A Snapshot of Global Internet Worm Activity

In this paper, we present a snapshot of Internet worm activity from September to November 2001, bearing witness to the rise of Nimda (and Nimda.E), the death of CodeRedII (and CodeRed.d), and a resurrection of the original CodeRed. We determine the demographics of the various worm-infected populations, and make predictions as to their future growth, attrition, and impact. These findings represent the early results of our ongoing research in “blackhole monitoring” – the instrumentation and analysis of an unused class A network, or 1/256 of the entire Internet address space, for evidence of global Internet attack activity.