All the latest UK technology news, reviews and analysis

Coreflood botnet shutdown raises concerns about government tactics

by Iain Thomson

More from this author

19 Apr 2011

Be the first to comment

  • Tweet this

Last week's Coreflood botnet shutdown looks to be have been successful, but the case raises some interesting questions about how the fight against computer crime will be handled in the future.

Coreflood was a large botnet that had infected over two million PCs around the world. The code to control it has been around for nearly a decade, and some estimates suggest that it was responsible for up to a third of spam at one point.

Coreflood was a good target for shutdown, but the way that the FBI and Department of Justice acted was unusual.

After identifying the botnet's command-and-control (C&C) servers, federal agents replaced them with their own systems. These waited for infected machines to register with the servers, and then sent out a message to the malware telling it to shut down.

Noa Bar-Yosef, senior security strategist at Imperva, told V3.co.uk that the researchers/federal agents had approached the task in an interesting way.

"The alternative C&C server is going to log all IPs interacting with it. With these lists in hand they're planning to work with ISPs so that the ISPs can inform their customers that they are infected," he said.

The tactics differ sharply from those used in the Rustock botnet shutdown last month. The C&C servers were simply replaced with blank drives, with the help of federal agents, and the malware servers taken away for analysis. Such a technique is non-intrusive, in comparison to government tactics.

The Electronic Frontier Foundation (EFF) and others have reportedly objected to the tactics, since they set a legal precedent.

If the principle of allowing an official agency to use malware to download code onto infected systems becomes accepted, IT managers and individuals face difficult times ahead.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

PHP Developer - PHP 5, HTML, CSS, MVC

PHP Developers - Fixed Term Contracts (initially 6 months...

Junior Ruby on Rails Developer - London - Permanent

Junior Ruby on Rails Developer - London - Permanent...

Project Manager

A Project Manager is required to join a leading Insurance...

CCIE Network Engineer

CCIE Network Engineer required with fluent Hungarian...

To send to more than one email address, simply separate each address with a comma.