BOTNET
A BOTNET is a network
of devices connected through internet which includes Personal Computers, Servers,
Mobile devices and Internet of Things. All these devices are infected and
controlled by a common type of malware. Users are often unaware of a BOTNET
infecting their system.
Botnets are networks
of compromised computers that are remotely controlled by malicious Agents. They
are used to send massive quantities of spam e-mail messages, co-ordinate
distributed denial-of-service (DDOS) attacks and facilitate financial and
identity fraud, among other economically and socially harmful activities
How
BOTNET works
The term botnet is derived from the words robot and network. A bot in this case is a device infected by
malicious code, which then becomes part of a network, or net, of infected
devices controlled by a single attacker or attack group.
The botnet malware
typically looks for vulnerable devices across the internet, rather than
targeting specific individuals, companies or industries. The objective for
creating a botnet is to infect as many connected devices as possible and to use
the computing power and resources of those devices for automated tasks that
generally remain hidden to the users of the devices.
BOTNET Architecture
Botnet infections are usually spread through malware. Botnet
malware is typically designed to automatically scan systems and devices for
common vulnerabilities that haven't been patched in hopes of infecting as many
devices as possible.
Vulnerable devices
The recent influx of cheap, internet-capable devices is
vulnerable to botnet attacks. This is because these devices have either limited
security features to begin with or because the security features are difficult
to manage.
Impacts of Botnets
Criminals also use botnets to launch DDoS attacks that bring
down organizational websites/Services
Typically, users don’t even realize their computer is part of a
botnet You’re living your life and meanwhile, your computer is part of an army
of zombies, carrying out the orders of cybercriminals.
They also pose a risk to consumer privacy. Private credentials
like passwords can be stolen, giving access to online bank accounts, social
media accounts, and other personal data.
How to detect and prevent botnet
attacks
Botnet attacks frequently go undetected because they involve a
wide network of devices that operate in the background of a user's device and
occupy little bandwidth. They also target the wide variety of devices in IoT,
which all vary in the ways that they interact with the physical world and in
the ways in which users can secure them. There is no one-size-fits-all solution
to botnet detection and prevention, but manufacturers and enterprises can start
by incorporating the following:
Strong user authentication method.
Secure remote firmware updates. Only firmware from the original
manufacturer should be permitted.
Secure boot. This ensures the device only executes code produced by
trusted parties.
Advanced behavioral analysis. This detects unusual behavior in IoT
traffic.
Automation, machine learning and
artificial intelligence (AI). These enable response to new threats at digital speeds
before they cause serious harm.
- Unfortunately, botnet attacks are hard to detect on an individual level because devices continue to act normally while infected by botnet malware. It may be possible for the user to remove the malware itself but less likely for the user to be able to have any effect on the botnet as a whole.
Comments
Post a Comment