Welcome | Sign In
CRMBuyer.com
Kernel

1 Million Linux Kernels Booted for Vast Botnet Simulation

Print Version
E-Mail Article
Reprints
1 Million Linux Kernels Booted for Vast Botnet Simulation

Computer security researchers still don't know much about how botnets work. At Sandia National Laboratories, though, scientists are preparing for a massive experiment. They've booted up 1 million Linux kernels as virtual machines, which will allow them to observe the behavior of a simulated network of 10 million computers online at once -- complete with users who get infected with botnets.


To thrive in today’s highly competitive business environment, you need innovative approaches to attract and retain customers. Click here to see how Salesforce.com, West Marine, and VForce-AAA Ohio use LiveOps to optimize their customer experiences.

Researchers at Sandia National Laboratories have laid the groundwork for an unprecedented simulation of a large-scale botnet after booting up 1 million Linux kernels as virtual machines.

Sandia computer scientists Ron Minnich (foreground) and Don Rudish (background) have successfully run more than a million Linux kernels as virtual machines.
(click image to enlarge)

They now are waiting for completion of a new, faster and more capable supercomputer at the Livermore, Calif., lab, on which they hope to run 10 million kernels in a simulation of the open Internet -- complete with Web and mail servers, as well as simulated users clicking on simulated emails, getting simulated infections, and joining a simulated botnet.

A kernel is the core component of the operating system that passes instructions between hardware and software. To make the unprecedented achievement of running 1 million kernels as virtual machines, researchers stripped out support Learn how SugarCRM will improve your business. Free Trial. Click here. for extraneous devices like Bluetooth and wireless connectivity.

Managing a Challenge

They still had difficulty keeping up with all of the virtual machines, said Sandia computer science researcher Don Rudish, who worked on the experiment.

For instance, the Ethernet switch on the lab's supercomputer, called "Thunderbird," wasn't designed to recognize one million MAC addresses online.

"After 100,000, the whole network came to a crawl," Rudish told LinuxInsider. "Just looking through 1 million lines on a text log takes some time."

While the experiment was a success, Rudish said researchers didn't entirely solve the issue of monitoring the vast network, even after working out ways to visualize some of the data and reduce the amount of information flowing to them.

Virtual Botnet

They hope to solve that in the future by using botnet behavior to help control the network, Rudish said.

Unfortunately, researchers still don't know much about how botnets actually work. So, they're planning to use the lab's new Red Sky supercomputer, currently under construction, to create a 10 million kernel system and introduce botnet software into the system to see what happens, Rudish said.

Other researchers have simulated the behavior of botnets in computer models, but little is known about how they really operate. Sandia's experiment will be different because it's much closer to an actual real-world application with what will look to the network like 10 million computers online at once, he said.

"It's implemented in software, so you can say it's a simulation, but it's a much better one in that you're running real code, real TCP stacks," Rudish said.

Some of the computers will be programmed to act as Web and mail servers, others as simulated users with a percentage chance to click on incoming "emails" -- some of which will download botnet software to infect the virtual machine. That machine will then take on one of several roles in the botnet: storage server, Web server, or aggressor seeking to further propagate the botnet's control.

The experiment should give researchers more insight into how botnets work and how to combat them, Rudish said.

Project Cost

It's difficult to calculate the cost of the 1 million kernel experiment because so much of the technology that went into it was developed for other purposes, explained Rudish.

However, direct costs ran about US$100,000, he said. The Department of Energy's Office of Science, the National Nuclear Security Administration, and Sandia funded the project.


Print Version E-Mail Article Reprints More by Mike Pearson


Talkback: Join the Discussion.
This is stupid
hairyfeet
Posted 2009-08-03
Why on this green earth would you create a botnet in Wine? What are they, nuts? They spent all ...
already making excuses.
skepticaljohn
Posted 2009-08-01
"...looking through 1 million lines on a text log .." ...
yeah, right
skepticaljohn
Posted 2009-08-01
I will be waiting for actual results, but I won't hold my breath. Certain folks at a large DOE ...
Running on Linux?
Runaway1956
Posted 2009-07-31
Article is somewhat misleading, in that it implies the botnet is "running on Linux". ...

More by Mike Pearson

Microsoft Gives Devs a Glimpse of HTML 5-Friendly IE9
March 17, 2010
Microsoft's preview of IE9 got a warm reception at MIX10 for its speed and support for HTML 5. However, XP diehards won't be able to use it, due to advances intended to reduce limitations on Web design and development. Creating a great next version of Explorer is critical for Microsoft as it attempts to build on the early success of Windows 7.
Facebook Traffic: A Whole Lot of Hustle but Not Much Flow
March 17, 2010
What does the mad rush of traffic to Facebook mean, really? The social networking colossus drew more traffic than Google for the third time this year, but Facebook still hasn't figured out how to turn all that activity into gold. It's not as though users are turning to Facebook as their primary Internet search tool -- and advertisers apparently don't see it that way either.
Analyst: WinPho7 App Tools Likely to Please Devs
March 15, 2010
Microsoft could become a contender in the smartphone space after all. It just introduced a set of developer tools for its Windows Phone 7 Series operating system with an emphasis on gaming. "If you think abut the smartest devices in the land -- prior to the iPhone -- that were mobile and handheld, they were the Nintendo Game Boys, the DSis and so on," noted IDC analyst Al Hilwa.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network