Home > Storm Botnet Ebbing, Says UC San Diego Analyst

News

Storm Botnet Ebbing, Says UC San Diego Analyst

11/8/2007

An Oct. 20 presentation at the ToorCon hacker conference by Brandon Enright, a computer security researcher at the University of California, San Diego, struck a nerve in the CS community by concluding that the notorious Storm Worm could be losing steam.

"The size of the network has been falling pretty rapidly and pretty consistently," Enright told the conference during his presentation, which was titled, "Exposing Storm."

The Storm worm emerged in January as one of the first pieces of malware to use a P2P network for command and control, Enright said in his presentation, "making it one of the most resilient bots ever." The lack of a centralized command and control has made it highly resistant to countermeasures, he said.

Enright said the extent of the Storm network has been unscientifically reported by media outlets as between 1 million and 50 million bots. "Fortunately, most of these estimates are inaccurate or completely wrong," according to his presentation.

Since July, when a a concerted e-mail attack infected an estimated 1.5 million PCs, Storm has ebbed somewhat.

Enright ascribed this to aggressive work by anti-virus vendors. In particular, Microsoft Corp.'s addition of  Storm detection in September to its Malicious Software Removal Tool put a "measurable dent" in the network, Enright reported.

Read More:


Paul McCloskey is a contributing editor for the Campus Technology group of publications.

Cite this Site

Paul McCloskey, "Storm Botnet Ebbing, Says UC San Diego Analyst," Campus Technology, 11/8/2007, http://www.campustechnology.com/article.aspx?aid=52729

copy text (above) for proper citation



Recommended Reading
  • College of Southern Nevada Implementing Angel To Run Online Courses

    The College of Southern Nevada (CSN), a community college in Las Vegas with 41,000 students, has adopted the Angel Learning Management Suite (LMS) to support its online course offerings. In Spring 2008 CSN began evaluating alternatives to WebCT, which it currently runs, and made the decision to adopt Angel in the fall. In January 2009, CSN's 865 sections of online enrollment will be delivered using the Angel LMS.

  • Toshiba Brings DisplayLink to Docking Station

    Toshiba has introduced a new USB docking station that incorporates DisplayLink--a technology that allows computers to connect to projectors and other types of displays through USB 2.0.

  • Mitsubishi Ships SXGA+ Projector with DICOM Simulation

    Mitsubishi has begun shipping a new LCD-based SXGA+ projector aimed at higher education, specifically medical schools. The new MH2850U, according to Mitsubishi, is "specially engineered for projecting DICOM simulation images for use in medical education and training."

  • First Look: Komodo IDE 5.0

    Last month, ActiveState released Komodo IDE 5.0, the company's latest integrated development environment (IDE). Komodo supports multiple programming and markup languages, including HTML, JavaScript, PHP, Perl, Java, Python, C++ and more. It does not support some .NET languages at present, such as ASP/ASP.NET, C# and VB.NET.

  • IBM Offers Cloud Computing Help

    IBM last week announced consulting services specifically designed to help organizations assess their options in using cloud computing technology. "Cloud computing" is a much argued term, but it typically refers to solutions delivered over the Internet, rather than via customer premises-installed software.

  • Hollins U Chooses Omnilert for Emergency Notification Ahead of VA Deadline

    Hollins University, among other higher ed institutions in Virginia, has implemented Omnilert's e2Campus emergency notification system (ENS) just ahead of a state-mandated deadline requiring them at every public institution of higher education by Jan. 1. Hollins itself isn't a public campus, but wished to implement an ENS before the end of the year, the school said in a company statement.