By Mike Pearson LinuxInsider Part of the ECT News Network
07/31/09 4:00 AM PT
Computer security researchers still don't know much about how botnets work. At Sandia National Laboratories, though, scientists are preparing for a massive experiment. They've booted up 1 million Linux kernels as virtual machines, which will allow them to observe the behavior of a simulated network of 10 million computers online at once -- complete with users who get infected with botnets.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Researchers at
Sandia National Laboratories have laid the groundwork for an unprecedented simulation of a large-scale botnet after booting up 1 million Linux kernels as virtual machines.
Sandia computer scientists Ron Minnich (foreground) and Don Rudish (background) have successfully run more than a million Linux kernels as virtual machines.
(click image to enlarge)
They now are waiting for completion of a new, faster and more capable supercomputer at the Livermore, Calif., lab, on which they hope to run 10 million kernels in a simulation of the open Internet -- complete with Web and mail servers, as well as simulated users clicking on simulated emails, getting simulated infections, and joining a simulated botnet.
A kernel is the core component of the operating system that passes instructions between hardware and software. To make the unprecedented achievement of running 1 million kernels as virtual machines, researchers stripped out support for extraneous devices like Bluetooth and wireless connectivity.
Managing a Challenge
They still had difficulty keeping up with all of the virtual machines, said Sandia computer science researcher Don Rudish, who worked on the experiment.
For instance, the Ethernet switch on the lab's supercomputer, called "Thunderbird," wasn't designed to recognize one million MAC addresses online.
"After 100,000, the whole network came to a crawl," Rudish told LinuxInsider. "Just looking through 1 million lines on a text log takes some time."
While the experiment was a success , Rudish said researchers didn't entirely solve the issue of monitoring the vast network, even after working out ways to visualize some of the data and reduce the amount of information flowing to them.
Virtual Botnet
They hope to solve that in the future by using botnet behavior to help control the network, Rudish said.
Unfortunately, researchers still don't know much about how botnets actually work. So, they're planning to use the lab's new Red Sky supercomputer, currently under construction, to create a 10 million kernel system and introduce botnet software into the system to see what happens, Rudish said.
Other researchers have simulated the behavior of botnets in computer models, but little is known about how they really operate. Sandia's experiment will be different because it's much closer to an actual real-world application with what will look to the network like 10 million computers online at once, he said.
"It's implemented in software, so you can say it's a simulation, but it's a much better one in that you're running real code, real
TCP stacks," Rudish said.
Some of the computers will be programmed to act as Web and mail servers, others as simulated users with a percentage chance to click on incoming "emails" -- some of which will download botnet software to infect the virtual machine. That machine will then take on one of several roles in the botnet: storage server, Web server, or aggressor seeking to further propagate the botnet's control.
The experiment should give researchers more insight into how botnets work and how to combat them, Rudish said.
Project Cost
It's difficult to calculate the cost of the 1 million kernel experiment because so much of the technology that went into it was developed for other purposes, explained Rudish.
Article is somewhat misleading, in that it implies the botnet is "running on Linux". ...
Next Article in Kernel
Shill-Shocked: The Dark Side of Community Discussion July 30, 2009
When does free speech become a club that actually stifles the free flow of ideas? That's just one potential ramification of the question posed to the FOSS community this week: What makes someone a "shill"? This negative label can come with a pretty sharp sting. Does concern over negative criticism and even ostracism cause some people to keep their good ideas to themselves?
Related Stories
Botnet Hunters Bypass Cops to Bring Down Spam Host November 13, 2008
Rather than wait for the cops to go to a judge and get a subpoena, a group of security researchers took their case directly to the ISPs that serve McColo, which the researchers identified as a major enabler of an eastern European spam botnet.
Hunting Botnets With Randal Vaughn May 23, 2008
When Randal Vaughn isn't teaching computer courses at Baylor University, he's busy putting an end to zombies hordes. As a member of the Anti-Phishing Working Group, Vaughn aims to put an end to the Internet's ailments, including masses of zombie computers under the control of illegal botnets.
Botnet Survivor: Outwit, Outplay, Outlast Bot Herders at Their Own Game April 02, 2008
Despite their shady nature, bot herders -- those who hijack zombie computers in order to commit cyber crimes -- follow IT best practices to a surprisingly high degree. That's why they're sometimes so difficult to catch. Lit IP space analysis and actionable botnet intelligence are two useful tools at bot hunters' disposal.
Related News Alerts
More by Mike Pearson
Firefox Locks Out Microsoft's App Dev Tech October 19, 2009
Developers who use Firefox found themselves without some Microsoft add-ons after Mozilla blocked them due to security concerns. Browser access to one of the tools, .Net Framework Assistant, has been restored. The companies are working together to come up with a way to safely reopen access to Windows Presentation Foundation.
New WiFi Spec: Look Ma, No Hotspot October 14, 2009
The Wi-Fi Alliance believes it has come up with a secure, reliable technology that will allow WiFi-enabled devices to communicate with one another without the need for a hotspot. Devices using the spec will be able to communicate over the same ranges and at the same speeds as existing WiFi connections, the Alliance said.
GPS Safety, Part 2: Which Products Get It Right? October 06, 2009
Using a GPS navigation unit in the car may not be as dangerous as texting, but some kinds of devices are safer than others. Voice-activated controls let the user make commands without taking his or her eyes off the road. Larger screens are easier to glance at while driving, and if you're using a cellphone-based nav app, investing in a dash or window mount is probably a good decision.