Director, Network World Test Alliance

IDS and IPS play key role in defending against an attack of the killer bots

Opinion
Aug 9, 20072 mins

* Network World's IDS and IPS Buyer’s Guides help you find products to battle botnets

In her recent feature on just how bad the botnet problem across the Internet is right now, Julie Bort likened these zombie computers to termites, saying they burrow in behind the walls of an IT security perimeter, lie dormant for a period of time, then attack on the orders of a criminal bot herder.

How many bots are actually out there? Bort’s sidebar on the severity of the problem points to several best guesses that range anywhere from 3 million to 6 million – but those are only the active ones. No one can count those that lie in wait.

That’s not to say that IT organizations should lie around waiting. In the third piece in this package, Bort outlines six ways to proactively defend against a botnet infestation. No. 4 on the list is fine tuning your Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) products to look for botlike activity.

Evidence that a botnet is residing on your network include:

* Any machine suddenly blasting away on Internet Relay Chat is certainly suspicious.

* Any machine connecting to offshore IP addresses or illegitimate DNS addresses.

* A sudden uptake in SSL traffic on a machine, particularly in unusual ports, which could indicate a botnet-control channel has been activated.

* Machines routing e-mail to servers other than your own e-mail server.

* Web crawlers that operate at high “fetch levels” that activate all links located on a Web page, which could indicate a machine is being sent to a malicious Web site.

If you are in the market for either an IDS or an IPS to help you pinpoint botnet activity, you can tap into the Network World Buyer’s Guides for detailed product listings in both segments. Security: Intrusion Detection Systems and Security: Network Intrusion Prevention Systems.

Christine Burns is the Executive Editor of Testing. She can be reached at cburns@nww.com