{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T18:31:15Z","timestamp":1785609075609,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2004,10,25]],"date-time":"2004-10-25T00:00:00Z","timestamp":1098662400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2004,10,25]]},"DOI":"10.1145\/1028788.1028794","type":"proceedings-article","created":{"date-parts":[[2005,1,30]],"date-time":"2005-01-30T17:58:48Z","timestamp":1107107928000},"page":"27-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":227,"title":["Characteristics of internet background radiation"],"prefix":"10.1145","author":[{"given":"Ruoming","family":"Pang","sequence":"first","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vinod","family":"Yegneswaran","sequence":"additional","affiliation":[{"name":"University of Wisconsin at Madison"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Barford","sequence":"additional","affiliation":[{"name":"University of Wisconsin at Madison"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vern","family":"Paxson","sequence":"additional","affiliation":[{"name":"International Computer Science Institute, Lawrence Berkeley Laboratory"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Larry","family":"Peterson","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2004,10,25]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"W32 A gobot IB. http:\/\/www.sophos.com\/virusinfo\/analyses\/trojagobotib.html.  W32 A gobot IB. http:\/\/www.sophos.com\/virusinfo\/analyses\/trojagobotib.html."},{"key":"e_1_3_2_1_2_1","volume-title":"January","author":"Anley C.","year":"2002","unstructured":"C. Anley . Creating arbitrary shellcode in unicode expanded strings , January 2002 . http:\/\/www.nextgenss.com\/papers\/unicodebo.pdf. C. Anley. Creating arbitrary shellcode in unicode expanded strings, January 2002. http:\/\/www.nextgenss.com\/papers\/unicodebo.pdf."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/233013.233034"},{"key":"e_1_3_2_1_4_1","unstructured":"L. Baldwin P. Sloss and S. Friedl. Iraqi Trace. http:\/\/www.mynetwatchman.com\/kb\/security\/articles\/iraqiworm\/iraqitrace. htm.  L. Baldwin P. Sloss and S. Friedl. Iraqi Trace. http:\/\/www.mynetwatchman.com\/kb\/security\/articles\/iraqiworm\/iraqitrace. htm."},{"key":"e_1_3_2_1_5_1","unstructured":"W32 Beagle. J. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/w32.beagle.j@mm.html.  W32 Beagle. J. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/w32.beagle.j@mm.html."},{"key":"e_1_3_2_1_6_1","unstructured":"B. Caswell and M. Roesch. The SNORT network intrusion detection system. http:\/\/www.snort.org April 2004.  B. Caswell and M. Roesch. The SNORT network intrusion detection system. http:\/\/www.snort.org April 2004."},{"key":"e_1_3_2_1_7_1","unstructured":"Common Internet File System. http:\/\/www.snia.org\/tech_activities\/CIFS\/CIFS-TR-1p00_FINAL.pdf.  Common Internet File System. http:\/\/www.snia.org\/tech_activities\/CIFS\/CIFS-TR-1p00_FINAL.pdf."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of NATO Symposium","author":"Dacier M.","year":"2004","unstructured":"M. Dacier , F. Pouget , and H. Debar . Attack processes found on the internet . In Proceedings of NATO Symposium , 2004 . M. Dacier, F. Pouget, and H. Debar. Attack processes found on the internet. In Proceedings of NATO Symposium, 2004."},{"key":"e_1_3_2_1_9_1","first-page":"1","article-title":"An empirical workload model for driving wide-area TCP\/IP network simulations. Internetworking","volume":"3","author":"Danzig P.","year":"1992","unstructured":"P. Danzig , S. Jamin , R. C'aceres , D. Mitzel , and D. Estrin . An empirical workload model for driving wide-area TCP\/IP network simulations. Internetworking : Research and Experience , 3 : 1 -- 26 , 1992 . P. Danzig, S. Jamin, R. C'aceres, D. Mitzel, and D. Estrin. An empirical workload model for driving wide-area TCP\/IP network simulations. Internetworking: Research and Experience, 3:1--26, 1992.","journal-title":"Research and Experience"},{"key":"e_1_3_2_1_10_1","unstructured":"DCE 1.1: Remote procedure call. http:\/\/www.opengroup.org\/onlinepubs\/9629399\/toc.htm.  DCE 1.1: Remote procedure call. http:\/\/www.opengroup.org\/onlinepubs\/9629399\/toc.htm."},{"key":"e_1_3_2_1_11_1","unstructured":"Flowreplay Design Notes. http:\/\/www.synfin.net\/papers\/flowreplay.pdf.  Flowreplay Design Notes. http:\/\/www.synfin.net\/papers\/flowreplay.pdf."},{"key":"e_1_3_2_1_12_1","volume-title":"June","author":"Greene B.","year":"2002","unstructured":"B. Greene . BGPv4 Security Risk Assessment , June 2002 . B. Greene. BGPv4 Security Risk Assessment, June 2002."},{"key":"e_1_3_2_1_13_1","volume-title":"http:\/\/project.honeynet.org","author":"Project The Honeynet","year":"2003","unstructured":"The Honeynet Project . http:\/\/project.honeynet.org , 2003 . The Honeynet Project. http:\/\/project.honeynet.org, 2003."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2004.1301325"},{"key":"e_1_3_2_1_15_1","volume-title":"13th USENIX Security Symposium","author":"Kim H.","year":"2004","unstructured":"H. Kim and B. Karp . Autograph: Toward automated, distributed worm signature detection . In 13th USENIX Security Symposium , San Diego, California , August 2004 . H. Kim and B. Karp. Autograph: Toward automated, distributed worm signature detection. In 13th USENIX Security Symposium, San Diego, California, August 2004."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/354871.354874"},{"key":"e_1_3_2_1_17_1","volume-title":"2nd Workshop on Hot Topics in Networks (Hotnets-II)","author":"Kreibich C.","year":"2003","unstructured":"C. Kreibich and J. Crowcroft . Honeycomb--creating intrusion detection signatures using honeypots . In 2nd Workshop on Hot Topics in Networks (Hotnets-II) , Cambridge, Massachusetts , November 2003 . C. Kreibich and J. Crowcroft. Honeycomb--creating intrusion detection signatures using honeypots. In 2nd Workshop on Hot Topics in Networks (Hotnets-II), Cambridge, Massachusetts, November 2003."},{"key":"e_1_3_2_1_18_1","volume-title":"Observing small or distant security events. Invited Presentation at the 11th USENIX Security Symposium","author":"Moore D.","year":"2002","unstructured":"D. Moore . Network telescopes : Observing small or distant security events. Invited Presentation at the 11th USENIX Security Symposium , 2002 . D. Moore. Network telescopes: Observing small or distant security events. Invited Presentation at the 11th USENIX Security Symposium, 2002."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"e_1_3_2_1_20_1","unstructured":"D. Moore V. Paxson S. Savage C. Shannon S. Staniford and N. Weaver. The spread of the sapphire\/slammer worm. http:\/\/www.caida.org\/outreach\/papers\/2003\/sapphire\/sapphire.html 2003.  D. Moore V. Paxson S. Savage C. Shannon S. Staniford and N. Weaver. The spread of the sapphire\/slammer worm. http:\/\/www.caida.org\/outreach\/papers\/2003\/sapphire\/sapphire.html 2003."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2003.1209212"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251327.1251329"},{"key":"e_1_3_2_1_24_1","unstructured":"W32 Mydoom. A@mm. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/w32.mydoom.a@mm.html.  W32 Mydoom. A@mm. http:\/\/securityresponse.symantec.com\/avcenter\/venc\/data\/w32.mydoom.a@mm.html."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.330413"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_27_1","unstructured":"N. Provos. The Honeyd Virtual Honeypot. http:\/\/www.honeyd.org 2003.  N. Provos. The Honeyd Virtual Honeypot. http:\/\/www.honeyd.org 2003."},{"key":"e_1_3_2_1_28_1","unstructured":"W32 Randex. D. http:\/\/www.liutilities.com\/products\/wintaskspro\/processlibrary\/msmsgri32.  W32 Randex. D. http:\/\/www.liutilities.com\/products\/wintaskspro\/processlibrary\/msmsgri32."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of USENIX LISA","author":"Roesch M.","year":"1999","unstructured":"M. Roesch . Snort : Lightweight intrusion detection for networks . In Proceedings of USENIX LISA , 1999 . M. Roesch. Snort: Lightweight intrusion detection for networks. In Proceedings of USENIX LISA, 1999."},{"key":"e_1_3_2_1_30_1","unstructured":"W32 Sasser. Worm. http:\/\/securityresponse. symantec. com\/avcenter\/venc\/data\/w32. sasser. worm. html.  W32 Sasser. Worm. http:\/\/securityresponse. symantec. com\/avcenter\/venc\/data\/w32. sasser. worm. html."},{"key":"e_1_3_2_1_31_1","unstructured":"Security Focus. Microsoft IIS 5. 0 \"translate: f\" source disclosure vulnerability. http:\/\/www.securityfocus. com\/bid\/1578\/discussion\/ April 2004.  Security Focus. Microsoft IIS 5. 0 \"translate: f\" source disclosure vulnerability. http:\/\/www.securityfocus. com\/bid\/1578\/discussion\/ April 2004."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720288"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.642356"},{"key":"e_1_3_2_1_35_1","unstructured":"Make your richer! Get more money easily! http:\/\/www.per.rcpt.to\/lists\/rlinetd\/msg01850.html.  Make your richer! Get more money easily! http:\/\/www.per.rcpt.to\/lists\/rlinetd\/msg01850.html."},{"key":"e_1_3_2_1_36_1","unstructured":"Dame Ware Mini Remote Control Server &lt;= 3. 72 buffer overflow. http:\/\/www.securityfocus.com\/archive\/1\/347576.  Dame Ware Mini Remote Control Server &lt;= 3. 72 buffer overflow. http:\/\/www.securityfocus.com\/archive\/1\/347576."},{"key":"e_1_3_2_1_37_1","unstructured":"Microsoft Windows DCOM RPC interface buffer overrun vulnerability (MS 03-026). http:\/\/www.securityfocus.com\/bid\/8205.  Microsoft Windows DCOM RPC interface buffer overrun vulnerability (MS 03-026). http:\/\/www.securityfocus.com\/bid\/8205."},{"key":"e_1_3_2_1_38_1","unstructured":"Microsoft Windows Locator Service buffer overflow vulnerability (MS 03-001). http:\/\/www.securityfocus.com\/bid\/6666.  Microsoft Windows Locator Service buffer overflow vulnerability (MS 03-001). http:\/\/www.securityfocus.com\/bid\/6666."},{"key":"e_1_3_2_1_39_1","unstructured":"Microsoft Windows 2000 Web DAV buffer overflow vulnerability (MS 03-007). cite http:\/\/www.securityfocus.com\/bid\/7116.  Microsoft Windows 2000 Web DAV buffer overflow vulnerability (MS 03-007). cite http:\/\/www.securityfocus.com\/bid\/7116."},{"key":"e_1_3_2_1_40_1","unstructured":"Windows Messenger Popup Spam. http:\/\/www.lurhq.com\/popup_spam.html.  Windows Messenger Popup Spam. http:\/\/www.lurhq.com\/popup_spam.html."},{"key":"e_1_3_2_1_41_1","unstructured":"W32 Xibo. http:\/\/www.sophos.com\/virusinfo\/analyses\/w32xiboa.html.  W32 Xibo. http:\/\/www.sophos.com\/virusinfo\/analyses\/w32xiboa.html."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_8"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/781027.781045"}],"event":{"name":"IMC04: Internet Measurement Conference","location":"Taormina Sicily, Italy","acronym":"IMC04","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 4th ACM SIGCOMM conference on Internet measurement"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1028788.1028794","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1028788.1028794","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:12Z","timestamp":1750264272000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1028788.1028794"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2004,10,25]]},"references-count":42,"alternative-id":["10.1145\/1028788.1028794","10.1145\/1028788"],"URL":"https:\/\/doi.org\/10.1145\/1028788.1028794","relation":{},"subject":[],"published":{"date-parts":[[2004,10,25]]},"assertion":[{"value":"2004-10-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}