why cant they tell the origin of botnets?

264 Views Asked by At

I was reading about bot-nets and was wondering why it is not possible to find the origin of these nets and route them out by identifying the origin computer which sets these up ?

I perhaps don't understand them very much so pardon my naive question.

Theoritically all traffic that originates from every computer has to go through an ISP, a bunch of intermediate routers and finally reach it's destination host. So if the ISPs monitor incoming and outgoing addresses they should be able to tell which IP addresses is making all these connections to a large number of destinations or some such heuristic...

In general these backbone providers and ISPS together essentially know where the connections from each computer go, so why not follow them ?

2

There are 2 best solutions below

4
On

Normally it's not a single computer that sets them up. Many botnets are propagated by a worm/virus/trojan, so it's only a bit simpler to find the originating host as it is to find the first guy with influenza.

Another problem is if the signal hops across several ISPs, it's not very easy to trace, since an ISP doesn't have access into the logs of the preceding ISPs in the chain, nor do they see the activity that is going on in hosts downchain from them. It takes a central authority like FBI to track things down, and even they have problems if connection hops through, say, Vanuatu.

0
On

The reason is because botnets are literally slaves of a main computer. The bots have been infected by viruses or rootkits that can be controlled and be told to do things remotely. This is normally small things, like DDoS. The controller is normally located on a VPS or dedicated server and can be moved from place to place so the origin is very hard to find.

Also saying that ISP's could just look for the connection. Thousands of connections come in from the internet every day to your computer. So routing through all these connections on the thousands of computers that are infected would consume vast amounts of time and could come up with nothing, as logs are not always kept.

I'm sure if ISP's wanted to they could track them, however it's a massive waste, in their eyes, of resources.