CYBER COPS India Headline Animator

Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts

Monday, August 01, 2011

Global Botnet Activity / Infection Map for later 2010

Botnet is a network of private computers infected with malicious software and controlled as a group without the owners' knowledge, e.g. to send spam messages or to carry out Distributed Denial of Service (DDoS) attacks.


According to Digital Activism, a botnet is a network of automated software controlled and manipulated by a third party, that is, neither the owner of the machine running the bot nor the target of the attack. A botnet can refer to a legitimate group of computers that share program processing. However, the term generally refers to computers running malicious software that was downloaded without the consent of the computer’s owner and is used to make attacks against other systems.



Botnet = Robot + Network


Symantec's MessageLabs Intelligence (MLI) regularly reviews global botnet activity to identify and characterize the top spam-sending botnets. As part of this analysis MLI also collect the IP addresses of computers under the control of each botnet as they are used to send spam. Using all available data, MLI had plotted the geographical locations of these individual bots that make up the major botnets.


This map shows these locations, aggregated to within one degree latitude by one degree longitude grid; the darker red the dot indicates that more bots are active from that locationThe top locations are identified as follows: 

  • a black outline indicates the locations of the top 10 most active bots; 
  • a gold outline indicates locations where the top 11-50 most active bots are found. 
  • The percentage of spam sent from each group is also highlighted on the chart.





Reference: Symantec Cloud
URL: http://www.symanteccloud.com/globalthreats

Friday, July 29, 2011

A Deeper Look at Malware Networks

Malware and malicious software have been around for years. Malware Networks don’t traditionally come with names, as one might expect, but the security industry has now been tracking the biggest malware offenders for long enough that they’ve been able to identify trends. Traditionally, malware has been identified by particular attacks (and named accordingly), but the reality, is that some networks have grown so large that they have their hands in many different scams at once. And they need names, because these networks are fast, and they’re slippery. The average number of unique host names per day for the top 10 malware delivery networks is 4,107, and an average of over 40,000 users make unwitting requests to malware networks each day. 

Read on to get an idea of some of the size, shape and growing threat of larger Malware networks, their points of entry and a list of prevention techniques. This is created by Blue Coat's Senior malware researcher Chris Larsen has pulled data from the company's Mid-Year Security Report, 2011.