Follow Us

Malware authors adopt domain generation algorithms to evade detection

Domain generation algorithms are increasingly used to evade network filters and protect botnets from takedown attempts

Malware authors are increasingly adopting flexible domain generation algorithms (DGAs) in order to evade detection and prevent their botnets from being shut down by security researchers or law enforcement agencies.

DGAs are generally used as a fallback mechanism for sending instructions to infected computers when the hard-coded command and control (C&C) servers become unavailable.

The algorithms generate a list of unique pseudo-random domain names every day. Clients in a botnet attempt to connect to them and receive commands when the primary servers can't be reached.

Knowing the algorithm allows malware authors to predict which domain names infected computers will attempt to access on a certain date, so they can register one of them in advance.

The infamous Conficker worm used a domain generation algorithm for receiving instructions from its creators. This brought the technique to the public's attention for a short time in 2009.

Customisable DGA modules are now available

However, DGAs have advanced considerably since then, said Gunter Ollmann, vice president of research at network security vendor Damballa. According to Ollmann, there's a trend in malware development to implement DGAs in order to evade security systems that rely on domain name reputation, blacklists or signatures.

Customisable DGA modules are now available for some of the most popular crimeware packs, such as ZeuS, which means each botnet based on them will contact its own list of domain names.

That makes it very hard to shut them down, especially for law enforcement authorities, which have little time - around 24 hours - to investigate a C&C server, Ollmann said.

By the time the authorities get a subpoena and take control of a temporary domain name to perform forensics, the cybercriminals will likely already have switched to a new one.

Six new malware families now using DGA 

Even security vendors have had a hard time identifying the use of DGAs in certain types of malware or accounting for it when building detection, Ollmann said.

Damballa has studied DGAs for the past year and plans to present a research paper on the subject this Tuesday at the RSA Conference 2012 in San Francisco.

The company has identified six new malware families that use DGA for evasion purposes during the past 12 months. The malware families are used by dozens of cybercrime organisations.

Six additional types of DGAs have been spotted on large networks, but it's not clear what malware families are using them because samples could not be obtained from the infected clients.

The availability of the ZeuS source code on the Internet and cybercriminals' need to protect their botnets from takedowns are likely to push more malware developers to adopt DGAs in the future, Ollmann said.




Comments

James said: Malware authors are increasingly adopting flexible domain generation algorithms DGAs in order to evade detection and prevent



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *