Internet Measurement Data Catalog
| Collection: CAIDA Code-Red Worm Dataset |
Jump to: Description | Annotations | Citation | Record Details
Collection Contents| Summary | Information useful for studying the spread of the Code-Red worms, as observed by the UCSD Network Telescope in 2001, including infection start and end times, infection durations, latitude, longitude, Autonomous System (AS) and country locations for infected computers. The dataset consists of 2 parts: a July dataset, which covers July 19-20 and an August dataset, which covers July 30 to August 19. Possible uses include modeling and visualization of worm propagation. Statistics: 359,104 infected IP addresses in the July dataset and 4,478,473 infected IP addresses in the August dataset. |
| Motivation | To provide a set of data useful for studying the Code-Red worms. The data does not contain sensitive information and therefore can be made publicly available. |
| Data Start Time | 2001-07-19 00:01:12.242 UTC (+0000) |
| Data End Time | 2001-08-19 06:00:01.354 UTC (+0000) |
| Data Duration | 31 days 05:58:49.112 (2699929.112 s) |
| Creators | CAIDA Network Telescope Project - Code-Red |
| Primary contact | (none) |
| Keywords | background radiation, blackhole address space, CAIDA, Code-Red, Code-Redv2, CodeRed, CodeRedII, CodeRedv2, darknet, Internet worm, network telescope, passive, security, summary, worm |
| Used in publications | (none) |
| Member of collections | (none) |
| Description | This dataset contains information useful for studying the spread of the Code-Red version 2 and CodeRedII worms. The dataset consists of a publicly available set of files that contain summarized information that does not individually identify infected computers.
The first Code-Red worm (CRv1) began to infect hosts running unpatched versions of Microsoft's IIS webserver on July 12th, 2001. This version of the worm used a static seed for its random number generator. Around 10:00 UTC July 19th, a random seed variant (CRv2) appeared and spread. On August 4th, a new worm began to infect hosts exploiting the same vulnerability as the original Code-Red worm. Although the new worm shared no code with the first, it contained in its source code the string "CodeRedII" and was thus named CodeRed II. Caveats that apply to this data:
Data included in these datasets:
Data Use RestrictionsThe data cannot be redistributed. Every six months, a summary of research findings must be reported back to CAIDA. A copy of all publications (including presentations) must be sent to CAIDA. The following citation must be used in publications:
|
| For more information | http://www.caida.org/data/passive/codered_worms_dataset.xml |
\url{...} command for nice URL formatting, you must call \usepackage{url} in the LaTeX preamble.
| Handle | imdc.datcat.org/collection/1-001P-M=CAIDA+Code-Red+Worm+Dataset |
| Contributor | CAIDA Automated Data Contributor |
| Contributed | 2006-05-31 20:35:36.915 UTC (+0000) |
| Last Modified | 2006-05-31 20:36:24.272 UTC (+0000) |