Of Botnets and CISA

Sheldon Whitehouse's amendment to tackle botnets in the Senate cyber bill failed. How much good might the legislation have done?

broken lock

Sen. Sheldon Whitehouse's (D-R.I.) CISA amendment to tackle botnets failed.

In one of the more colorful episodes of the Senate's recent debate on the Cybersecurity Information Sharing Act, Rhode Island Democrat Sheldon Whitehouse solemnly took to the podium to wonder if there was "some hidden pro-botnet, pro-foreign cybercriminal caucus here that won't let a bill like mine get a vote."

Whitehouse grew exasperated during the late-October speech, as he mused about why lawmakers would not consider his amendment to crack down on botnets, the armies of computers that are high-jacked to distribute spam or carry out distributed denial-of-service attacks. The amendment was bipartisan and supported by the Justice Department, but still missed the boat, Whitehouse lamented.

The Senate approved CISA on Oct. 27.  Yet Whitehouse's proposed changes were provocative enough that debate over them continues.

The amendment would have updated a legal injunction against fraud to include botnets. It also would have added broad language to the legal code to target anyone who "intentionally traffics in the means of access to a protected computer."

That measure and others in the amendment drew the ire of a coalition of civil liberties groups and security experts. The amendment would have expanded prohibited behavior to include "means of access" to a computer, "without clarifying how the law applies to legitimate computer security research," groups such as the Electronic Frontier Foundation and the Government Accountability Project wrote in an open letter.

Tony Cole, vice president and global government CTO at FireEye, a cybersecurity firm, echoed those concerns. The Whitehouse amendment was "vague enough where it could have unintended consequences on cyber researchers that are trying to help us and could potentially open new avenues for prosecution of researchers," he said.

Whitehouse argued that the amendment would empower the DOJ to proactively take down botnets rather than waiting for the commandeered computers to do harm to American citizens. A spokesperson for Whitehouse did not respond to questions on the senator's future plans for botnet legislation.

The Rhode Island Democrat knows far more about botnets than other lawmakers, but still fell short in his attempt at legislation because it was vaguely worded to the point of potentially criminalizing research in the public good, said Paul Vixie, an Internet security expert who has helped take down botnets.

"What we need to do is to define responsible disclosure" of discoveries of malicious computer activity such as botnets and zero-day threats, added Vixie, who is CEO of Farsight Security. "Right now, responsible disclosure is pretty well understood by industry but not at all by government."

But not all IT security experts interviewed by FCW were opposed to the Whitehouse amendment. Cheri McGuire, a vice president at Symantec, said her firm supported the amendment because it would have provided a clearer framework for shutting down botnets.

"We need to ensure our law enforcement is equipped with the tools to effectively fight botnets and cybercrime," McGuire said.

Zombies on the cheap

As with many other cyber exploits, the economics of botnets favor the attacker. A look at 20 botnets-for-hire by cybersecurity firm Imperva found their average cost to be just $38 per month.

Crackdowns by the FBI, Europol and other law enforcement agencies have in the last year cut down on the number of bots in circulation, with an 18 percent decline in botnets in 2014 compared to 2013, according to a Symantec report.

Estimates of bots in circulation vary. Cybersecurity firm Trend Micro puts the number of bots active in the last two weeks at about 5.5 million.

But while botnets can be disruptive and wreak financial havoc, Justin Harvey, chief security officer at Fidelis Cybersecurity, said the zombie computer armies are less acute of a cyber threat than, say, attempts to hack sensitive government or commercial data. The botnet problem, like a lot of computer security challenges, can't be legislated away, he added.

There will always be the technological means for cyber criminals to target endpoints, Harvey said. "If certain nefarious characters want to figure out how to harness a lot of those people's computers into attacking some other organization, it's going to happen, regardless of what lawmakers want to do."

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.