Technology Voices

Publishing the blogs of technology leaders and connecting them to a large audience of industry decision makers.

Jose Nazario’s blog

Senior Security Engineer, Arbor Networks

Dr. Jose Nazario is a Senior Security Engineer within Arbor Networks' Arbor Security Engineering & Response Team (ASERT). In this capacity, he is responsible for analyzing burgeoning Internet security threats, reverse engineering malicious code, software development, developing security mechanisms that are then distributed to Arbor's Peakflow platforms via the Active Threat Feed (ATF) threat detection service. Dr. Nazario's research interests include large-scale Internet trends such as reachability and topology measurement, Internet-scale events such as DDoS attacks, botnets and worms, source code analysis tools, and data mining. He is the author of the books "Defense and Detection Strategies against Internet Worms" and "Secure Architectures with OpenBSD." He earned a Ph.D. in biochemistry from Case Western Reserve University in 2002. Prior to joining Arbor Networks, he was an independent security consultant. Dr. Nazario regularly speaks at conferences worldwide, with past presentations at CanSecWest, PacSec, Blackhat, and NANOG. He also maintains WormBlog.com, a site devoted to studying worm detection and defense research.

Entries in the archive

November 12, 2006

Bits and Pieces: November 12

Security

A few things caught my eye this week, so I’ll post them here.After Virus Bulletin, I had a nice conversation with Ryan at eWeek that he recorded for the OnSecurity Podcast: The Rise of For-Profit Botnets [MP3, duration: 17:38]. I had never done a podcast before, and I don’t usually listen to them (though I...

Read this day in the archive

July 18, 2006

Googling for Malware, Bobbing for Mass Mailers

arbor networks / backdoors / interesting research / malware / Security / trojan horses / viruses / worms

HD Moore recently released a malware search engine. Dan Hubbard and the team at Websense, frustrated that they didn’t get a copy of the code (evidently all he had to do was ask …), wrote their own. I actually prefer Dan’s implementation, as it uses a couple of different ideas, however I prefer the results...

Read this day in the archive

July 18, 2006

DDoS Attacks from Nowhere

arbor networks / botnets / forensics / Security

Over the weekend Ed Vielmetti pointed out to me that Zooomr had been under a DDoS attack as they were preparing to roll out their 2.0 site. As discussed on their blog, the Zooomr guys describe what’s going on (well, in very limited detail):Well that’s how it feels when you work really hard for something...

Read this day in the archive

April 14, 2006

More Pie Charts & Fingerprinting

forensics / interesting research / phishing / Security

I’ve been fingerprinting a lot of malicious servers the past couple of days and improving my approach. I focused on phishing servers because they represent a class of boxes I can interrogate in a few ways. Sure enough, when I run the original tests based on p0f2 and xprobe2, I get similar results as I...

Read this day in the archive

Back to the author index · Open the day-by-day archive