Thursday, January 7, 2016

Internships for Summer 2016

The ICSI Networking and Security Group is accepting applications for summer interns for 2016. ICIR's internships are paid positions, and generally aimed at Ph.D. students actively engaged in network and/or security research and with research interests that have overlap with the general areas of research of one or more of the group's staff.

Please send your applications no later than Friday, January 29, 2016. We will notify applicants of our decisions by February 16, 2015.

You can find details regarding the application process here.

Thursday, January 22, 2015

Internships for Summer 2015

The ICSI Networking and Security Group is accepting applications for summer interns for 2015. ICIR's internships are paid positions, and generally aimed at Ph.D. students actively engaged in network and/or security research and with research interests that have overlap with the general areas of research of one or more of the group's staff.

Please send your applications no later than Friday, January 30, 2015. We will notify applicants of our decisions by February 13, 2015.

You can find details regarding the application process here.

Tuesday, January 14, 2014

Internships for Summer 2014

The ICSI Networking and Security Group now accepts applications for summer interns for 2014. ICIR's internships are paid positions, and generally aimed at Ph.D. students actively engaged in network and/or security research and with research interests that have overlap with the general areas of research of one or more of the group's staff.

Please send your applications no later than Friday, January 31, 2014. We will notify applicants of our decisions by February 14, 2014.

You can find details regarding the application process here.

Thursday, April 18, 2013

Fathom is a Google Summer of Code Project

Fathom, our browser-based network measurement platform, is part of M-lab's list of Google Summer of Code Projects. If you're a great browser/JavaScript hacker and interested in working with us on this project in the summer, check out the Fathom website and the GSoC ideas page, and get in touch!

Friday, January 18, 2013

Internships for Summer 2013

The ICSI Networking and Security Group is accepting applications for summer interns for Summer 2013. ICIR's internships are paid positions, and generally aimed at Ph.D. students actively engaged in network and/or security research and with research interests that have overlap with the general areas of research of one or more of the group's staff.

The deadline for submissions is Friday February 8, 2013.
Applicants will be notified of decisions by February 22, 2013.

The application process is outlined here.


Friday, November 2, 2012

Announcing the ICSI Certificate Notary

We are happy to announce the ICSI Certificate Notary today. This service provides near real-time reputation information on a large number of TLS/SSL certificates seen in the wild, collected continuously from a set of partner network sites. The notary’s data includes the time when a certificate was first and last seen, and whether we can establish a valid chain to a root certificate from the Mozilla root store.

Since the beginning of this year we collaborate with operations at about ten large network sites to passively extract certificates from their upstream traffic using Bro. This has allowed us to build a certificate database that now comprises roughly half a million unique web certificates from over 8 billion connections, representing the activity of estimated 220,000 users. (In fact, we have collected 7 million unique certificates but the majority is non-web activity and hence excluded from the notary.)

You can use the service by sending a DNS request for an A or TXT record to:

<sha1>.notary.icsi.berkeley.edu

The token <sha1> represents the SHA1 digest of the certificate to query, which you may find when consulting your browser for details about a certificate. For A record queries, the result comes back either as the address 127.0.0.1 to indicate that our data providers have seen the certificate, as 127.0.0.2 if we could recently validate the certificate against the Mozilla root store, or NXDOMAIN if we have not seen the certificate. For TXT record queries, the notary returns key-value pairs with more details. Here is an example reply:

"version=1 first_seen=15387 last_seen=15646 times_seen=260 validated=1"

For further details, usage instructions, and background reading, please visit the notary website at http://notary.icsi.berkeley.edu. We much appreciate your feedback at this early stage, both positive works-for-me notices as well as problems and suggestions for improvements.

Monday, February 6, 2012

Summer Internships

The Networking Group is now accepting applications for Summer 2012 internships. Applicants should be Ph.D. students with a solid research background in networking and/or security. To apply, send a resume to summer@icir.org, and arrange for a letter of reference to be sent to that address too. The deadline for applications is February 24, 2012.

Thursday, June 9, 2011

Oakland'11 papers

At this year's IEEE Symposium on Security and Privacy we presented two papers.

The first presents an extensive measurement study our team of 15 researchers, postdocs and graduate students at UCSD and ICSI has worked on for two years. It expands the analysis of the spam value chain into the financial domain, illuminates the affiliate program landscape for pharmaceuticals, replica goods, and software, and identifies three banks that together receive the credit card transactions of 95% of the spam we observe.

The second paper presents Monarch, a real-time system that crawls URLs as they are submitted to web services and determines whether the URLs direct to spam. The paper evaluates the fundamental challenges that arise due to the diversity of web service spam. Monarch could protect a service such as Twitter—which needs to process 15 million URLs/day—for a bit under $800/day.

Wednesday, June 8, 2011

SIGCOMM awards

ACM has awarded this year's SIGCOMM award to Vern Paxson, for his seminal contributions to the fields of Internet measurement and Internet security, and for distinguished leadership and service to the Internet community.

SIGCOMM's Test-Of-Time Award recognizes papers published at least ten years ago that have turned out to make significant contributions to the field of networking. This year one of the two papers chosen is "A Scalable Content-addressable Network" which appeared in SIGCOMM 2001 and is authored by current and past ICSI researchers Sylvia Ratnasamy, Paul Francis, Mark Handley, Richard Karp and Scott Shenker.

Wednesday, February 23, 2011

Bro Internship

The Bro project is looking for an intern this summer as well.

Tuesday, February 22, 2011

Summer Internships

The Networking Group is now accepting applications for Summer 2011 internships. Applicants should be Ph.D. students with a solid research background in networking and/or security. To apply, send a resume to summer@icir.org, and arrange for a letter of reference to be sent to that address too. The deadline for applications is March 18, 2011.

Tuesday, December 7, 2010

Characterizing Scanning Behavior

Last week, Tom Dooner and Brian Stack, two undergraduates we're working with at Case Western Reserve University, presented a poster at Case's Intersections: SOURCE Undergraduate Symposium and Poster Session. The work presented is a preliminary characterization of scanning patterns as observed over 12+ years at LBNL. You can view the poster here.

Followup: Tom and Brian's poster won second place among posters from the College of Engineering at this event. Congrats!

Tuesday, November 23, 2010

IMC'10 Paper on Illuminating Edge Networks

Earlier this month we presented the ICSI Netalyzr at the Internet Measurement Conference in Melbourne, Australia. The Netalyzr is a public edge network measurement and debugging service that evaluates the functionality provided by people's Internet connectivity. Its tests include outbound port filtering, hidden in-network HTTP caches, DNS manipulations, NAT behavior, path MTU issues, access-modem buffer capacity, and growing IPv6 support and performance. The paper is available here: The Netalyzr has been one of our major research efforts over the past two years, and we're thrilled by the popularity it has gained since we launched it—to date, Netalyzr has collected 160,000 sessions from 6,800 different organisations in 190 countries: The study is ongoing, so visit the Netalyzr website and run it yourself!

Wednesday, November 17, 2010

Paper on Emergency Notification

We recently published a paper that discusses a special-purpose social network for communicating during an wide-scale emergency situation (e.g., an earthquake). The CCR public review of the paper is also available here.

Friday, October 22, 2010

Dealing with Tussle

At HotNets this week Aditya Akella presented our joint paper outlining an architectural framework for dealing with the tussle that naturally arise between networks that want to control resources and enforce policies, on the one hand, and users who are trying to accomplish some work, on the other. The paper is: While many of the details of a practical implementation would need to be worked out we'd appreciate feedback on this thought experiment.

Monday, September 13, 2010

Postdoctoral Fellowship Opening

The International Computer Science Institute (ICSI) invites applications for a Postdoctoral Fellow position in the area of applying modern compiler technology to the domain of high-performance network security monitoring.

The Fellow will be working with ICSI's Networking Group on designing, implementing, and evaluating novel approaches for efficient monitoring of large-scale network environments. The position's primary research focus is on developing strategies for compiling high-level analysis descriptions into highly optimized code for execution on current multi-core architectures.

Please see the full posting for more information.

Tuesday, August 24, 2010

Major NSF Funding for Bro Development

The Bro team is jazzed to announce that the National Science Foundation has awarded a grant of almost $3M to the International Computer Science Institute (ICSI) and the National Center for Supercomputing Applications (NCSA) for extensive Bro development.

The funded project aims specifically at addressing much of the feedback that we have received from Bro users over the years. It will enable us to refine many of the rough edges that the system has accumulated over time[*], improve Bro's performance significantly, and also make it much easier for the community to contribute to the project.

For further information, see the joint ICSI/NCSA press release.

Thanks to everybody who helped make this happen!

[*] Yes, that includes documentation!

Cybercasing the Joint

Earlier this month, we presented a paper on how geotagging can leave users vulnerable to what we termed "cybercasing":

Gerald Friedland, Robin Sommer
Cybercasing the Joint: On the Privacy Implications of Geo-Tagging
Proc. USENIX Workshop on Hot Topics in Security, 2010

This work was featured by the New York Times, ABC News, Toronto Star, and New Scientist.

Monday, May 24, 2010

Machine Learning For Network Intrusion Detection

At last week's IEEE Symposium on Security & Privacy, we presented some thoughts on using machine learning for intrusion detection:

Robin Sommer, Vern Paxson
Outside the Closed World: On Using Machine Learning For Network Intrusion Detection
Proc. IEEE Symposium on Security and Privacy, 2010

Slides are here.

Tuesday, May 4, 2010

LEET'10 paper on proactive domain blacklisting

At last week's LEET'10 workshop we presented our recent work on proactive domain blacklisting based on registration patterns of domain names used in scams.