Response

Rak1993
NeedResponsesforthementioneddiscussions.docx

Discussion 1

After reading the chapter 1 which mainly talks about BOTNET attack, after doing some research I understood that it’s one of the dangerous malware attacks and riskiest dangers to web security. Bot refers to software code that runs without user’s permission automatically on compromised machines, it usually runs on the instructions and controlled by any attacker or group of individuals with malware techniques remotely (Provos, 2015).

When the Bot is installed on user’s system with the help of remote-control mechanism, any attacker can operate it by remote control with the help of issuing commands by the attacker who will have the control to access over victim’s system. By using the various techniques, attacker will access the user’s private information like passwords, records and other personal data which will be saved in their computers and it also hides attacker’s existence in the PC.

Botnet attackers mainly focuses on financial abuse like Phishing which will be used widely to host malicious phishing sites, Spam production which sends spam emails, clicking for fraud which will make users to click on links and advertisements in the purpose of commercial/personal abuse and Distribute a denial – of – service (DDoS) usually work on two commands SYN and UDP flooding attack against any devices or computers (K, 2020).

 

References

K, B. (2020). Statistical Approach Based Detection of Distributed Denial of Service Attack in a Software Defined Network. IEEE.

Provos, T. H. (2015). Virtual Honeypots: From Botnet Tracking to Intrusion Detection. Addison-Wesley Professional, 2007.

Discussion-2

Threats of Botnet attack

Cybercriminals find various ways to execute malicious acts that hunt for damaging data, stealing data and gaining unauthorized access into secure systems. One such attacks are Botnet attacks that dangerously impacts large scale internet connected devices which enables user to take over the control and override their behavior to carry out malicious activities.

The problem of Botnet is global in nature, Ineffective techniques for detecting and mitigating the malicious behaviors of botnets will expose thousands of computers to serious threat in regard to stealing valuable information from organizations. Web robots also called Internet Bots that are developed by cybercriminals secretly seizes control over the individuals or a set of devices without user’s knowledge. They initially gain access by using special Trojan viruses to act upon the computers secure components and disable them to further command and manage software to implement malicious activities. One such infamous attack is DDoS attack; botnet is often and highly used for this attack on IT applications where multiple compromised devices enact heavy traffic to the targeted system and causes unplanned downtime.

Traffic Sniffing is another common threat posed by botnets which starts sniffing clear-text data passed by a compromised machine, therefore, to collect sensitive information like user credentials. Although it is difficult to stop botnet attacks, Businesses can overcome by following effective approaches like using firewalls as defensive technique and by frequently updating software systems to latest version including but not limited to stopping threats at DNS level.

References

M. D. Amala Dhaya, R. Ravi, "Multi feature behavior approximation model based efficient botnet detection to mitigate financial frauds", Journal of Ambient Intelligence and Humanized Computing, 2020.