- Title
- A network telescope perspective of the Conficker outbreak
- Creator
- Irwin, Barry V W
- Subject
- To be catalogued
- Date Issued
- 2012
- Date
- 2012
- Type
- text
- Type
- article
- Identifier
- http://hdl.handle.net/10962/429728
- Identifier
- vital:72635
- Identifier
- 10.1109/ISSA.2012.6320455
- Description
- This paper discusses a dataset of some 16 million packets targeting port 445/tcp collected by a network telescope utilising a /24 netblock in South African IP address space. An initial overview of the collected data is provided. This is followed by a detailed analysis of the packet characteristics observed, including size and TTL. The peculiarities of the observed target selection and the results of the flaw in the Conficker worm's propagation algorithm are presented. An analysis of the 4 million observed source hosts is reported by grouped by both packet counts and the number of distinct hosts per network address block. Address blocks of size /8, 16 and 24 are used for groupings. The localisation, by geographic region and numerical proximity, of high ranking aggregate netblocks is highlighted. The paper concludes with some overall analyses, and consideration of the application of network telescopes to the monitoring of such outbreaks in the future.
- Format
- 8 pages
- Format
- Language
- English
- Relation
- Information Security for South Africa
- Relation
- Irwin, B., 2012, August. A network telescope perspective of the Conficker outbreak. In 2012 Information Security for South Africa (pp. 1-8). IEEE
- Relation
- Information Security for South Africa volume 2012 number 1 1 8 2012 2330-9881
- Rights
- Publisher
- Rights
- Use of this resource is governed by the terms and conditions of the IEEE Xplore Terms of Use Statement (https://ieeexplore.ieee.org/Xplorehelp/overview-of-ieee-xplore/terms-of-use)
- Hits: 137
- Visitors: 136
- Downloads: 3
Thumbnail | File | Description | Size | Format | |||
---|---|---|---|---|---|---|---|
View Details Download | SOURCE1 | A network telescope perspective of the Conficker outbreak.pdf | 637 KB | Adobe Acrobat PDF | View Details Download |