Flow-level traffic analysis of the Blaster and Sobig worm outbreaks in an Internet backbone

被引:0
|
作者
Dübendorfer, T [1 ]
Wagner, A [1 ]
Hossmann, T [1 ]
Plattner, B [1 ]
机构
[1] ETH, Comp Engn & Networks Lab TIK, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present an extensive flow-level traffic analysis of the network worm Blaster.A and of the e-mail worm Sobig.F. Based on packet-level measurements with these worms in a testbed we defined flow-level filters. We then extracted the flows that carried malicious worm traffic from AS559 (SWITCH) border router backbone traffic that we had captured in the DDoSVax project. We discuss characteristics and anomalies detected during the outbreak phases, and present an in-depth analysis of partially and completely successful Blaster infections. Detailed flow-level traffic plots of the outbreaks are given. We found a short network test of a Blaster pre-release, significant changes of various traffic parameters, backscatter effects due to non-existent hosts, ineffectiveness of certain temporary port blocking countermeasures, and a surprisingly low frequency of successful worm code transmissions due to Blaster's multi-stage nature. Finally, we detected many TCP packet retransmissions due to Sobig.F's far too greedy spreading algorithm.
引用
收藏
页码:103 / 122
页数:20
相关论文
共 50 条
  • [41] Flow-level performance analysis of a multi-rate system supporting stream and elastic services
    Gero, B. P.
    Palyi, P. L.
    Racz, S.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2013, 26 (08) : 974 - 988
  • [42] Analysis and modeling of Internet backbone traffic with 5G/B5G
    Yang Y.
    Xu M.
    Chen H.
    Tongxin Xuebao/Journal on Communications, 2019, 40 (08): : 36 - 44
  • [43] Fair Internet traffic integration:: network flow models and analysis
    Key, P
    Massoulié, L
    Bain, A
    Kelly, F
    ANNALS OF TELECOMMUNICATIONS, 2004, 59 (11-12) : 1338 - 1352
  • [44] Internet of Things Traffic Characterization using flow and packet analysis
    Preda, Marius
    Bica, Ion
    Patriciu, Victor-Valeriu
    PROCEEDINGS OF THE 2020 12TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTERS AND ARTIFICIAL INTELLIGENCE (ECAI-2020), 2020,
  • [45] Traffic Analysis on the WIDE Backbone Link: From Transport Level to End User Activity
    Tamazian, Araik
    Markelov, Oleg
    Bogachev, Mikhail
    PROCEEDINGS OF THE 2016 IEEE NORTH WEST RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (ELCONRUSNW), 2016, : 356 - 359
  • [46] Flow-Level Analysis of Energy Efficiency Performance for Device-to-Device Communications in OFDM Cellular Networks
    Lei, Lei
    Zhao, Jing
    Zhong, Zhangdui
    Zheng, Kan
    COMPUTER JOURNAL, 2013, 56 (08): : 1001 - 1009
  • [47] Comparison and Analysis of Flow Features at the Packet Level for Traffic Classification
    Lu, Gang
    Zhang, Hongli
    Qassrawi, Mahmoud
    Yu, Xiangzhan
    2012 INTERNATIONAL CONFERENCE ON CONNECTED VEHICLES AND EXPO (ICCVE), 2012, : 262 - 267
  • [48] ANALYSIS OF THE INFLUENCE OF TRAFFIC FLOW VARIABILITY ON NOISE LEVEL ON ROADS
    Splawinska, Malwina
    ROADS AND BRIDGES-DROGI I MOSTY, 2019, 18 (02): : 135 - 150
  • [49] Network traffic flow analysis and its application in early detection of Internet worms
    Cai, Zhongmin
    Qin, Tao
    Guan, Xiaohong
    Ma, Xiaobo
    Zhou, Xiaoming
    DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2006, 13 : 1077 - 1080
  • [50] Intelligent Traffic Flow Prediction and Analysis Based on Internet of Things and Big Data
    Liu, Bing
    Zhang, Tao
    Hu, Weicheng
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022