What can you do about botnets? As promised, a followup on my previous post.
- Let someone tell you. Make sure that your IP range is properly registrated at ARIN or APNIC or RIPE and that you list an abuse@yourdomain.com address so you can be reached
- Sniff your network. Deploy a network IDS (such as snort or one of the many commercial ones) to look for suspicious activity. If your security network policy (and firewalls) doesn't allow IRC, this might be an indication. The most common used communication protocol for botnets is IRC (at least for now).
- Try to define a baseline of your network. Monitor the bandwidth usage through SNMP and something like MRTG or CACTI. A sudden increase in network usage may indicate bots or attacks. Tools like wireshark can help you analyze the packets.
- Check your firewall logfiles on a regular basis. Especially scans with an internal source address might indicate a bot.
- Protect your endpoints. Run Anti-malware agents on desktops and laptops. Centralize the management and check every day if their databases are up-to-date. Follow up on errors.
- Keep systems patched and up-to-date.
- Receive warning of a infected instance
- Open a trouble ticket/incident number
- Disconnect the pc from the network
- Perform a quick forensic analysis of the pc
- Copy the user's data and scan it for viruses
- Reimage the PC
Check all processes and all open networkports and look for any unusal activity. Check which programs are set to run at boottime. Use a clean PC to compare if necessary. Scan it with a bootable CD with an up-to-date virusscanner. If you have any indication of a compromise, re-image the PC.
Security4all Blog
Twitter
Slideshare
Facebook
Digg
Flickr




2 comments:
These are the basics for monitoring and remediation for botnets. The more advanced stuff would require the isp to assistance and of course, maybe configure the routers or firewall to harden the stack. Servers will also have to be configured to harden their stack.
hackathology
Any reference to more advanced stuff is always appreciated! :)
Post a Comment