230 likes | 367 Views
SPAM/BOTNETS and Malware. Neil Warner, CIO, GoDaddy.com Moderator: Dan Kaplan, deputy editor, SC Magazine. We Put Up Walls. Modern Day Fort. War Against SPAM. How do you Detect SPAM Mails? Key words Heuristics/Abnormal behavior What can you do to defend against it? SPAM Filters
E N D
SPAM/BOTNETS and Malware Neil Warner, CIO, GoDaddy.com Moderator: Dan Kaplan, deputy editor, SC Magazine
War Against SPAM • How do you Detect SPAM Mails? • Key words • Heuristics/Abnormal behavior • What can you do to defend against it? • SPAM Filters • Reputation services to block traffic from those Spamming IP addresses • Take down the root cause
Bot Army • What are Botnets used for? • How do we detect them? • How can we defend Against it? • Botnet lifecycle • Bot-herder configures initial bot parameters such as infection vectors, payload, stealth, C&C details • Register a DDNS • Register a static IP • Bot-herder launches or seeds new bot(s) • Bots spread • Causes an increase of DDoS being sent to the victim • Losing bots to rival botnets
Camouflaged Attacks • Different types of Malware • Broad Category • Trojans, Rootkits, Backdoors • Malware for Fun and Profit • Spyware, Key loggers, Dialers, Bots, Proxies, SEO etc.. • Grayware
Fake AV • 0 Day vulnerability in a web application or Web Server • Compromises the web sites • Redirects the end user to a malware site or competitors website. • Example: Fake AV Campaign
What Can We Do? Network/Application Security tools Firewalls Intrusion Prevention Systems Intrusion Detection Systems Web Application Firewalls Network Access Controls Antivirus Reputation based Access Code Audits
The Most Important Deterent Security Professionals
Thank You| Q&A Neil Warner, CIO GoDaddy.com nwarner@godaddy.com
References • https://zeustracker.abuse.ch/ • http://www.malwaredomainlist.com/ • http://www.phishtank.com/ • http://www.clean-mx.de/ • http://en.wikipedia.org/wiki/Botnet • http://en.wikipedia.org/wiki/Malware