Enter your email address:

Delivered by FeedBurner

AddThis Social Bookmark Button

Support


Books To Read

July 2009

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

« JOURNAL: Hybrid Gangs in the US | Main | JOURNAL: Blog-based Analysis of Naxalite Violence »

Thursday, 04 October 2007

MALWARE, WARFARE, AND SELF-REPLICATION

The tinkering networks of the Internet criminal/hacker marketplace have produced a major innovation called the "Storm Worm" and it is rewriting the rules of engagement in computer security. It's essentially a new breed of malware that is a combination of worm/trojan/bot. What makes it special is that the Storm Worm's method of operation is sophisticated, so much so, that it is nearly immune to defense, suppression, or eradication -- demonstrated in that it has already infected up to 50 million computers and slaved them into a massive botnet.

However, the really dangerous aspect of this isn't the smart way the Storm Worm is operated, it's what the network will be able to do once it activated. If the developers are as smart as their approach indicates, that outcome will either be a big pay-off or substantial damage.

A Rogue Network Expands

So, what's so special about it? Bruce Schneier, an expert on computer security and the author of an excellent blog (as well as the book, Beyond Fear), lists the details of Storm Worm's behavior:
  • Storm is patient. A worm that attacks all the time is much easier to detect; a worm that attacks and then shuts off for a while hides much more easily.
  • Storm is designed like an ant colony, with a separation of duties. Only a small fraction of infected hosts spread the worm. A much smaller fraction are C2: command-and-control servers. The rest stand by to receive orders. By only allowing a small number of hosts to propagate the virus and act as command-and-control servers, Storm is resilient against attack. Even if those hosts shut down, the network remains largely intact, and other hosts can take over those duties.
  • Stealth. Storm doesn't cause any damage, or noticeable performance impact, to the hosts. Like a parasite, it needs its host to be intact and healthy for its own survival. This makes it harder to detect, because users and network administrators won't notice any abnormal behavior most of the time.
  • Distributed/resilient command and control. Rather than having all hosts communicate to a central server or set of servers, Storm uses a peer-to-peer network for C2. This makes the Storm botnet much harder to disable. The most common way to disable a botnet is to shut down the centralized control point. Storm doesn't have a centralized control point, and thus can't be shut down that way. This technique has other advantages, too. Companies that monitor net activity can detect traffic anomalies with a centralized C2 point, but distributed C2 doesn't show up as a spike. Communications are much harder to detect.

    One standard method of tracking root C2 servers is to put an infected host through a memory debugger and figure out where its orders are coming from. This won't work with Storm: An infected host may only know about a small fraction of infected hosts -- 25-30 at a time -- and those hosts are an unknown number of hops away from the primary C2 servers. And even if a C2 node is taken down, the system doesn't suffer. Like a hydra with many heads, Storm's C2 structure is distributed. Not only are the C2 servers distributed, but they also hide behind a constantly changing DNS technique called "fast flux." So even if a compromised host is isolated and debugged, and a C2 server identified through the cloud, by that time it may no longer be active.

  • Rapid evolution. Storm's payload -- the code it uses to spread -- morphs every 30 minutes or so, making typical AV (antivirus) and IDS techniques less effective. Also, Storm's delivery mechanism also changes regularly. Storm started out as PDF spam, then its programmers started using e-cards and YouTube invites -- anything to entice users to click on a phony link. Storm also started posting blog-comment spam, again trying to trick viewers into clicking infected links. While these sorts of things are pretty standard worm tactics, it does highlight how Storm is constantly shifting at all levels. The Storm e-mail also changes all the time, leveraging social engineering techniques. There are always new subject lines and new enticing text: "A killer at 11, he's free at 21 and ...," "football tracking program" on NFL opening weekend, and major storm and hurricane warnings. Storm's programmers are very good at preying on human nature.
  • Retaliation. Last month, Storm began attacking anti-spam sites focused on identifying it -- spamhaus.org, 419eater and so on -- and the personal website of Joe Stewart, who published an analysis of Storm. I am reminded of a basic theory of war: Take out your enemy's reconnaissance. Or a basic theory of urban gangs and some governments: Make sure others know not to mess with you.

Superempowerment Through Self-Replication

It's not surprising that the methods of operation we see with the Storm Worm are similar to the methods of open source warfare in the real world explored on this blog and in Brave New War. The interesting part is that it uses individual superempowerment, a major trend cited in the book, to bring it to a new level. This superempowerment is accomplished by adding hard self-replication to the mix (as opposed to soft self-replication through the propagation of ideas or disruption -- ala al Qaeda). Hard self-replication makes exact copies of itself through an automated process, ad infinitum, and is something we will see much more of in biotech weapons/crimes in the future. It is the path to a one man against the world scenario.

NOTE to insiders: Hard self-replication likely a hallmark of a fifth generation of warfare.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451576d69e200e54ef04d6a8833

Listed below are links to weblogs that reference MALWARE, WARFARE, AND SELF-REPLICATION:

» What's Next for the Storm Worm? from IntelFusion
DHS Open Source Newsletter quotes an excellent Wired commentary on the Storm Worm by Bruce Schneier: Not that we really have any idea how to mess with Storm. Storm has been around for almost a year, and the antivirus companies [Read More]

Comments

>>Superempowerment Through Self-Replication<<

... I got a kick out of reading this, reminded me of AGENTS from Matrix.

"Because of you, Mr. Anderson," "Because of You..."

Mr. Robb, I´d be interested in hearing your thoughts on the recent developments, as detailed on the Storm Botnet wiki that the makers of Storm are now "leasing out" subdivisions of the botnet for money. I´d think that putting a capitalistic dynamic in play will inevitably lead to competition, intensification and innovation - these things will get more elusive, more sophisticated and more nasty.

Also, now that money is involved, and potentially ever-escalating sums of money, rather than just hacker "street-cred", how do you see cybercrime like this possibly merging more closely with black globalization and terrorism? It´s bad enough that this kind of computing power is in the hands of hackers - now that a comfortable "hand-over" mechanism is in place to sell parts of the botnet to some far more nasty people is in place, could we see these kinds of nets being employed by global guerillas or organized crime as fundraisers and weapons of attack?

John,
While this is a terrifying prospect--it certainly reminds me of the line-wire diagrams used in revolutionary/insurgent "cells." Just as with Al Qaeda, a decapitation will prove entirely ineffective. Truly chilling.

The comments to this entry are closed.

My Photo

On Brave New War

  • Purchase Brave New War
  • New York Times Op-Ed
    ...a fast, thought-sparking book.. -- David Brooks
  • Greenpeace
    I read it twice and bought six copies for my friends -- John Passacantando (Exec. Dir. Greenpeace)
  • G. Gordon Liddy Show (radio)
    ...this is a seminal book in the truest sense of the term.. way ahead of the curve... go out and buy it right now -- G. Gordon Liddy
  • City Journal
    Robb has written an important book that every policymaker should read -- Glenn Reynolds (Instapundit)
  • Small Wars Journal
    Without reservation Brave New War is for professional students of irregular warfare and for any citizen who wants to understand emerging trends and the dark potential of 4GW -- Frank Hoffman
  • Scripps Howard News Service
    A brilliant new book published by terrorism expert John Robb, titled "Brave New War," hit stores last month with virtually no fanfare. It deserves both significant attention and vigorous debate... - Thomas P.M. Barnett
  • Chet Richards DNI
    John has produced an important book that should help jar the United States and other legacy states out of their Cold War mindset. You can read it in a couple of hours – so you should read it twice...
  • Washington Times / UPI
    Robb correctly finds the antidote to 4GW not in Soviet-style state structures such as the Department of Homeland Security, but in decentralization -- William Lind (the father of 4th generation warfare).
  • Robert Paterson
    Having painted a crystal clear picture of how a war of networks is playing out, he comes to an astonishing conclusion that I hope he fills out in his next book.
  • The Daily Dish
    John Robb of Global Guerrillas has written the most important book of the year, Brave New War. - Daily Dish (The Atlantic)
  • Simulated Laughter
    Well-written. Brave New War reads more like an action novel than a ponderous policy book. - Adam Elkus
  • FutureJacked
    Go buy a copy of this book. Now. If you are low on cash, skip a few lunches and save up the cash. It is worth it. - Michael Flagg
  • ZenPundit
    The second audience is composed of everyone else. Brave New War is simply going to blow them away. - Mark Safranski
  • Haft of the Spear
    There aren’t a lot of books that make me recall a 12-year-old self aching for the next issue of The Invincible Iron Man to hit the shelves. Well done. - Michael Tanji
  • Ed Cone
    His book posits an Army of Davids -- with the traditional nation state in the role of Goliath. - Ed Cone (Ziff Davis)
  • The Newshoggers
    I highly recommend reading and re-reading this work. - Fester
  • Shloky.com
    This is the first real text on next generation warfare designed for the general population and it sets the bar high for following acts. It is smart, it is a short read, and it will change your thinking. - Shlok Vaidya
  • Politics in the Zeros
    I suggest this is something Lefties need to start thinking about now, as that decentralized world is coming. - Bob Morris
  • Hidden Unities
    A thoughtful book that should be read more widely than the latest Tom Friedman whopper, Chalmers Johnson scare tale or Bill Kristol hack fest. - EB

Stats


Stats2