Perform Scanning Activity on an Emerging Technology for Your Organization

profileRainebow
MITTechnologyReview8.pdf

B o

t n

e t

s of

Th ing

s

88

TECHNOLOGYREVIEW.COM MIT TECHNOLOGY REVIEW VOL. 120 | NO. 2 BREAKTHROUGH TECHNOLOGIES

MA17_10_botnets.indd 88 2/7/17 3:27 PM

B o

t n

e t

s of

Th ing

s

TECHNOLOGYREVIEW.COM MIT TECHNOLOGY REVIEW

VOL. 120 | NO. 2 BREAKTHROUGH TECHNOLOGIES

By Bruce Schneier

The relentless push to add connectivity to home gadgets is creating dangerous side effects that figure to get even worse.

Breakthrough Malware that takes control of webcams, video recorders, and other consumer devices to cause widespread Internet outages.

Why It Matters Botnets based on this software are disrupting larger and larger swaths of the Internet—and getting harder to stop.

Key Players - Whoever created the

Mirai botnet software - Anyone who runs a poorly

secured device online— including you?

Availability Now

R O

B E

R T

B E

A T

T Y

MA17_10_botnets.indd 89 2/8/17 1:22 PM

90

TECHNOLOGYREVIEW.COM MIT TECHNOLOGY REVIEW VOL. 120 | NO. 2 BREAKTHROUGH TECHNOLOGIES

B otnets have existed for at least a decade. As early as 2000, hack- ers were breaking into com- puters over the Internet and controlling them en masse from

centralized systems. Among other things, the hackers used the combined comput- ing power of these botnets to launch dis- tributed denial-of-service attacks, which flood websites with traffic to take them down.

But now the problem is getting worse, thanks to a flood of cheap webcams, dig- ital video recorders, and other gadgets in the “Internet of things.” Because these devices typically have little or no secu- rity, hackers can take them over with lit- tle effort. And that makes it easier than ever to build huge botnets that take down much more than one site at a time.

In October, a botnet made up of 100,000 compromised gadgets knocked

an Internet infrastructure provider par- tially offline. Taking down that provider, Dyn, resulted in a cascade of effects that ultimately caused a long list of high- profile websites, including Twitter and Netflix, to temporarily disappear from the Internet. More attacks are sure to follow: the botnet that attacked Dyn was created with publicly available malware called Mirai that largely automates the process of coöpting computers.

The best defense would be for every- thing online to run only secure software, so botnets couldn’t be created in the first place. This isn’t going to happen anytime soon. Internet of things devices are not designed with security in mind and often have no way of being patched. The things that have become part of Mirai botnets, for example, will be vulnerable until their owners throw them away. Botnets will get larger and more powerful simply because

the number of vulnerable devices will go up by orders of magnitude over the next few years.

What do hackers do with them? Many things.

Botnets are used to commit click fraud. Click fraud is a scheme to fool advertisers into thinking that people are clicking on, or viewing, their ads. There are lots of ways to commit click fraud, but the easiest is probably for the attacker to embed a Google ad in a Web page he owns. Google ads pay a site owner accord- ing to the number of people who click on them. The attacker instructs all the com- puters on his botnet to repeatedly visit the Web page and click on the ad. Dot, dot, dot, PROFIT! If the botnet makers figure out more effective ways to siphon revenue from big companies online, we could see the whole advertising model of the Internet crumble.

This map shows the extent of some of the Internet outages caused by denial-of-service attacks on Dyn on October 21, 2016. Dyn operates domain-name servers that connect end users to websites.

O U

T A

G E

D A

T A

F R

O M

D O

W N

D E

T E

C T

O R

MA17_10_botnets.indd 90 2/8/17 1:22 PM

91

TECHNOLOGYREVIEW.COM MIT TECHNOLOGY REVIEW

VOL. 120 | NO. 2 BREAKTHROUGH TECHNOLOGIES

Similarly, botnets can be used to evade spam filters, which work partly by know- ing which computers are sending millions of e-mails. They can speed up password guessing to break into online accounts, mine bitcoins, and do anything else that requires a large network of computers. This is why botnets are big businesses. Criminal organizations rent time on them.

But the botnet activities that most often make headlines are denial-of- service attacks. Dyn seems to have been the vic- tim of some angry hackers, but more financially motivated groups use these attacks as a form of extortion. Political groups use them to silence websites they don’t like. Such attacks will certainly be a tactic in any future cyberwar.

Once you know a botnet exists, you can attack its command-and-control sys- tem. When botnets were rare, this tactic was effective. As they get more common, this piecemeal defense will become less so. You can also secure yourself against the effects of botnets. For example, several companies sell defenses against denial-of- service attacks. Their effectiveness varies, depending on the severity of the attack and the type of service.

But overall, the trends favor the attacker. Expect more attacks like the one against Dyn in the coming year.

Bruce Schneier, chief technology officer at IBM Resilient, is the author of 13 books on cryptography and data security.

Bo tne

ts wi

ll g et

lar ge

r an

d m or

e p ow

erf ul

sim ply

be

ca us

e t he

nu mb

er of

vu lne

ra ble

de vic

es wi

ll g o

u p

b y

o r

d e

r s

o

f m

a g

n it

u d

e

o v

e r

t h

e n

e x

t

f e

w y

e a

r s

.

Worldwide number of “Internet- connectable” devices

D A

T A

F R

O M

IH S

M A

R K

IT

2011 8.0 billion

2012 9.3 billion

2013 11.1 billion

2015 15.2 billion

2016 17.4 billion

2014 13.1 billion

MA17_10_botnets.indd 91 2/7/17 3:27 PM

Copyright of MIT Technology Review is the property of MIT Technology Review and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.