FINDING · EVALUATION

Conficker-like traffic to TCP port 445 constitutes more than 40% of packets observed at the UCSD /8 Network Telescope and Windows XP/NT hosts consistently emit exactly 2-packet SYN flows; γC stayed within the narrow band 1.98–2.02 throughout an entire month (January 2012) with no large-scale outages. A second signal from default Windows 3-SYN flows (approximately 156 million flows/month from ~14K hosts/hour) provides a non-malware-specific validation stream with inter-packet times consistently between 3.09 and 3.37 seconds.

From 2013-benson-gainingGaining Insight into AS-level Outages through Analysis of Internet Background Radiation · §II–III · 2013 · Traffic Monitoring and Analysis

Implications

Tags

censors
generic
techniques
measurement-platform

Extracted by claude-sonnet-4-6 — review before relying.