Re: mitigating botnet C&Cs has become useless

From: Sean Donelan (no email)
Date: Tue Aug 08 2006 - 12:06:42 EDT

  • Next message: Hank Nussbacher: "Re: SORBS Contact"

    On Tue, 8 Aug 2006, Arjan Hulsebos wrote:
    > We (ISPs) already do have that power, we can disconnect misbehaving
    > subscribers. And in cases like this, we should keep them off the 'net
    > until they've cleaned up their PC.

    Botnet C&Cs are not naturally occuring phenomena. Relying only on
    defensive security, and not arresting the criminals, will just result
    in the criminals becoming bolder and more aggressive.

    In most cases ISPs are just taking action against innocent bystanders that
    got hit in the cross-fire. Those bystanders aren't the cause. If you let
    the criminals continue trying over and over again, you are just training
    them to become better shots. Telling your customers they should wear
    bullet-proof vests whenever they go outside isn't going to stop snippers.
    Arresting the snipper is going to stop the snipper.


  • Next message: Hank Nussbacher: "Re: SORBS Contact"





    Hosted Email Solutions

    Invaluement Anti-Spam DNSBLs



    Powered By FreeBSD   Powered By FreeBSD