New free tool detects malware on networks

A new tool is being used within the U.S. government and the Department of Defense to fight malware on their networks.

The free, downloadable malware-detection tool, called BotHunter, was sponsored by the U.S. Army Research Office,
and there have been 35,000 downloads so far, Phillip Porras, program director of enterprise and infrastructure security at SRI International, a research and technology organization, and lead developer of the BotHunter project, told SCMagazineUS.com Tuesday.

“It works so well that it has even found infected Mac computers, much to the embarrassment of the Mac owners who, of course, swear that their computers cannot be infected with bots,” Marcus Sachs, director at SANS Internet Storm Center, told SCMagazineUS.com Tuesday in an email.

The tool was developed by SRI International and funded through a Cyber-Threat Analytics research grant from the U.S. Army Research Office.

It reportedly helps Windows, Mac and Linux users detect malware-infected hosts on their networks by tracking interactions that typically occur when a PC is infected with malware, Porras said. The tool will generate an infection profile with all the forensic evidence that was gathered.

The infection profile report will then allow users to determine which machines on the network are acting like they are infected. The tool anonymizes infection profiles and passes them back to SRI, where they go into a repository that is used to help generate new threat intelligence.

BotHunter will not clean up machines. If infected, Porras recommended removing the machine from the network and running various removal tools –  including anti-virus and spyware solutions – to try and clear up infection. 

Botnet-infected machines remain a pervasive threat. In September, internet intelligence organization Shadowserver Foundation reported the number of zombie computers quadrupled during a three-month span, coinciding with a rise in SQL injection attacks.

Nearly 200 researchers, law enforcement officers and academics met last month at the International Botnet Task Force gathering in Arlington, Va. The organization was formed by Microsoft in 2004 to share information and investigation case studies.

 


Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.