The Experts below are selected from a list of 201 Experts worldwide ranked by ideXlab platform
Daniela Brauckhoff - One of the best experts on this subject based on the ideXlab platform.
-
The Effect of Packet Sampling on Anomaly Detection
2012Co-Authors: Daniela Brauckhoff, Arno Wagner, Bernhard Tellenbach, Anukool Lakhina, Martin MayAbstract:Packet sampling methods such as Cisco’s NetFlow are widely employed by large networks to reduce the amount of traffic data measured. A key problem with packet sampling is that it is inherently a lossy process, discarding (potentially useful) information. In this paper, we empirically evaluate the impact of sampling on anomaly detection. Starting with unsampled traffic records collected during the Blaster Worm outbreak, we reconstruct the underlying packet trace and simulate packet sampling at increasing rates. We then use our knowledge of the Blaster anomaly to build a baseline of normal traffic (without Blaster), against which we can measure the anomaly size at various sampling rates. This approach allows us to evaluate the impact of packet sampling on anomaly detection without being restricted to (or biased by) a particular anomaly detection method. We find that packet sampling does not disturb the anomaly size when measured in volume metrics such as the number of bytes and number of packets, but grossly biases the number of flows. However, we find that recently proposed entropy-based summarizations of packet and flow counts are affected less by sampling, and expose the Blaster Worm outbreak even at higher sampling rates. Our findings suggest that entropy summarizations are more resilient to sampling than volume metrics. Thus, while not perfect, sampling still preserves sufficient distributional structure, which when harnessed by tools like entropy, can expose hard-to-detect scanning anomalies
-
ABSTRACT Comparison of Anomaly Signal Quality in Common Detection Metrics
2009Co-Authors: Daniela Brauckhoff, Martin May, Bernhard PlattnerAbstract:Problems involving classification and pattern recognition can often be profitably viewed from the perspective of signal detection theory. We present ANEX (ANomaly EXposure), a simple and intuitive measure for comparing anomaly detection metrics regarding their capability to expose certain types of anomalies. ANEX is based on signal detection theory and determines the anomaly signal quality with the help of the intersection area of the metric’s probability density functions in the normal and anomalous case. We illustrate the applicability of our measure by comparing 15 frequently-used detection metrics for the Blaster Worm and discuss some early results by comparing NetFlow data from four different border gateway routers of a medium-sized ISP network
-
MineNet - Comparison of anomaly signal quality in common detection metrics
Proceedings of the 3rd annual ACM workshop on Mining network data - MineNet '07, 2007Co-Authors: Daniela Brauckhoff, Martin May, Bernhard PlattnerAbstract:Problems involving classification and pattern recognition can often be profitably viewed from the perspective of signal detection theory. We present ANEX (ANomaly EXposure), a simple and intuitive measure for comparing anomaly detection metrics regarding their capability to expose certain types of anomalies. ANEX is based on signal detection theory and determines the anomaly signal quality with the help of the intersection area of the metric's probability density functions in the normal and anomalous case. We illustrate the applicability of our measure by comparing 15 frequently-used detection metrics for the Blaster Worm and discuss some early results by comparing NetFlow data from four different border gateway routers of a medium-sized ISP network.
-
Impact of packet sampling on anomaly detection metrics
Proceedings of the 6th ACM SIGCOMM conference on Internet measurement, 2006Co-Authors: Daniela Brauckhoff, Martin May, Arno Wagner, Bernhard Tellenbach, Anukool LakhinaAbstract:Packet sampling methods such as Cisco's NetFlow are widely employed\nby large networks to reduce the amount of traffic data measured.\nA key problem with packet sampling is that it is inherently a lossy\nprocess, discarding (potentially useful) information. In this paper,\nwe empirically evaluate the impact of sampling on anomaly detection\nmetrics. Starting with unsampled flow records collected during the\nBlaster Worm outbreak, we reconstruct the underlying packet trace\nand simulate packet sampling at increasing rates. We then use our\nknowledge of the Blaster anomaly to build a baseline of normal traffic\n(without Blaster), against which we can measure the anomaly size\nat various sampling rates. This approach allows us to evaluate the\nimpact of packet sampling on anomaly detection without being restricted\nto (or biased by) a particular anomaly detection method.We find that\npacket sampling does not disturb the anomaly size when measured in\nvolume metrics such as the number of bytes and number of packets,\nbut grossly biases the number of flows. However, we find that recently\nproposed entropy-based summarizations of packet and flow counts are\naffected less by sampling, and expose the Blaster Worm outbreak even\nat higher sampling rates. Our findings suggest that entropy summarizations\nare more resilient to sampling than volume metrics. Thus, while not\nperfect, sampling still preserves sufficient distributional structure,\nwhich when harnessed by tools like entropy, can expose hard-to-detect\nscanning anomalies.
-
Internet Measurement Conference - Impact of packet sampling on anomaly detection metrics
Proceedings of the 6th ACM SIGCOMM on Internet measurement - IMC '06, 2006Co-Authors: Daniela Brauckhoff, Martin May, Arno Wagner, Bernhard Tellenbach, Anukool LakhinaAbstract:Packet sampling methods such as Cisco's NetFlow are widely employed by large networks to reduce the amount of traffic data measured. A key problem with packet sampling is that it is inherently a lossy process, discarding (potentially useful) information. In this paper, we empirically evaluate the impact of sampling on anomaly detection metrics. Starting with unsampled flow records collected during the Blaster Worm outbreak, we reconstruct the underlying packet trace and simulate packet sampling at increasing rates. We then use our knowledge of the Blaster anomaly to build a baseline of normal traffic (without Blaster), against which we can measure the anomaly size at various sampling rates. This approach allows us to evaluate the impact of packet sampling on anomaly detection without being restricted to (or biased by) a particular anomaly detection method.We find that packet sampling does not disturb the anomaly size when measured in volume metrics such as the number of bytes and number of packets, but grossly biases the number of flows. However, we find that recently proposed entropy-based summarizations of packet and flow counts are affected less by sampling, and expose the Blaster Worm outbreak even at higher sampling rates. Our findings suggest that entropy summarizations are more resilient to sampling than volume metrics. Thus, while not perfect, sampling still preserves sufficient distributional structure, which when harnessed by tools like entropy, can expose hard-to-detect scanning anomalies.
Jose Nazario - One of the best experts on this subject based on the ideXlab platform.
-
the internet motion sensor a distributed blackhole monitoring system
Network and Distributed System Security Symposium, 2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
NDSS - The Internet Motion Sensor - A Distributed Blackhole Monitoring System.
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Evan Cooke, Michael Bailey, Farnam Jahanian, David Watson, Jose NazarioAbstract:Abstract — As national utility infrastructures become intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attack
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose Nazario, David WatsonAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning effort
-
The Internet Motion Sensor: A distributed global scoped Internet threat monitoring system
2004Co-Authors: Evan Cooke, Michael Bailey, Farnam Jahanian, David W. Watson, Jose NazarioAbstract:Networks are increasingly subjected to a broad spectrum of threats that impact the reliability and availability of critical infrastructure. In response, researchers and network operators have increasingly relied on monitoring to characterize and track these threats. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet threat monitoring system whose goal is to measure, characterize, and track threats. The dark address sensors in the IMS extend simple passive capture using a novel transport layer service emulation technique to elicit payloads across all services, thereby addressing the issue depth of service coverage. To achieve breadth of coverage, the IMS employs a distributed infrastructure and utilizes sensors that are aware of their address diversity and their position in the actively routed topology. Finally, the IMS uses an innovative signature encoding and data warehousing system combined with a hierarchical architecture to realize a system that is not only time and space efficient, but is also scalable to a global deployment. We explore the various architectural tradeoffs in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. We show how the current architecture emulates services across a diverse set of routed and address topologies in a scalable manner. Results from three recent events are presented to illustrate the utility of such a system: the SCO Denial of Service attacks (December, 2003), the Blaster Worm (August, 2003), and the Bagle backdoor scanning efforts (March, 2004).
Michael Bailey - One of the best experts on this subject based on the ideXlab platform.
-
The Blaster Worm: then and now
IEEE Security and Privacy Magazine, 2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, David W. WatsonAbstract:The Blaster Worm of 2003 infected at least 100000 Microsoft Windows systems and cost millions in damage. In spite of cleanup efforts, an antiWorm, and a removal tool from Microsoft, the Worm persists. Observing the Worm's activity can provide insight into the evolution of Internet Worms.
-
the internet motion sensor a distributed blackhole monitoring system
Network and Distributed System Security Symposium, 2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
NDSS - The Internet Motion Sensor - A Distributed Blackhole Monitoring System.
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Evan Cooke, Michael Bailey, Farnam Jahanian, David Watson, Jose NazarioAbstract:Abstract — As national utility infrastructures become intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attack
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose Nazario, David WatsonAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning effort
Martin May - One of the best experts on this subject based on the ideXlab platform.
-
The Effect of Packet Sampling on Anomaly Detection
2012Co-Authors: Daniela Brauckhoff, Arno Wagner, Bernhard Tellenbach, Anukool Lakhina, Martin MayAbstract:Packet sampling methods such as Cisco’s NetFlow are widely employed by large networks to reduce the amount of traffic data measured. A key problem with packet sampling is that it is inherently a lossy process, discarding (potentially useful) information. In this paper, we empirically evaluate the impact of sampling on anomaly detection. Starting with unsampled traffic records collected during the Blaster Worm outbreak, we reconstruct the underlying packet trace and simulate packet sampling at increasing rates. We then use our knowledge of the Blaster anomaly to build a baseline of normal traffic (without Blaster), against which we can measure the anomaly size at various sampling rates. This approach allows us to evaluate the impact of packet sampling on anomaly detection without being restricted to (or biased by) a particular anomaly detection method. We find that packet sampling does not disturb the anomaly size when measured in volume metrics such as the number of bytes and number of packets, but grossly biases the number of flows. However, we find that recently proposed entropy-based summarizations of packet and flow counts are affected less by sampling, and expose the Blaster Worm outbreak even at higher sampling rates. Our findings suggest that entropy summarizations are more resilient to sampling than volume metrics. Thus, while not perfect, sampling still preserves sufficient distributional structure, which when harnessed by tools like entropy, can expose hard-to-detect scanning anomalies
-
ABSTRACT Comparison of Anomaly Signal Quality in Common Detection Metrics
2009Co-Authors: Daniela Brauckhoff, Martin May, Bernhard PlattnerAbstract:Problems involving classification and pattern recognition can often be profitably viewed from the perspective of signal detection theory. We present ANEX (ANomaly EXposure), a simple and intuitive measure for comparing anomaly detection metrics regarding their capability to expose certain types of anomalies. ANEX is based on signal detection theory and determines the anomaly signal quality with the help of the intersection area of the metric’s probability density functions in the normal and anomalous case. We illustrate the applicability of our measure by comparing 15 frequently-used detection metrics for the Blaster Worm and discuss some early results by comparing NetFlow data from four different border gateway routers of a medium-sized ISP network
-
MineNet - Comparison of anomaly signal quality in common detection metrics
Proceedings of the 3rd annual ACM workshop on Mining network data - MineNet '07, 2007Co-Authors: Daniela Brauckhoff, Martin May, Bernhard PlattnerAbstract:Problems involving classification and pattern recognition can often be profitably viewed from the perspective of signal detection theory. We present ANEX (ANomaly EXposure), a simple and intuitive measure for comparing anomaly detection metrics regarding their capability to expose certain types of anomalies. ANEX is based on signal detection theory and determines the anomaly signal quality with the help of the intersection area of the metric's probability density functions in the normal and anomalous case. We illustrate the applicability of our measure by comparing 15 frequently-used detection metrics for the Blaster Worm and discuss some early results by comparing NetFlow data from four different border gateway routers of a medium-sized ISP network.
-
Impact of packet sampling on anomaly detection metrics
Proceedings of the 6th ACM SIGCOMM conference on Internet measurement, 2006Co-Authors: Daniela Brauckhoff, Martin May, Arno Wagner, Bernhard Tellenbach, Anukool LakhinaAbstract:Packet sampling methods such as Cisco's NetFlow are widely employed\nby large networks to reduce the amount of traffic data measured.\nA key problem with packet sampling is that it is inherently a lossy\nprocess, discarding (potentially useful) information. In this paper,\nwe empirically evaluate the impact of sampling on anomaly detection\nmetrics. Starting with unsampled flow records collected during the\nBlaster Worm outbreak, we reconstruct the underlying packet trace\nand simulate packet sampling at increasing rates. We then use our\nknowledge of the Blaster anomaly to build a baseline of normal traffic\n(without Blaster), against which we can measure the anomaly size\nat various sampling rates. This approach allows us to evaluate the\nimpact of packet sampling on anomaly detection without being restricted\nto (or biased by) a particular anomaly detection method.We find that\npacket sampling does not disturb the anomaly size when measured in\nvolume metrics such as the number of bytes and number of packets,\nbut grossly biases the number of flows. However, we find that recently\nproposed entropy-based summarizations of packet and flow counts are\naffected less by sampling, and expose the Blaster Worm outbreak even\nat higher sampling rates. Our findings suggest that entropy summarizations\nare more resilient to sampling than volume metrics. Thus, while not\nperfect, sampling still preserves sufficient distributional structure,\nwhich when harnessed by tools like entropy, can expose hard-to-detect\nscanning anomalies.
-
Internet Measurement Conference - Impact of packet sampling on anomaly detection metrics
Proceedings of the 6th ACM SIGCOMM on Internet measurement - IMC '06, 2006Co-Authors: Daniela Brauckhoff, Martin May, Arno Wagner, Bernhard Tellenbach, Anukool LakhinaAbstract:Packet sampling methods such as Cisco's NetFlow are widely employed by large networks to reduce the amount of traffic data measured. A key problem with packet sampling is that it is inherently a lossy process, discarding (potentially useful) information. In this paper, we empirically evaluate the impact of sampling on anomaly detection metrics. Starting with unsampled flow records collected during the Blaster Worm outbreak, we reconstruct the underlying packet trace and simulate packet sampling at increasing rates. We then use our knowledge of the Blaster anomaly to build a baseline of normal traffic (without Blaster), against which we can measure the anomaly size at various sampling rates. This approach allows us to evaluate the impact of packet sampling on anomaly detection without being restricted to (or biased by) a particular anomaly detection method.We find that packet sampling does not disturb the anomaly size when measured in volume metrics such as the number of bytes and number of packets, but grossly biases the number of flows. However, we find that recently proposed entropy-based summarizations of packet and flow counts are affected less by sampling, and expose the Blaster Worm outbreak even at higher sampling rates. Our findings suggest that entropy summarizations are more resilient to sampling than volume metrics. Thus, while not perfect, sampling still preserves sufficient distributional structure, which when harnessed by tools like entropy, can expose hard-to-detect scanning anomalies.
Evan Cooke - One of the best experts on this subject based on the ideXlab platform.
-
The Blaster Worm: then and now
IEEE Security and Privacy Magazine, 2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, David W. WatsonAbstract:The Blaster Worm of 2003 infected at least 100000 Microsoft Windows systems and cost millions in damage. In spite of cleanup efforts, an antiWorm, and a removal tool from Microsoft, the Worm persists. Observing the Worm's activity can provide insight into the evolution of Internet Worms.
-
the internet motion sensor a distributed blackhole monitoring system
Network and Distributed System Security Symposium, 2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
NDSS - The Internet Motion Sensor - A Distributed Blackhole Monitoring System.
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose NazarioAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attacks (December 2003).
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Evan Cooke, Michael Bailey, Farnam Jahanian, David Watson, Jose NazarioAbstract:Abstract — As national utility infrastructures become intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning efforts (March 2004), and the SCO Denial of Service attack
-
The Internet Motion Sensor: A Distributed Blackhole Monitoring System
2005Co-Authors: Michael Bailey, Evan Cooke, Farnam Jahanian, Jose Nazario, David WatsonAbstract:As national infrastructure becomes intertwined with emerging global data networks, the stability and integrity of the two have become synonymous. This connection, while necessary, leaves network assets vulnerable to the rapidly moving threats of today’s Internet, including fast moving Worms, distributed denial of service attacks, and routing exploits. This paper introduces the Internet Motion Sensor (IMS), a globally scoped Internet monitoring system whose goal is to measure, characterize, and track threats. The IMS architecture is based on three novel components. First, a Distributed Monitoring Infrastructure increases visibility into global threats. Second, a Lightweight Active Responder provides enough interactivity that traffic on the same service can be differentiated independent of application semantics. Third, a Payload Signatures and Caching mechanism avoids recording duplicated payloads, reducing overhead and assisting in identifying new and unique payloads. We explore the architectural tradeoffs of this system in the context of a 3 year deployment across multiple dark address blocks ranging in size from /24s to a /8. These sensors represent a range of organizations and a diverse sample of the routable IPv4 space including nine of all routable /8 address ranges. Data gathered from these deployments is used to demonstrate the ability of the IMS to capture and characterize several important Internet threats: the Blaster Worm (August 2003), the Bagle backdoor scanning effort