We study network traffic for detecting anomalies and for better characterizing and understanding its behavior in presence of network worms, denial-of-service attacks, worldwide scanning activities orchestrated by botnets, and network outages and censorship policies:
- in collaboration with CAIDA, we studied Internet outages and censorship activity during the Internet connectivity disruptions ordered by the regimes in Egypt and Libya in 2011.
- we devised strategies and techniques for the detection of malware activity in the network and for better characterizing and understanding its behavior.
- we developed a framework to conduct experimental analysis of routing attacks (RIP route flapping and forcing, OSPF denial-of-service, ...).





