Exploiting underlying structure for detailed reconstruction of an internet-scale event
Explore this paper's citation graph
Summary
It is shown that by carefully exploiting the structure of the worm, especially its pseudo-random number generation, from limited and imperfect telescope data, this work can with high fidelity extract the individual rate at which each infectee injected packets into the network prior to loss.
- Type
- article
- Published
- 2005-11-11
- Cited by
- 81
- References
- 23
- OpenAlex
- https://openalex.org/W3216912485
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:16321045
Keywords
Computer science, Scale (ratio), Event (particle physics), The Internet, World Wide Web
References
- The Spread of the Sapphire/Slammer Worm
- Network Telescopes: Technical Report
- The Internet Motion Sensor - A Distributed Blackhole Monitoring System
- The internet worm program: an analysis
- Code red worm propagation modeling and analysis
- Inside the Slammer Worm
- The Spread of the Witty Worm
- Code-Red: a case study on the spread and victims of an internet worm
- With microscope and tweezers: an analysis of the Internet virus of November 1988
- Toward understanding distributed blackhole placement
- Characteristics of internet background radiation
- The Art of Computer Programming
- Code red worm propagation modeling and analysis
- Inferring Internet denial-of-service activity
- How to 0wn the Internet in Your Spare Time
Cited by
- Is Host-Based Anomaly Detection + Temporal Correlation = Worm Causality
- Rethinking Antivirus: Executable Analysis in the Network Cloud
- The Dark Oracle: Perspective-Aware Unused and Unreachable Address Discovery
- CloudAV: N-Version Antivirus in the Network Cloud
- Leveraging the Cloud for Software Security Services
- On the use of context in network intrusion detection systems
- Principal Component Analysis of Port-scans for Reduction of Distributed Sensors
- Fibonacci Modeling of Malware Propagation
- Scalable Long-term Network Forensics for Epidemic Attacks
- A baseline study of potentially malicious activity across five network telescopes
- SANE: A Protection Architecture for Enterprise Networks
- Characterizing Internet Worm Infection Structure
- Models to Combat Email Spam Botnets and Unwanted Phone Calls
- An empirical study of malware evolution
- Outside the Closed World: On Using Machine Learning for Network Intrusion Detection
- High-Speed Application Protocol Parsing and Extraction for Deep Flow Inspection
- Internet background radiation revisited
- Darknet-Based Inference of Internet Worm Temporal Characteristics
- On the impact of dynamic addressing on malware propagation
- Leveraging Internet Background Radiation for Opportunistic Network Analysis
Related papers
- Design and Implement a IDS Based on Event driven
- PHP Event Mechanism Based on Hidden Field
- Method of complex events detection based on shared matching results
- Unpredictable event and internet user activities: a study on network event and social network interference with information entrophy
- Development and validation of an internet entrepreneurial self-efficacy scale
- Determination of the linguopragmatic potential of a conflict Internet commentary by the context of the event
- On the scale making and characteristics of young people's internet communication
- Design and Application of Immoral Internet Behavior Scale——The Study of College Students Internet Users as a Case