,

Bulletproof hosting, cybercrime and botnets

The Register has an interesting piece analysing how cybercrime botnets are connected and why they seem impervious to outside attack. It seems that the botnets are programmed to reconfigure themselves if one upstream provider goes down, and are each strongly interconnected, which creates a whole lot of redundancy:

“What they’ve worked really hard to do for themselves is build a spiderweb of connections to the outer ring if the outer ring were the internet at large,” Sean Brady, manager of RSA’s identity protection and verification group, told The Register. “As you start picking off threads, they work to reroute, to crawl along different threads.”

Needless to say, this redundancy is pretty attractive to botnet controllers (who typically seem to buy or lease access from malware creators). What’s really interesting, though, is that it turns out all the major botnets rely on about nine commercial ISPs, which are legitimate businesses. Take those ISPs offline — or require them to block botnet communications — and it will be much harder for botnet operators to re-establish contact with infected computers once the command and control link is severed (as recently happened with the Zeus botnet). This raises a very interesting legal question about whether those ISPs are, or should be, liable to block access.