Jose Nazario’s blog
Senior Security Engineer, Arbor Networks
Dr. Jose Nazario is a Senior Security Engineer within Arbor Networks' Arbor Security Engineering & Response Team (ASERT). In this capacity, he is responsible for analyzing burgeoning Internet security threats, reverse engineering malicious code, software development, developing security mechanisms that are then distributed to Arbor's Peakflow platforms via the Active Threat Feed (ATF) threat detection service. Dr. Nazario's research interests include large-scale Internet trends such as reachability and topology measurement, Internet-scale events such as DDoS attacks, botnets and worms, source code analysis tools, and data mining. He is the author of the books "Defense and Detection Strategies against Internet Worms" and "Secure Architectures with OpenBSD." He earned a Ph.D. in biochemistry from Case Western Reserve University in 2002. Prior to joining Arbor Networks, he was an independent security consultant. Dr. Nazario regularly speaks at conferences worldwide, with past presentations at CanSecWest, PacSec, Blackhat, and NANOG. He also maintains WormBlog.com, a site devoted to studying worm detection and defense research.
Entries in the archive
November 12, 2006
Bits and Pieces: November 12
Security
A few things caught my eye this week, so I’ll post them here.After Virus Bulletin, I had a nice conversation with Ryan at eWeek that he recorded for the OnSecurity Podcast: The Rise of For-Profit Botnets [MP3, duration: 17:38]. I had never done a podcast before, and I don’t usually listen to them (though I...
Read this day in the archive
July 18, 2006
Googling for Malware, Bobbing for Mass Mailers
arbor networks / backdoors / interesting research / malware / Security / trojan horses / viruses / worms
HD Moore recently released a malware search engine. Dan Hubbard and the team at Websense, frustrated that they didn’t get a copy of the code (evidently all he had to do was ask …), wrote their own. I actually prefer Dan’s implementation, as it uses a couple of different ideas, however I prefer the results...
Read this day in the archive
July 18, 2006
DDoS Attacks from Nowhere
arbor networks / botnets / forensics / Security
Over the weekend Ed Vielmetti pointed out to me that Zooomr had been under a DDoS attack as they were preparing to roll out their 2.0 site. As discussed on their blog, the Zooomr guys describe what’s going on (well, in very limited detail):Well that’s how it feels when you work really hard for something...
Read this day in the archive
April 14, 2006
More Pie Charts & Fingerprinting
forensics / interesting research / phishing / Security
I’ve been fingerprinting a lot of malicious servers the past couple of days and improving my approach. I focused on phishing servers because they represent a class of boxes I can interrogate in a few ways. Sure enough, when I run the original tests based on p0f2 and xprobe2, I get similar results as I...
Read this day in the archive
Back to the author index · Open the day-by-day archive