RE: [Theory] P2P botnet 07-22-2014, 08:40 AM
#9
Then don't implement NAT punchthrough until later, using the scripting interface I'm sure you have.
A few things.
1) Your node structure leaks too much information to each secure peer trying to get into the network. Instead of broadcasting all known nodes to the secure peer, only a handful should be broadcast, keeping it so totalNodes - n >= n whenever possible. This prevents an adversary from downing your entire network off of one infected client.
2) If you ever have to do weird things like distribute a private key, you're likely doing something wrong. Instead, you should have mandatory sign AND encrypt for inter-node comms. When a node receives a command that successfully decrypts, and is signed with the admin key, it redistributes the signed and encrypted message as it was originally received.
3) You should ALWAYS verify receipt of comms, especially of a command, whenever possible. To verify that a node received a command, the admin node would only need be configured to have a list of what nodes have broadcast the command to the admin node, while determining if the endpoints had received the command would be more complicated.
A few things.
1) Your node structure leaks too much information to each secure peer trying to get into the network. Instead of broadcasting all known nodes to the secure peer, only a handful should be broadcast, keeping it so totalNodes - n >= n whenever possible. This prevents an adversary from downing your entire network off of one infected client.
2) If you ever have to do weird things like distribute a private key, you're likely doing something wrong. Instead, you should have mandatory sign AND encrypt for inter-node comms. When a node receives a command that successfully decrypts, and is signed with the admin key, it redistributes the signed and encrypted message as it was originally received.
3) You should ALWAYS verify receipt of comms, especially of a command, whenever possible. To verify that a node received a command, the admin node would only need be configured to have a list of what nodes have broadcast the command to the admin node, while determining if the endpoints had received the command would be more complicated.






![[+]](https://sinister.li/images/modern/collapse_collapsed.png)