It's not so easy.
Type your comment here — plain text only, no HTML
Firewall management isn't really the solution seeing as HTTP seems to be the communication route taken by bots. Unless you have trained your staff to specifically track encoded traffic of a size unknown, either incoming or/and outgoing. For eg, as far as I know Zeus/Zbot uses RC4 but I could be wrong. Also I think, most bots will be scantime and runtime crypted against AV detection, ie physically undectable and memorially undetectable.
This is why botnets grow to such a size, and infect systems where more than average protection and security is employed. The spread of conficker only confirms that. Corporations spend more on system security than your average Joe, this being that they probably have more resources to protect, which makes them all the more attractive to bot herders, they also have more resources to exploit.
Perhaps it's time to look at the quality of protection these companies are employing, not the quantity.


