Latest Trending Discover Timelines Categories
All explainers

Technology explainer

How Can Defenders Disrupt a Botnet With No Central Server?

Peer-to-peer botnets replace a central command server with a web of infected devices. Defenders can still intervene by exploiting how those devices discover peers, trust updates and refresh their view of the network.

A conventional botnet often depends on one or more command-and-control servers. Seizing those servers or their domains can sever the operator's connection to infected devices. A peer-to-peer botnet removes that obvious target by allowing bots to pass commands directly among themselves.

How peers find one another

Each infected device needs a starting list of reachable peers and rules for updating it. Some nodes may act as super peers because they are publicly reachable and remain online for long periods. The protocol decides which entries are trusted, when inactive peers are removed and how new addresses spread.

Where defenders can intervene

Investigators can reverse-engineer the protocol and introduce defender-controlled nodes called sinkholes. If bots accept these entries, their peer lists can gradually shift away from criminal infrastructure. Domain seizures, cryptographic weaknesses or software-update mechanisms may provide additional points of control.

Disruption is not disinfection

A successful sinkhole can stop new commands and reveal infected addresses, but it usually cannot remove malware from private computers. Internet providers and incident-response teams must notify victims, investigate affected systems and clean or rebuild them. The operator may also modify the protocol or launch a replacement network, so defenders must watch whether control returns.

First appeared in

A 23-Year-Old Botnet Was Tricked Into Cutting Off Its Own Computers

A new version of NewTqnia is ready.