Thursday, January 7, 2016
Internships for Summer 2016
Please send your applications no later than Friday, January 29, 2016. We will notify applicants of our decisions by February 16, 2015.
You can find details regarding the application process here.
Thursday, January 22, 2015
Internships for Summer 2015
Please send your applications no later than Friday, January 30, 2015. We will notify applicants of our decisions by February 13, 2015.
You can find details regarding the application process here.
Tuesday, January 14, 2014
Internships for Summer 2014
Please send your applications no later than Friday, January 31, 2014. We will notify applicants of our decisions by February 14, 2014.
You can find details regarding the application process here.
Thursday, April 18, 2013
Fathom is a Google Summer of Code Project
Friday, January 18, 2013
Internships for Summer 2013
The deadline for submissions is Friday February 8, 2013.
Applicants will be notified of decisions by February 22, 2013.
The application process is outlined here.
Friday, November 2, 2012
Announcing the ICSI Certificate Notary
We are happy to announce the ICSI Certificate Notary today. This service provides near real-time reputation information on a large number of TLS/SSL certificates seen in the wild, collected continuously from a set of partner network sites. The notary’s data includes the time when a certificate was first and last seen, and whether we can establish a valid chain to a root certificate from the Mozilla root store.
Since the beginning of this year we collaborate with operations at about ten large network sites to passively extract certificates from their upstream traffic using Bro. This has allowed us to build a certificate database that now comprises roughly half a million unique web certificates from over 8 billion connections, representing the activity of estimated 220,000 users. (In fact, we have collected 7 million unique certificates but the majority is non-web activity and hence excluded from the notary.)
You can use the service by sending a DNS request for an A or TXT record to:
<sha1>.notary.icsi.berkeley.edu
The token <sha1> represents the SHA1 digest of the certificate to query,
which you may find when consulting your browser for details about a
certificate. For A record queries, the result comes back either as the address
127.0.0.1 to indicate that our data providers have seen the certificate, as
127.0.0.2 if we could recently validate the certificate against the Mozilla
root store, or NXDOMAIN if we have not seen the certificate. For TXT record
queries, the notary returns key-value pairs with more details. Here is an
example reply:
"version=1 first_seen=15387 last_seen=15646 times_seen=260 validated=1"
For further details, usage instructions, and background reading, please visit the notary website at http://notary.icsi.berkeley.edu. We much appreciate your feedback at this early stage, both positive works-for-me notices as well as problems and suggestions for improvements.
Monday, February 6, 2012
Summer Internships
The Networking Group is now accepting applications for Summer 2012 internships. Applicants should be Ph.D. students with a solid research background in networking and/or security. To apply, send a resume to summer@icir.org, and arrange for a letter of reference to be sent to that address too. The deadline for applications is February 24, 2012.
Thursday, June 9, 2011
Oakland'11 papers
At this year's IEEE Symposium on Security and Privacy we presented two papers.
The first presents an extensive measurement study our team of 15 researchers, postdocs and graduate students at UCSD and ICSI has worked on for two years. It expands the analysis of the spam value chain into the financial domain, illuminates the affiliate program landscape for pharmaceuticals, replica goods, and software, and identifies three banks that together receive the credit card transactions of 95% of the spam we observe.
- K. Levchenko, A. Pitsillidis, N. Chachra, B. Enright, M. Felegyhazi, C. Grier, T. Halvorson, C. Kanich, C. Kreibich, H. Liu, D. McCoy, N. Weaver, V. Paxson, G. M. Voelker, and S. Savage. Click Trajectories: End-to-End Analysis of the Spam Value Chain. IEEE Symposium on Security and Privacy, 2011, Oakland, USA.
The second paper presents Monarch, a real-time system that crawls URLs as they are submitted to web services and determines whether the URLs direct to spam. The paper evaluates the fundamental challenges that arise due to the diversity of web service spam. Monarch could protect a service such as Twitter—which needs to process 15 million URLs/day—for a bit under $800/day.
- K. Thomas, C. Grier, J. Ma, V. Paxson and D. Song. Monarch: Providing Real-Time URL Spam Filtering as a Service. IEEE Symposium on Security and Privacy, 2011, Oakland, USA.
Wednesday, June 8, 2011
SIGCOMM awards
ACM has awarded this year's SIGCOMM award to Vern Paxson, for his seminal contributions to the fields of Internet measurement and Internet security, and for distinguished leadership and service to the Internet community.
SIGCOMM's Test-Of-Time Award recognizes papers published at least ten years ago that have turned out to make significant contributions to the field of networking. This year one of the two papers chosen is "A Scalable Content-addressable Network" which appeared in SIGCOMM 2001 and is authored by current and past ICSI researchers Sylvia Ratnasamy, Paul Francis, Mark Handley, Richard Karp and Scott Shenker.
Wednesday, February 23, 2011
Tuesday, February 22, 2011
Summer Internships
The Networking Group is now accepting applications for Summer 2011 internships. Applicants should be Ph.D. students with a solid research background in networking and/or security. To apply, send a resume to summer@icir.org, and arrange for a letter of reference to be sent to that address too. The deadline for applications is March 18, 2011.
Tuesday, December 7, 2010
Characterizing Scanning Behavior
Followup: Tom and Brian's poster won second place among posters from the College of Engineering at this event. Congrats!
Tuesday, November 23, 2010
IMC'10 Paper on Illuminating Edge Networks
- Christian Kreibich, Nicholas Weaver, Boris Nechaev, and Vern Paxson. Netalyzr: Illuminating The Edge Network. Internet Measurement Conference, 2010, Melbourne, Australia. (bib)
The study is ongoing, so visit the Netalyzr website and run it yourself!
Wednesday, November 17, 2010
Paper on Emergency Notification
- Mark Allman. On Building Special-Purpose Social Networks for Emergency Communication. ACM Computer Communication Review, 40(5), October 2010.
Friday, October 22, 2010
Dealing with Tussle
- Chitra Muthukrishnan, Vern Paxson, Mark Allman, Aditya Akella. Using Strongly Typed Networking to Architect for Tussle. ACM SIGCOMM Workshop on Hot Topics in Networks (HotNets), October 2010.
Monday, September 13, 2010
Postdoctoral Fellowship Opening
The International Computer Science Institute (ICSI) invites applications for a Postdoctoral Fellow position in the area of applying modern compiler technology to the domain of high-performance network security monitoring.
The Fellow will be working with ICSI's Networking Group on designing, implementing, and evaluating novel approaches for efficient monitoring of large-scale network environments. The position's primary research focus is on developing strategies for compiling high-level analysis descriptions into highly optimized code for execution on current multi-core architectures.
Please see the full posting for more information.
Tuesday, August 24, 2010
Major NSF Funding for Bro Development
The Bro team is jazzed to announce that the National Science Foundation has awarded a grant of almost $3M to the International Computer Science Institute (ICSI) and the National Center for Supercomputing Applications (NCSA) for extensive Bro development.
The funded project aims specifically at addressing much of the feedback that we have received from Bro users over the years. It will enable us to refine many of the rough edges that the system has accumulated over time[*], improve Bro's performance significantly, and also make it much easier for the community to contribute to the project.
For further information, see the joint ICSI/NCSA press release.
Thanks to everybody who helped make this happen!
[*] Yes, that includes documentation!
Cybercasing the Joint
Earlier this month, we presented a paper on how geotagging can leave users vulnerable to what we termed "cybercasing":
Gerald Friedland, Robin Sommer
Cybercasing the Joint: On the Privacy Implications of Geo-Tagging
Proc. USENIX Workshop on Hot Topics in Security, 2010
This work was featured by the New York Times, ABC News, Toronto Star, and New Scientist.
Monday, May 24, 2010
Machine Learning For Network Intrusion Detection
At last week's IEEE Symposium on Security & Privacy, we presented some thoughts on using machine learning for intrusion detection:
Robin Sommer, Vern Paxson
Outside the Closed World: On Using Machine Learning For Network Intrusion Detection
Proc. IEEE Symposium on Security and Privacy, 2010
Slides are here.
Tuesday, May 4, 2010
LEET'10 paper on proactive domain blacklisting
- M. Felegyhazi, C. Kreibich, and V. Paxson. On the Potential of Proactive Domain Blacklisting. Third USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET '10), 2010, San Jose, CA, USA. (bib)