Flow-level traffic analysis of the Blaster and Sobig worm outbreaks in an Internet backbone

被引:0
|
作者
Dübendorfer, T [1 ]
Wagner, A [1 ]
Hossmann, T [1 ]
Plattner, B [1 ]
机构
[1] ETH, Comp Engn & Networks Lab TIK, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an extensive flow-level traffic analysis of the network worm Blaster.A and of the e-mail worm Sobig.F. Based on packet-level measurements with these worms in a testbed we defined flow-level filters. We then extracted the flows that carried malicious worm traffic from AS559 (SWITCH) border router backbone traffic that we had captured in the DDoSVax project. We discuss characteristics and anomalies detected during the outbreak phases, and present an in-depth analysis of partially and completely successful Blaster infections. Detailed flow-level traffic plots of the outbreaks are given. We found a short network test of a Blaster pre-release, significant changes of various traffic parameters, backscatter effects due to non-existent hosts, ineffectiveness of certain temporary port blocking countermeasures, and a surprisingly low frequency of successful worm code transmissions due to Blaster's multi-stage nature. Finally, we detected many TCP packet retransmissions due to Sobig.F's far too greedy spreading algorithm.
引用
收藏
页码:103 / 122
页数:20
相关论文
共 50 条
  • [21] TCP Flow-Level Traffic Model for Evaluating LTE-Advanced Networks
    Lossow, Moritz
    Arnold, Paul
    Droste, Heinz
    Kadel, Gerhard
    2016 EIGHTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN), 2016, : 1026 - 1030
  • [22] A Flow-Level Performance Model for Mobile Networks Carrying Adaptive Streaming Traffic
    Bonald, Thomas
    Elayoubi, Salah Eddine
    Lin, Yu-Ting
    2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [23] A Flow-Level Performance Evaluation of Elastic Traffic under Low Latency Queuing System
    Boussada, Mohamed El Hedi
    Frikha, Mounir
    Garcia, Jean Marie
    PROCEEDINGS 2018 IEEE 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2018, : 205 - 212
  • [24] Traffic measurement and analysis in an ATM-based internet backbone
    Kawahara, R
    Ishibashi, K
    Hirano, T
    Saito, H
    Ohara, H
    Satoh, D
    Asano, S
    Matsukata, J
    COMPUTER COMMUNICATIONS, 2001, 24 (15-16) : 1508 - 1524
  • [25] Impact of Access Bandwidth on Packet Loss: A Flow-level Analysis
    Mehmood, Muhammad Amir
    Sarrar, Nadi
    Uhlig, Steve
    Feldmann, Anja
    2013 IEEE MALAYSIA INTERNATIONAL CONFERENCE ON COMMUNICATIONS (MICC), 2013, : 259 - 264
  • [26] Flow-level performance analysis of some opportunistic scheduling algorithms
    Bonald, T
    EUROPEAN TRANSACTIONS ON TELECOMMUNICATIONS, 2005, 16 (01): : 65 - 75
  • [27] Statistical traffic identification method based on flow-level behavior for fair VoIP service
    Okabe, Toshiya
    Kitamura, Tsutomu
    Shizuno, Takayuki
    VOIP MASE 06: 1ST IEEE WORKSHOP ON VOIP MANAGEMENT AND SECURITY: SECURING AND MANAGING VOIP COMMUNICATIONS, 2006, : 35 - +
  • [28] Multifractal Analysis of Internet Backbone Traffic for Detecting Denial of Service Attacks
    Zegzhda, P. D.
    Lavrova, D. S.
    Shtyrkina, A. A.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2018, 52 (08) : 936 - 944
  • [29] Multi-Cell Flow-Level Performance of Traffic-Adaptive Beamforming under Realistic Spatial Traffic Conditions
    Klessig, Henrik
    Soszka, Maciej
    Fettweis, Gerhard
    2015 12TH INTERNATIONAL SYMPOSIUM ON WIRELESS COMMUNICATION SYSTEMS (ISWCS), 2015,
  • [30] Flow-Level Delay Optimization with Traffic Adaption and Inter-Cell Interference Coordination in Cellular Networks
    Liu, Bei
    Zhao, Ming
    Liang, Xiaowen
    Zhu, Jinkang
    2014 SIXTH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS AND SIGNAL PROCESSING (WCSP), 2014,