nanog mailing list archives
Re: Code Red growth stats
From: Kevin Houle <kjh () cert org>
Date: Thu, 02 Aug 2001 09:13:17 -0400
--On Wednesday, August 01, 2001 22:35:46 -0400 "Steven M. Bellovin" <smb () research att com> wrote:
In message <20010801190627.A7553 () caida org>, k claffy writes:albeit crippled caida monitor (we're working on it), it does seem to have reversed slope again: http://www.caida.org/analysis/security/code-red/aug1-live-hosts.gif
If it has indeed turned up again, I'm at a loss to explain it. While I'm sure there are some IIS servers on home machines, I doubt there are that many. But I don't have another explanation to offer.
For what it's worth, the "wake-up" of previously sleeping worm threads may be a contributing factor. In lab tests, a wake-up happens at variable times, measured in hours, after midnight UTC with all three versions we have tested (the system clock is not checked during lengthy sleep() calls). At the moment of wake-up, the rate of scanning (in a vaccuum) is around 160 hosts/hour. The scanning rate on a host infected during the scanning time of the month is over 50,000 hosts/hour (again, in a vaccuum). The difference being the number of threads actively scanning; it would appear not all threads wake up at the same time. So, over time, the rate of scanning and the scope of address coverage should increase even if the true number of infected hosts does not. There will be a point where everything that's going to wake up has woken up, but I don't know where that point is. Kevin
Attachment:
_bin
Description:
Current thread:
- Re: Code Red growth stats, (continued)
- Re: Code Red growth stats Steven M. Bellovin (Aug 01)
- Re: Code Red growth stats Jasper Wallace (Aug 01)
- Re: Code Red growth stats Larry Rosenman (Aug 01)
- Re: Code Red growth stats Jasper Wallace (Aug 01)
- RE: Code Red growth stats Paul Lantinga (Aug 01)
- Re: Code Red growth stats Steven M. Bellovin (Aug 01)
- Re: Code Red growth stats Dave Stewart (Aug 01)
- Re: Code Red growth stats Daniel Senie (Aug 02)
- Re: Code Red growth stats Greg A. Woods (Aug 01)
- Re: Code Red growth stats Ryan Tucker (Aug 01)
- Re: Code Red growth stats k claffy (Aug 01)
- Re: Code Red growth stats Kevin Houle (Aug 02)
- Re: Code Red growth stats Dave Stewart (Aug 01)
- RE: Code Red growth stats Roeland Meyer (Aug 01)
- Re: Code Red growth stats Steven M. Bellovin (Aug 01)
- Re: Code Red growth stats Etaoin Shrdlu (Aug 01)
- RE: Code Red growth stats Roeland Meyer (Aug 01)
- Re: Code Red growth stats Adam Rothschild (Aug 01)
- Re: Code Red growth stats Avi Freedman (Aug 01)
- Re: Code Red growth stats k claffy (Aug 01)
- Re: Code Red growth stats Valdis . Kletnieks (Aug 01)
- Re: Code Red growth stats k claffy (Aug 01)
- RE: Code Red growth stats Roeland Meyer (Aug 01)
- Re: Code Red growth stats Sean Donelan (Aug 02)
(Thread continues...)
- Re: Code Red growth stats Steven M. Bellovin (Aug 01)