ISPs agree to fight botnets using the U.S. Anti-Bot Code of Conduct

Opinion
Apr 20, 20125 mins

By some accounts, more than 10% of U.S. computers are enjoined to a botnet. The U.S. Federal Communications Commission recently approved the Anti-Bot Code of Conduct, a voluntary program for ISPs that aims to reduce the likelihood of users’ computers being recruited into botnet servitude.

Over the past few years, botnets have become an exceptionally egregious security issue for businesses and home computer users alike. While home PCs are the most desirable targets for recruitment into a botnet because they are less likely to be properly patched or secured behind a firewall, the botnets themselves are often used to direct attacks against corporate networks. A spate of DDoS attacks against businesses and government agencies in the past year utilized botnets under the command of groups like Anonymous and other criminal organizations.

According to the Honeynet Project, even a relatively small botnet with only 1,000 bots can cause a great deal of damage in a DDoS attack. These thousand bots have a combined bandwidth that is probably higher than the Internet connection of most corporate systems. (A thousand home PCs with an average upstream of 128Kbps can amount to more than 100Mbps.) In addition, the IP distribution of the bots makes ingress filter construction, maintenance and deployment difficult, and incident response is hampered by the large number of separate organizations involved.

IN THE NEWS: Fast-growing Flashback botnet includes over 60,000 Macs, malware experts say

In addition to providing a platform for conducting DDoS attacks, botnets are used to: distribute adware, malware and spam; steal passwords and personal and sensitive information; eavesdrop on network traffic; and conduct advertising click fraud.

By some accounts, more than 10% of U.S. computers are enjoined to a botnet, and computers on a corporate network are not immune. Infection methods such as drive-by downloads that exploit Web browser vulnerabilities and Trojan horse programs embedded in email attachments can catch even the most wary user off-guard.

A 2010 Security Intelligence Report by Microsoft revealed that the U.S. leads the world in numbers of Windows PCs that are part of botnets. In a short three-month span between April and June 2010, Microsoft cleaned more than 6.5 million computers of botnet infections — double the amount for the same period a year before. Without a doubt, botnets are a scourge to consumers and companies alike.

On March 22, the U.S. federal government took steps toward reducing the likelihood of users’ computers being recruited into botnet servitude. The FCC’s Communications Security, Reliability and Interoperability Council (CSRIC) advisory group on botnet remediation approved the U.S. Anti-Bot Code of Conduct, which tasks Internet service providers (ISPs) to implement five steps to protect customers and the Internet from zombie computers. Known as “the ABCs for ISPs,” the steps focus on residential computer users and cover the areas of education, detection, notification, remediation and collaboration.

Initially, the efforts should help about 23 million of the 81 million U.S. households that have broadband service from the ISPs that have already voluntarily adopted the Anti-Bot Code of Conduct. To participate in this Code, an ISP is required to take meaningful action in at least one of the following areas:

• Education — an activity intended to help increase end user education and awareness of botnet issues and how to help prevent bot infections;

• Detection — an activity intended to identify botnet activity in the ISP’s network, obtain information on botnet activity in the ISP’s network, or enable end users to self-determine potential bot infections on their end user devices;

• Notification — an activity intended to notify customers of suspected bot infections or enable customers to determine if they may be infected by a bot;

• Remediation — an activity intended to provide information to end users about how they can remediate bot infections, or to assist end-users in remediating bot infections;

• Collaboration — an activity to share with other ISPs feedback and experience learned from the participating ISP’s Code activities.

The working group that drafted the Code of Conduct includes many key players: AT&T, PayPal, Time Warner Cable, Sprint, Comcast, SANS Institute, Verizon, Microsoft and a number of other companies and government agencies. Hopefully they will have the influence to expand the number of ISPs that volunteer to observe and get active with the Code of Conduct. After all, botnets are a serious threat to the vitality and resiliency of the Internet and to the online economy.

ISPs will also benefit from keeping their customers’ computers bot-free. Various ISPs that have already implemented some aspects of the Code have benefited from lower call volumes to their help desks from customers with infected machines; reduced upstream bandwidth consumption by denial-of-service attacks and spam; increased customer goodwill and lower customer churn; and a reduction in spam-related complaints from other ISPs.

While the Anti-Bot Code of Conduct is a voluntary program for ISPs, it is a good first step. Let’s hope that every ISP in the country fully adopts the Code of Conduct and is proactive about all five steps. Keeping computers off the botnets and out of the control of cybercriminals and malcontents will help us all.

Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.

______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.