control ► Monetary gains ThenNow

3

4

5

6 Malware “Highways” ► E-mail ► Usenet ► Internet Relay Chat (IRC) ► Peer-to-peer (P2P) ► Instant Messaging (IM)

7 Usenet ► Since early 1980s ► Over 100,000 newsgroups ► Millions of users ► Over 2 Terabytes daily ► Mostly binaries – video, audio, software

8

9

10

11 Top Ten Malware Detections in Usenet in 2005 BackDoor-AZV46963 W32/Spybot.worm.gen.b 4876 BackDoor-CQZ1381 W32/Swen@MM283 W32/Torvil@MM192 MultiDropper-DC183 W32/Kelvir.worm.gen75 W32/Netsky.p@MM75 BackDoor-ACH72 BackDoor-Sub7.svr44

12 Internet Relay Chat (IRC) ► Since early 1990s ► Dozens of networks (EFNet, DALnet, Undernet, etc.) ► Millions of users ► Direct file spamming (via DCC Send) ► URL spamming (via text messages) ► Used by numerous malwares even when no IRC software was ever installed by user

13

14 Top Ten Malware Detections in IRC in 2005 W32/Drefir.worm453 IRC/Flood319 VBS/Redlof@MM224 IRC-Contact224 VBS/Gedza143 Downloader-TS107 BackDoor-JZ71 W32/Pate.b42 W32/Jeefo40 Nuke-Vai40

15 Peer-to-peer networks (P2P) ► File sharing: movies, music, software ► Numerous networks (Kazaa, eDonkey, BitTorrent, Gnutella, etc.) ► Millions of users ► “Bridging” between different networks

16

17 Top Ten Malware detections in Gnutella in 2005 Downloader-TS7540 W32/Tibick!p2p1764 W32/Generic.d!p2p1597 W32/Sndc.worm!p2p1438 VBS/Gedza1029 W32/Bagle.aa@MM784 Exploit-MS04-028757 W32/Pate.b649 W32/Sdbot.Worm.gen566 W32/Bagle.n@MM535

18 Protection ► Antivirus software ► Security patches ► Firewalls ► Strict policies – enforced ► Keep your fingers crossed…

19 Questions?


Download ppt "Malware in Popular Networks Dmitry O. Gryaznov. The Big Change ► Mostly viruses, few trojans ► Obvious destructive or annoying payload ► Mischief and."

Similar presentations


Ads by Google