printlogo
ETH Zuerich - Homepage
Computer Engineering and Networks Laboratory (TIK)
 

Publication Details for Inproceedings "Flow-level Traffic Analysis of the Blaster and Sobig Worm Outbreaks in an Internet Backbone"

 

 Back

 New Search

 

Authors: Thomas Dübendorfer, Arno Wagner, Theus Hossmann, Bernhard Plattner
Group: Communication Systems
Type: Inproceedings
Title: Flow-level Traffic Analysis of the Blaster and Sobig Worm Outbreaks in an Internet Backbone
Year: 2005
Month: July
Pub-Key: dimva2005
Book Titel: Proceedings of GI SIG SIDAR Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2005)
Keywords: Worm, Blaster, Sobig.F, Outbreak, DDoS, Internet, Attacks
Publisher: Springer`s Lecture Notes in Computer Science (LNCS 3548)
Abstract: We present an extensive flow-level traffic analysis of the network worm Blaster.A and of the e-mail worm Sobig.F. Based on packet-level measurements with these worms in a testbed we defined flow-level filters. We then extracted the flows that carried malicious worm traffic from AS559 (SWITCH) border router backbone traffic that we had captured in the DDoSVax project. We discuss characteristics and anomalies detected during the outbreak phases, and present an in-depth analysis of partially and completely successful Blaster infections. Detailed flow-level traffic plots of the outbreaks are given. We found a short network test of a Blaster pre-release, significant changes of various traffic parameters, backscatter effects due to non-existent hosts, ineffectiveness of certain temporary port blocking countermeasures, and a surprisingly low frequency of successful worm code transmissions due to Blaster`s multi-stage nature. Finally, we detected many TCP packet retransmissions due to Sobig.F`s far too greedy spreading algorithm.
Location: Vienna, Austria
Resources: [BibTeX] [Paper as PDF]

 

 Back

 New Search