<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Computer Network Security Solutions</title>
	<atom:link href="http://cnss.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cnss.wordpress.com</link>
	<description>Case studies and solutions by Gautam Saraswat</description>
	<lastBuildDate>Sun, 21 Sep 2008 10:07:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cnss.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Computer Network Security Solutions</title>
		<link>http://cnss.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cnss.wordpress.com/osd.xml" title="Computer Network Security Solutions" />
	<atom:link rel='hub' href='http://cnss.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Current Network Security Threats</title>
		<link>http://cnss.wordpress.com/2007/09/16/23/</link>
		<comments>http://cnss.wordpress.com/2007/09/16/23/#comments</comments>
		<pubDate>Sun, 16 Sep 2007 22:56:25 +0000</pubDate>
		<dc:creator>gautamsaraswat</dc:creator>
				<category><![CDATA[Network security]]></category>

		<guid isPermaLink="false">http://cnss.wordpress.com/2007/09/16/23/</guid>
		<description><![CDATA[&#160; &#160; &#160; &#160; Jaypee Institute of Information Technology University, Noida &#160; Current Network Security Threats &#160; 2007 &#160; These Documents Are For Educational Purpose Presented here by Gautam Sarswat Contact at : gautam.sarswat.jbs@gmail.com &#160; &#160; &#160; Outline • Network Telescope • Denial-of-Service Attacks • Viruses and Worms • Botnets Network Telescope • Chunk of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cnss.wordpress.com&amp;blog=1628368&amp;post=23&amp;subd=cnss&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:18pt;">Jaypee Institute of Information Technology University, Noida </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><img src="http://farm2.static.flickr.com/1117/1393220681_4c2fadc28c_o.jpg" alt="jiit logo" height="152" width="189" /><span></span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center"><span style="font-size:18pt;color:#004eea;">Current Network Security Threats</span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center"><span>2007</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:14pt;"> </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:14pt;"> </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:14pt;"> </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center">&nbsp;</p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:14pt;">These Documents Are For Educational Purpose</span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span style="font-size:14pt;">Presented here by</span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><span> </span></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span>Gautam Sarswat</span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span> </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span>Contact at : <a href="mailto:gautam.sarswat.jbs@gmail.com">gautam.sarswat.jbs@gmail.com</a></span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span> </span></strong></p>
<p class="MsoNormal" style="text-align:center;" align="center"><strong><span> </span></strong></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Outline</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Network Telescope</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Denial-of-Service Attacks</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Viruses and Worms</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Botnets</span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Network Telescope</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Chunk of (globally) routed IP address space – 16 million IP addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Little or no legitimate traffic (or easily filtered)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Unexpected traffic arriving at the network telescope can imply remote network/security events</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Generally good for seeing explosions, not small Events</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Depends on random component in spread</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Network Telescope: Denial-of-Service Attacks</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Attacker floods the victim with requests using random spoofed source IP addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Victim believes requests are legitimate and responds to each spoofed address</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• According to observation 1/256th of all <em>victim responses </em>to spoofed addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1398/1393220713_c2f0742784_o.gif" border="0" height="332" width="624" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Denial-of-Service Attacks</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1170/1394088228_9567652995_o.gif" border="0" height="367" width="652" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Analysis DoS Attacks over time</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1418/1394088230_d3275a566f_o.gif" border="0" height="347" width="680" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Network Telescope Observation Station</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• http://www.caida.org/data/realtime/telescope/</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Prevalence and trends in spoofed-source denial-of-service attacks</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– http://www.caida.org/data/realtime/telescope/?monitor</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">=telescope_backscatter</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• (live demo)</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">What is a Network Worm?</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Self-propagating self-replicating network program</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– Exploits some vulnerability to infect remote machines</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• No human intervention necessary</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– Infected machines continue propagating infection</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1268/1394088242_11c0b3d5dd_o.gif" border="0" height="249" width="632" /></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Network Telescope: Worm Attacks</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1145/1394088248_638576a5c5_o.gif" border="0" height="254" width="575" /></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Infected host scans for other vulnerable hosts by randomly generating IP addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• It monitor 1/256th of all IPv4 addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• It see 1/256th of all worm traffic of worms with no bias and no bugs</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Witty Worm Background</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">March 19, 2004</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• ISS Vulnerability</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– A buffer overflow in a PAM (Protocol Analysis Module) in a Internet Security Systems firewall products</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Version 3.6.16 of iss-pam1.dll</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Analyzes ICQ traffic (inbound port 4000)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Discovered by eEye on March 8, 2004</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Jointly announced March 18,2004 when “patch” available</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Upgrade to the next version at customer cost…</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• By far the closest to a zero-day exploit</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Instead of 2-4 weeks after bug release, Witty appeared after <em>36 hours</em></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Witty Worm Structure</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">March 19, 2004</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Infects a host running an ISS firewall product</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Sends 20,000 UDP packets as quickly as possible:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– to random source IP addresses</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– to random destination port</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– with random size between 796 and 1307 bytes</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Damage Victim:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– select random physical device</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– seek to random point on that device</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– attempt to write over 65k of data with a copy of the beginning of the vulnerable dll</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Repeat until machine is rebooted or machine crashes irreparably</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Typical (Code-Red) Host Infection Rate</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1399/1394088250_162c7870fd_o.gif" border="0" height="393" width="625" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Early Growth of Witty (5 minutes)</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1435/1394088256_e9ba100a7c_o.gif" border="0" height="372" width="657" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Witty Worm Spread</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">March 19, 2004</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Sharp rise via initial coordinated activity</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Peaked after approximately 45 minutes</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Approximately 30 minutes later than the fastest worm we’ve seen so far (SQL Slammer)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Still far faster than any human response</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– At peak, Witty generated:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• 90 GB/sec of network traffic</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• 11 million packets per second</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Early Growth of Witty (2 hours)</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1254/1393202007_d7b53a9829_o.gif" border="0" height="364" width="658" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Early Growth of Witty (3 days)</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1281/1393202015_ee7eaaaa37_o.gif" border="0" height="433" width="736" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Witty Worm Victims</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Consistent with past worms:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Globally distributed</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Majority high-bandwidth home/small business users</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Unique victim characteristics</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– 100% taking proactive security measures</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Infected via software they ran purposefully</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1369/1393202021_ac0e700366_o.gif" border="0" height="349" width="603" /></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Geographic Spread of Witty</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1012/1393202025_5476349348_o.gif" border="0" height="395" width="631" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Witty Summary</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><img src="http://farm2.static.flickr.com/1295/1393202029_6dd2a329cd_o.gif" border="0" height="255" width="623" /></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• ~12,000 hosts infected in <span>30 minutes</span></span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Averaged more than 11 million probes per second world-wide</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Unstoppable</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Irreparably destroyed a significant number of infected computers</span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Conclusions</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Witty incorporates a number of novel and disturbing features:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Next day exploit for publicized bug</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Wide-scale deployment</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Successful exploit of small population (no more security through obscurity)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Future worms will continue to emulate botnets</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– increasing levels of stealth and flexibility</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Infected a <em><span>security </span></em>product</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Witty demonstrates conclusively that the patch model of networked device security has</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">failed</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– You can’t encourage people to sign on to the ‘net with one click and then also expect them to be security experts</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Running commercial firewall software at their own expense is the gold standard for end user behavior</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Recognition that security is important</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Recognition that they can’t do it themselves</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• End-user behavior cannot solve current software security problems</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• End-user behavior cannot effectively mitigate current software security problems</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• We must:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Actively address prevention of software vulnerabilities</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– Turn our attention to developing large-scale, robust, reliable infrastructure that can mitigate current security problems without end-user intervention</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">About Blackworm</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Began to spread January 15, 2006</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• 95k Visual Basic executable email attachment run by users</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Also spread to attached network shares</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Malicious: on the 3rd day of every month:</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– searches for files with 12 common file extensions (.doc, .xls, .mdb, .mde, .ppt, .pps, .zip, .rar, .pdf, .psd,and .dmp)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">– replaces those files with the text string &#8220;DATA Error [47 0F 94 93 F4 K5]&#8220;</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">So who cares?</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Blackworm is not particularly different from many, many other email viruses, except…</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Every infected computer automatically generates an http request for a web page that displayed a hit count graph (self-documenting code?)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Logs for the website were available before the first date of payload destruction</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• <span>Some victims could be notified before they lost data</span></span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Log Analysis</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Simple! Just take the logs and look at who connected and you’ll have the infected IP</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">addresses!</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Except that the url was publicized…</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Many folks looked at the page to observe the spread of the virus</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Denial-of-service attacks added a large volume of spurious traffic</span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Log Filtering</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Why not just count IP addresses that were logged once?</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Web traffic aggregators (NAT, proxy servers) obscure victim IP addresses; multiple probes can represent multiple infections</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• DHCP use allows two different computers to have the same IP at the time that they</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">become infected</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Log Filtering Process</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Remove referer/browser strings set by common DDoS tools (91.1% of all hits)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Remove requests for pages different from the one accessed by the virus (0.2%)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Remove any request with a referer string (virus did not use one in its probes) (0.8%)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Remove requests from invulnerable Operating Systems: MacOS, Unix, cell phone, and PDA devices (0.03%)</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';">Sources of Error and Uncertainty</span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Infected computers that failed to send the probe</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Network firewalls or outages that prevented victims from reaching the web page</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• Denial-of-Service attacks preventing infected computers from reaching the web page</span></p>
<p class="MsoNormal" style="text-align:justify;"><span style="font-family:'Arial','sans-serif';">• People who viewed the counter only once using a vulnerable browser, but were not infected</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Estimating a Victim Count</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Lower bound: for each IP address, the number of unique, vulnerable browser types received from that IP address</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Upper bound: for each IP address, the total number of probes received from that IP address</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1302/1393220725_920cace1f8_o.gif" border="0" height="312" width="624" /></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Blackworm victim estimate: between 469,507 and 946,835 (3.2%-6.4% of original log entries)</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Blackworm Overall</span></strong></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1363/1393220719_6fdabdb40e_o.gif" border="0" height="388" width="615" /></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Blackworm by Continent</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1105/1393220717_6293fd1d60_o.gif" border="0" height="409" width="624" /></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Blackworm by Country (&gt;2%)</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><img src="http://farm2.static.flickr.com/1350/1393220715_a305eb0002_o.gif" border="0" height="302" width="624" /></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Concurrent Infections</span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• 45,401 Blackworm victims (10%) had concurrent spyware and/or botnet infections advertised in their browser string</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Sgrunt|V109|29|S493689067|dial; FunWebProducts; XBE|29|S04069679521143#398|isdn; snprtz|S04138822910124)</span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Conclusions</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Log analysis allows insight into email virus spread given sufficient data mining</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Email viruses spread in a slower and steadier pattern than Internet worms, which infect the vast majority of their victims in the first day</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Diurnal patterns are strongly apparent in spread data (people read their email when</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">they are awake)</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Country distribution of victims does not correlate with web infrastructure development</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Spread strongly influenced by geographic location (based on social and linguistic similarity)</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• TLD distribution reflects geographic distribution rather than # of vulnerable hosts/TLD</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• 10% of victims had concurrent botnet or spyware infection</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Botnets</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Significant transition in motivation for widespread, non-specific malicious activity</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– From notoriety -&gt; want to be noticed</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– To money -&gt; want stealth to protect revenue stream</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• So how do you make money?</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– Sending spam</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– DoS extortion</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">– Active (phishing) and passive identity theft</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Current Events</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Malicious software development is a business aimed at scalable, manageable</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">distributed systems</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Coordinated activity makes current antivirus activities increasingly irrelevant</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Demise of signature-based security?</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• High system complexity + naïve/uneducated = bad combination Cooperative Association for Internet Data Analysis Current Security Research</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Longitudinal study of Blackworm</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Spamscatter</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Botnet Economics</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Worm Risk Analysis</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';">• Anomaly Detection</span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><span style="font-family:'Arial','sans-serif';"> </span></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';">Reference</span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"> </span></strong></p>
<p class="MsoNormal"><strong><span style="font-family:'Arial','sans-serif';"><a href="http://www.caida.org/">http://www.caida.org</a> </span></strong></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/cnss.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/cnss.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cnss.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cnss.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cnss.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cnss.wordpress.com&amp;blog=1628368&amp;post=23&amp;subd=cnss&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cnss.wordpress.com/2007/09/16/23/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/64e9fb83caa7cc9bf1f9b8e04e40abd0?s=96&#38;d=identicon" medium="image">
			<media:title type="html">gautamsaraswat</media:title>
		</media:content>

		<media:content url="http://farm2.static.flickr.com/1117/1393220681_4c2fadc28c_o.jpg" medium="image">
			<media:title type="html">jiit logo</media:title>
		</media:content>

		<media:content url="http://farm2.static.flickr.com/1398/1393220713_c2f0742784_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1170/1394088228_9567652995_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1418/1394088230_d3275a566f_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1268/1394088242_11c0b3d5dd_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1145/1394088248_638576a5c5_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1399/1394088250_162c7870fd_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1435/1394088256_e9ba100a7c_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1254/1393202007_d7b53a9829_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1281/1393202015_ee7eaaaa37_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1369/1393202021_ac0e700366_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1012/1393202025_5476349348_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1295/1393202029_6dd2a329cd_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1302/1393220725_920cace1f8_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1363/1393220719_6fdabdb40e_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1105/1393220717_6293fd1d60_o.gif" medium="image" />

		<media:content url="http://farm2.static.flickr.com/1350/1393220715_a305eb0002_o.gif" medium="image" />
	</item>
	</channel>
</rss>
