[90500] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Are botnets relevant to NANOG?

daemon@ATHENA.MIT.EDU (Rick Wesson)
Fri May 26 19:47:00 2006

Date: Fri, 26 May 2006 16:47:04 -0700
From: Rick Wesson <wessorh@ar.com>
To: Martin Hannigan <hannigan@renesys.com>
Cc: nanog@merit.edu
In-Reply-To: <7.0.1.0.2.20060526191624.021d4530@renesys.com>
Errors-To: owner-nanog@merit.edu


> I am saying I am reading the OARC comments and this is sort of what
> it fees like. As much as Gadi seems to appropriate others credit,
> Randy Vaugh and him have been doing this work for some time and
> deserves some credit so I'd say "have you spoken to them about how
> to make their report better" yet instead of "create more".

Yes, we have worked with Gati and Randy Vaugh; infact randy helped me 
out today; thanks randy!

There is a difference in how Randy/Gati collect data and how we collect 
data. The stuff we publish are from numerous dns based realtime 
blacklists and spam traps we run. Other folks black-hole botnets and 
capture data.

We both come up with a dataset that overlaps but we don't yet know by 
how much. So our data is another view using a different methodology and 
isn't supposed to be "better" but confirming of where the problem is and 
  estimates of its magnitude.


-rick



home help back first fref pref prev next nref lref last post