What is a botnet-driven denial-of-service attack?¶
The practical answer¶
A botnet-driven denial-of-service attack uses many compromised devices or automated agents to generate disruptive traffic.
The key evidential caution¶
The dangerous assumption is that the owners of the participating devices knowingly took part.
They may be victims whose systems were infected or remotely controlled.
A botnet may include:
Key points¶
- home routers
- servers
- computers
- mobile devices
- internet-connected cameras
- cloud systems
- other compromised infrastructure
What investigators should establish¶
Investigators should identify:
Key points¶
- the attack command or coordination pattern
- participating source addresses
- malware or agent involved
- timing
- target
- traffic type
- common configuration
- control infrastructure
- provider records
Similar timing and request patterns may support common tasking.
But one source may also be a proxy, scanner or unrelated system.
Evidential limits¶
Do not infer one human decision from every packet. A single command may trigger thousands of devices automatically.
Where a participating device is examined, preserve malware, control-channel evidence, tasking and local owner context.
Practical interpretation¶
Where several bot sources are examined, compare malware, configuration, tasking time and target details. Common features may support central control, but differences may show several botnets or unrelated infected devices. Preserve the distinction between the person operating the botnet and the owner of any individual participating system.
Botnet traffic may continue after the controller stops active tasking because devices retain scheduled instructions or retry failed commands. Distinguish initial tasking from autonomous continuation and record whether the traffic pattern changes after control infrastructure is blocked.
Where possible, compare participating devices with known botnet infrastructure or malware configuration. A shared target and timing pattern can support common coordination, but should not replace direct evidence from a seized device, provider record or control channel.
Operational takeaway¶
Distinguish bot operator, control infrastructure, compromised devices and innocent owners, and attribute each layer only at the level the evidence supports.