| Correcting congestion-based error in network telescope's observations of worm dynamics |
| Full text |
Pdf
(488 KB)
|
Source
|
Internet Measurement Conference
archive
Proceedings of the 8th ACM SIGCOMM conference on Internet measurement
table of contents
Vouliagmeni, Greece
SESSION: Internet coordinates and anomaly detection
table of contents
Pages 125-130
Year of Publication: 2008
ISBN:978-1-60558-334-1
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 16, Downloads (12 Months): 197, Citation Count: 0
|
|
|
ABSTRACT
Network telescopes have been invaluable for collecting information about dynamics of large-scale worm events. Yet, a telescope's observation may be incomplete due to scan congestion drops, hardware limitations, filtering and presence of NATs, a worm's non-uniform scanning strategy or its short life. We investigate inaccuracies in telescope observations that arise from worm-induced congestion drops of worm scans and show that they may lead to significant underestimates of the number of infectees and their scanning rate. We propose a method to infer worm-induced congestion drops from telescope's observations and use them to accurately estimate global worm dynamics. We apply our methods to CAIDA telescope's observations of Witty worm's spread, and release corrected statistics of worm dynamics for public use.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
David Moore , Vern Paxson , Stefan Savage , Colleen Shannon , Stuart Staniford , Nicholas Weaver, Inside the Slammer Worm, IEEE Security and Privacy, v.1 n.4, p.33-39, July 2003
[doi> 10.1109/MSECP.2003.1219056]
|
 |
2
|
|
| |
3
|
|
| |
4
|
|
| |
5
|
Colleen Shannon and David Moore. The CAIDA Dataset on the Witty Worm. http://www.caida.org/data/passive/witty_worm_dataset.xml/.
|
| |
6
|
|
 |
7
|
|
| |
8
|
Ihab Hamadeh and George Kesidis. Toward a Framework for Forensic Analysis of Scanning Worms. In Proc. of ETRICS International Conference, Jun 2006.
|
 |
9
|
|
| |
10
|
David Moore, Collen Shannon, Geoffrey Voelker, and Stefan Savage. Network Telescopes: Technical Report. CAIDA technical report, 2004.
|
| |
11
|
|
| |
12
|
CAIDA. Network Telescope. http://www.caida.org/research/security/telescope,.
|
| |
13
|
University of Wisconsin-Madison Advanced Internet Lab. Web page. http://wail.cs.wisc.edu.
|
 |
14
|
|
 |
15
|
|
| |
16
|
George Cassella and Roger L. Berger. Statistical Inference. Duxburg Press, 2nd edition, 2001.
|
| |
17
|
University of Oregon. Route Views Project. http://www.routeviews.org.
|
| |
18
|
CAIDA. Internet Measurement Data Catalog. http://www.datcat.org.
|
|