Flow-level traffic analysis of the Blaster and Sobig worm outbreaks in an Internet backbone

被引:0
|
作者
Dübendorfer, T [1 ]
Wagner, A [1 ]
Hossmann, T [1 ]
Plattner, B [1 ]
机构
[1] ETH, Comp Engn & Networks Lab TIK, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an extensive flow-level traffic analysis of the network worm Blaster.A and of the e-mail worm Sobig.F. Based on packet-level measurements with these worms in a testbed we defined flow-level filters. We then extracted the flows that carried malicious worm traffic from AS559 (SWITCH) border router backbone traffic that we had captured in the DDoSVax project. We discuss characteristics and anomalies detected during the outbreak phases, and present an in-depth analysis of partially and completely successful Blaster infections. Detailed flow-level traffic plots of the outbreaks are given. We found a short network test of a Blaster pre-release, significant changes of various traffic parameters, backscatter effects due to non-existent hosts, ineffectiveness of certain temporary port blocking countermeasures, and a surprisingly low frequency of successful worm code transmissions due to Blaster's multi-stage nature. Finally, we detected many TCP packet retransmissions due to Sobig.F's far too greedy spreading algorithm.
引用
收藏
页码:103 / 122
页数:20
相关论文
共 50 条
  • [1] Modeling Internet backbone traffic at the flow level
    Barakat, C
    Thiran, P
    Iannaccone, G
    Diot, C
    Owezarski, P
    IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2003, 51 (08) : 2111 - 2124
  • [2] FLEO: A Flow-Level Network Simulator for Traffic Engineering Analysis
    Anggono, Gilbert
    Moors, Tim
    25TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC 2015), 2015, : 131 - 136
  • [3] Tuning the EDCA parameters in WLANs with heterogeneous traffic: A flow-level analysis
    Cano, C.
    Bellalta, B.
    Sfairopoulou, A.
    Barcelo, J.
    COMPUTER NETWORKS, 2010, 54 (13) : 2199 - 2214
  • [4] On the Design of Irregular HetNets with Flow-Level Traffic Dynamics
    Shojaeifard, Arman
    Hamdi, Khairi Ashour
    Alsusa, Emad
    So, Daniel K. C.
    Wong, Kai-Kit
    2016 IEEE 84TH VEHICULAR TECHNOLOGY CONFERENCE (VTC FALL), 2016,
  • [5] SubFlow: Towards Practical Flow-Level Traffic Classification
    Xie, Guowu
    Iliofotou, Marios
    Keralapura, Ram
    Faloutsos, Michalis
    Nucci, Antonio
    2012 PROCEEDINGS IEEE INFOCOM, 2012, : 2541 - 2545
  • [6] Accurate Rate-Aware Flow-level Traffic Splitting
    Wu, Ning
    Tseng, Shih-Hao
    Tang, Ao
    2018 56TH ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2018, : 774 - 783
  • [7] Flow-level and efficient traffic engineering in conventional routing systems
    Geng, Nan
    Yang, Yuan
    Xu, Mingwei
    COMPUTER NETWORKS, 2021, 185
  • [8] A flow-based model for Internet backbone traffic
    Barakat, C
    Thiran, P
    Iannaccone, G
    Diot, C
    Owezarski, P
    IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, 2002, : 35 - 47
  • [9] An Accurate and Extensible Machine Learning Classifier for Flow-Level Traffic Classification
    Lu, Gang
    Guo, Ronghua
    Zhou, Ying
    Du, Jing
    CHINA COMMUNICATIONS, 2018, 15 (06) : 125 - 138
  • [10] Flow-level traffic model for adaptive streaming services in mobile networks
    Lin, Yu-Ting
    Bonald, Thomas
    Elayoubi, Salah Eddine
    COMPUTER NETWORKS, 2018, 137 : 1 - 16