[91598] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: mitigating botnet C&Cs has become useless

daemon@ATHENA.MIT.EDU (Sean Donelan)
Tue Aug 8 12:07:15 2006

Date: Tue, 8 Aug 2006 12:06:42 -0400 (EDT)
From: Sean Donelan <sean@donelan.com>
To: NANOG <nanog@merit.edu>
In-Reply-To: <18ccbaee0608080703y10c8e6ffne778a98734b8f898@mail.gmail.com>
Errors-To: owner-nanog@merit.edu


On Tue, 8 Aug 2006, Arjan Hulsebos wrote:
> We (ISPs) already do have that power, we can disconnect misbehaving
> subscribers. And in cases like this, we should keep them off the 'net
> until they've cleaned up their PC.

Botnet C&Cs are not naturally occuring phenomena.  Relying only on 
defensive security, and not arresting the criminals, will just result
in the criminals becoming bolder and more aggressive.

In most cases ISPs are just taking action against innocent bystanders that 
got hit in the cross-fire. Those bystanders aren't the cause. If you let 
the criminals continue trying over and over again, you are just training 
them to become better shots.  Telling your customers they should wear
bullet-proof vests whenever they go outside isn't going to stop snippers.
Arresting the snipper is going to stop the snipper.

home help back first fref pref prev next nref lref last post