A graphic representation of computers captured into a robotic network to spread spam and snoop for financial information. (Stuart Isett for The New York Times)

Beware the digital zombies

REDMOND, Washington: In a windowless room on Microsoft's campus here, T. J. Campana, a cybercrime investigator, connects an unprotected computer running an early version of Windows XP to the Internet. In about 30 seconds the computer is "owned."

An automated program lurking on the Internet has remotely taken over the PC and turned it into a "zombie." That computer and other zombie machines are then assembled into systems called "botnets" — home and business PCs that are hooked together into a vast chain of cyber-robots that do the bidding of automated programs to send the majority of e-mail spam, to illegally seek financial information and to install malicious software on still more PCs.

Botnets remain an Internet scourge. Active zombie networks created by a growing criminal underground peaked last month at more than half a million computers, according to shadowserver.org, an organization that tracks botnets. Even though security experts have diminished the botnets to about 300,000 computers, that is still twice the number detected a year ago.

The actual numbers may be far larger; Microsoft investigators, who say they are tracking about 1,000 botnets at any given time, say the largest network still controls several million PCs.

"The mean time to infection is less than five minutes," said Richie Lai, who is part of Microsoft's Internet Safety Enforcement Team, a group of about 20 researchers and investigators. The team is tackling a menace that in the last five years has grown from a computer hacker pastime to a dark business that is threatening the commercial viability of the Internet.

Any computer connected to the Internet can be vulnerable. Computer security executives recommend that PC owners run a variety of commercial malware detection programs, like Microsoft's Malicious Software Removal Tool, to find infections of their computers. They should also protect the PCs behind a firewall and install security patches for operating systems and applications.

Even these steps are not a sure thing. Last week Secunia, a computer security firm, said it had tested a dozen leading PC security suites and found that the best one detected only 64 out of 300 software vulnerabilities that make it possible to install malware on a computer.

Botnet attacks now come with their own antivirus software, permitting the programs to take over a computer and then effectively remove other malware competitors. Campana said the Microsoft investigators were amazed recently to find a botnet that turned on the Microsoft Windows Update feature after taking over a computer, to defend its host from an invasion of competing infections.

Botnets have evolved quickly to make detection more difficult. During the last year botnets began using a technique called fast-flux, which involved generating a rapidly changing set of Internet addresses to make the botnet more difficult to locate and disrupt.

Companies have realized that the only way to combat the menace of botnets and modern computer crime is to build a global alliance that crosses corporate and national boundaries. On Tuesday, Microsoft, the world's largest software company, will convene a gathering of the International Botnet Taskforce in Arlington, Virginia At the conference, which is held twice a year, more than 175 members of government and law enforcement agencies, computer security companies and academics will discuss the latest strategies, including legal efforts.

Although the Microsoft team has filed more than 300 civil lawsuits against botnet operators, the company also relies on enforcement agencies like the FBI and Interpol-related organizations for criminal prosecution.

Last month the alliance received support from new U.S. legislation, which for the first time specifically criminalized the use of botnets. Many of the bots are based in other countries, however, and Campana said there were many nations with no similar laws.

"It's really a sort of cat-and-mouse situation with the underground," said David Dittrich, a senior security engineer at the University of Washington Applied Physics Laboratory and a member of the International Botnet Taskforce. "Now there's profit motive, and the people doing stuff for profit are doing unique and interesting things."

Microsoft's botnet hunters, who have kept a low profile until now, are led by Richard Boscovich, who until six months ago served as a U.S. government prosecutor in Miami. Boscovich, a federal prosecutor for 18 years, said he was optimistic that despite the growing number of botnets, progress was being made against computer crime. Recent successes have led to arrests.

"Every time we have a story that says bot-herders get locked up, that helps," said Boscovich, who in 2000 helped convict Jonathan James, a teenage computer hacker who had gained access to Defense Department and National Air and Space Administration computers.

Back to top
Home  >  Technology & Media

Latest News

Eyad Baba/The Associated Press
Israel agreed to do so for three hours each day to permit humanitarian relief goods to reach the beleaguered population.
Music labels are embracing free ad-supported music models and all-you-can-download services.
John Schwartz of the New York Times tests a jetpack with the help of its inventor, Glenn Martin, and Ray Thoms...
Jane Sims and her husband, David, spend hours reading print. Their children spend most of their reading time o...
David Pogue reviews the the world's first pocket-sized digital camera with an S.L.R.-sized sensor.
David Pogue discusses some of the new applications for the iPhone.
David Pogue looks at the new iPhone, which will cost much less than the original one.
David Pogue looks at the Mobile Digital Scribe, from Iogear, and the ZPen, from Dane-Elec.
A. O. Scott discusses the universal appeal of Pixar's films.
David Pogue looks at the Eye-Fi memory card, which stamps photos with the location where they were taken.
David Pogue talks about how to save your old photo prints, cassette tapes and vinyl records from the dustbin o...