The best defense would be for everything online to run only secure software, so botnets couldn’t be created in the first place. This isn’t going to happen anytime soon. Internet of things devices are not designed with security in mind and often have no way of being patched. The things that have become part of Mirai botnets, for example, will be vulnerable until their owners throw them away. Botnets will get larger and more powerful simply because the number of vulnerable devices will go up by orders of magnitude over the next few years.
Botnets are used to commit click fraud.
Similarly, botnets can be used to evade spam filters, which work partly by knowing which computers are sending millions of e-mails. They can speed up password guessing to break into online accounts, mine bitcoins, and do anything else that requires a large network of computers. This is why botnets are big businesses. Criminal organizations rent time on them.
But the botnet activities that most often make headlines are denial-of-service attacks. Political groups use them to silence websites they don’t like.
But overall, the trends favor the attacker. Expect more attacks like the one against Dyn in the coming year.
Bruce Schneier, chief technology officer at IBM Resilient, is the author of 13 books on cryptography and data security.
See the full story here: https://www.technologyreview.com/s/603500/10-breakthrough-technologies-2017-botnets-of-things/