ACM Home Page
Please provide us with feedback. Feedback
Correcting congestion-based error in network telescope's observations of worm dynamics
Full text PdfPdf (488 KB)
Source
Internet Measurement Conference archive
Proceedings of the 8th ACM SIGCOMM conference on Internet measurement table of contents
Vouliagmeni, Greece
SESSION: Internet coordinates and anomaly detection table of contents
Pages 125-130  
Year of Publication: 2008
ISBN:978-1-60558-334-1
Authors
Songjie Wei  University of Delaware, Newark, DE, USA
Jelena Mirkovic  University of Southern California, Marina Del Rey, CA, USA
Sponsors
SIGCOMM: ACM Special Interest Group on Data Communication
SIGMETRICS: ACM Special Interest Group on Measurement and Evaluation
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 16,   Downloads (12 Months): 197,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1452520.1452536
What is a DOI?

ABSTRACT

Network telescopes have been invaluable for collecting information about dynamics of large-scale worm events. Yet, a telescope's observation may be incomplete due to scan congestion drops, hardware limitations, filtering and presence of NATs, a worm's non-uniform scanning strategy or its short life. We investigate inaccuracies in telescope observations that arise from worm-induced congestion drops of worm scans and show that they may lead to significant underestimates of the number of infectees and their scanning rate. We propose a method to infer worm-induced congestion drops from telescope's observations and use them to accurately estimate global worm dynamics. We apply our methods to CAIDA telescope's observations of Witty worm's spread, and release corrected statistics of worm dynamics for public use.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
 
3
 
4
 
5
Colleen Shannon and David Moore. The CAIDA Dataset on the Witty Worm. http://www.caida.org/data/passive/witty_worm_dataset.xml/.
 
6
7
 
8
Ihab Hamadeh and George Kesidis. Toward a Framework for Forensic Analysis of Scanning Worms. In Proc. of ETRICS International Conference, Jun 2006.
9
 
10
David Moore, Collen Shannon, Geoffrey Voelker, and Stefan Savage. Network Telescopes: Technical Report. CAIDA technical report, 2004.
 
11
 
12
CAIDA. Network Telescope. http://www.caida.org/research/security/telescope,.
 
13
University of Wisconsin-Madison Advanced Internet Lab. Web page. http://wail.cs.wisc.edu.
14
15
 
16
George Cassella and Roger L. Berger. Statistical Inference. Duxburg Press, 2nd edition, 2001.
 
17
University of Oregon. Route Views Project. http://www.routeviews.org.
 
18
CAIDA. Internet Measurement Data Catalog. http://www.datcat.org.

Collaborative Colleagues:
Songjie Wei: colleagues
Jelena Mirkovic: colleagues