usenix conference policies
Network Telescopes: Observing Small or Distant Security Events
Abstract:
A network telescope is a portion of routed IP address space on which little or no legitimate traffic exists. Monitoring unexpected traffic arriving at a network telescope yields a view of certain remote network events. Among the visible events are various forms of flooding DoS attacks, infection of hosts by Internet worms, and network scanning. In this presentation, we'll examine questions such as: How large should my network telescope be? How well can one go backwards from a local view to an estimate of the global phenomenon? How big (in packets sent) or long (in duration) must an event be to be seen? What can I see from my own backyard telescope?
BibTeX
@inproceedings {270573,
author = {David Moore},
title = {Network Telescopes: Observing Small or Distant Security Events},
booktitle = {11th USENIX Security Symposium (USENIX Security 02)},
year = {2002},
address = {San Francisco, CA},
url = {https://www.usenix.org/conference/11th-usenix-security-symposium/network-telescopes-observing-small-or-distant-security},
publisher = {USENIX Association},
month = aug
}
author = {David Moore},
title = {Network Telescopes: Observing Small or Distant Security Events},
booktitle = {11th USENIX Security Symposium (USENIX Security 02)},
year = {2002},
address = {San Francisco, CA},
url = {https://www.usenix.org/conference/11th-usenix-security-symposium/network-telescopes-observing-small-or-distant-security},
publisher = {USENIX Association},
month = aug
}
connect with us