LACREND: Los Angeles/Colorado Research Exchange for Network Data

Project Summary

The LACREND project participates as a data provider and a data-hosting site under the PREDICT program. LACREND will provide the research community with a rich set of high-quality network data, including traffic traces and network topology information. The ultimate goal of this work is to enable new research and improvements in network security.

LACREND is a joint research effort of USC's Information Sciences Institute, Computer Science Department, and Information Technology Services and is supported by the DHS IMPACT program through contract NBCHC040137 (2004-2007) and NBCHC080035 (2007-2017).

People

  • Maureen Dougherty, project lead and director of USC HPC (USC Information Technology Services)
  • Hang Guo, PhD student (USC CS Dept. and ISI)
  • John Heidemann, PI on this project, project leader and professor (USC/ISI)
  • Basileal Imana, PhD student (USC CS Dept. and ISI)
  • Aqib Nisar, PhD student (USC CS Dept. and ISI)
  • Christos Papadopoulos, co-PI on this project, professor (Colorado State University CS Dept.) christos (at) cs.colostate.edu
  • Yuri Pradkin, researcher (USC/ISI)
  • Lan Wei, PhD student (USC CS Dept. and ISI)
  • Liang Zhu, PhD student (USC CS Dept. and ISI)

Alumni

  • Abdulla Alwabel, PhD student (USC CS Dept. and ISI)
  • Xue Cai, USC CS PhD graduate (2013) (USC/ISI and CSD)
  • Xun Fan, USC PhD graduate (2015) (USC CS Dept. and ISI)
  • Kaustubh Gadkari, PhD student (Colorado State University CS Dept.)
  • Romello Goodman, undergraduate researcher (USC/SURE Program) romellogood (at) gmail.com
  • Lin Quan, USC CS PhD graduate (2014) (USC/ISI and CSD)

Publications

  • Liang Zhu and John Heidemann 2017. LDplayer: DNS Experimentation at Scale. Technical Report 722. USC/Information Sciences Institute. [PDF] [Code] ["Details"]
  • Wouter B. de Vries, Ricardo de O. Schmidt, Wes Haraker, John Heidemann, Pieter-Tjerk de Boer and Aiko Pras 2017. Verfploeter: Broad and Load-Aware Anycast Mapping. Proceedings of the ACM Internet Measurement Conference (London, UK, 2017). [DOI] [PDF] [Dataset] ["Details"]
  • Moritz Müller, Giovane C. M. Moura, Ricardo de O. Schmidt and John Heidemann 2017. Recursives in the Wild: Engineering Authoritative DNS Servers. Proceedings of the ACM Internet Measurement Conference (London, UK, 2017). [DOI] [PDF] [Dataset] ["Details"]
  • Kensuke Fukuda, John Heidemann and Abdul Qadeer 2017. Detecting Malicious Activity with DNS Backscatter Over Time. ACM/IEEE Transactions on Networking. 25, 5 (Aug. 2017), 3203–3218. [DOI] [PDF] [Dataset] ["Details"]
  • Liang Zhu and John Heidemann 2017. LDplayer: DNS Experimentation at Scale (abstract with poster). Technical Report ISI-TR-2017-721. USC/Information Sciences Institute. [PDF] [Code] ["Details"]
  • Liang Zhu and John Heidemann 2017. LDplayer: DNS Experimentation at Scale (poster abstract). Proceedings of the SIGCOMM Posters and Demos (Aug. 2017), 60–62. [DOI] [PDF] [Code] ["Details"]
  • Lan Wei and John Heidemann 2017. Does Anycast Hang up on You? IEEE. [PDF] ["Details"]
  • Jelena Mirkovic, Genevieve Bartlett, John Heidemann, Hao Shi and Xiyue Deng 2017. Do You See Me Now? Sparsity in Passive Observations of Address Liveness. IEEE International Workshop on Traffic Monitoring and Analaysis (Dublin, Ireland, Jul. 2017), to appear. [DOI] [PDF] ["Details"]
  • John Heidemann 2017. Digging in to Ground Truth in Network Measurements. Talk at the Network Traffic Measurement and Analysis PhD School. [PDF] ["Details"]
  • Moritz Müller, Giovane C. M. Moura, Ricardo de O. Schmidt and John Heidemann 2017. Recursives in the Wild: Engineering Authoritative DNS Servers. Technical Report ISI-TR-720. USC/Information Sciences Institute. [PDF] ["Details"]
  • Wouter B. de Vries, Ricardo de O. Schmidt, Wes Haraker, John Heidemann, Pieter-Tjerk de Boer and Aiko Pras 2017. Verfploeter: Broad and Load-Aware Anycast Mapping. Technical Report ISI-TR-719. USC/Information Sciences Institute. [PDF] [Dataset] ["Details"]
  • Hang Guo and John Heidemann 2017. Detecting ICMP Rate Limiting in the Internet. Technical Report ISI-TR-717. USC/Information Sciences Institute. [PDF] ["Details"]
  • Ricardo de O. Schmidt, John Heidemann and Jan Harm Kuipers 2017. Anycast Latency: How Many Sites Are Enough? Proceedings of the Passive and Active Measurement Workshop (Sydney, Australia, Mar. 2017), to appear. [PDF] ["Details"]
  • Liang Zhu and John Heidemann 2017. Infrastructure for Experimental Replay and Mutation of DNS Queries. Talk at Active Internet Measurement Workshop. [PDF] ["Details"]
  • John Heidemann 2017. Collecting and Visualizing Outages Over the Long Haul. Talk at Active Internet Measurement Workshop. [PDF] ["Details"]
  • John Heidemann 2017. DNS Privacy, Service Management, and Research: Friends or Foes. Talk at ISOC NDSS Workshop on DNS Privacy . [PDF] ["Details"]
  • Lan Wei and John Heidemann 2017. Does Anycast Hang up on You? (extended). Technical Report ISI-TR-716. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann 2016. Distributed Denial-of-Service: What Datasets Can Help? Invited talk at ACM Annual Computer Security Applications Conference. [PDF] ["Details"]
  • Anant Shah, Romain Fontugne and Christos Papadopoulos 2016. Towards Characterizing International Routing Detours. Proceedings of the 12th Asian Internet Engineering Conference (AINTEC) (Bangkok, Thailand, Nov. 2016), to appear. ["Details"]
  • Giovane C. M. Moura, Ricardo de O. Schmidt, John Heidemann, Wouter B. de Vries, Moritz Müller, Lan Wei and Christian Hesselman 2016. Anycast vs. DDoS: Evaluating the November 2015 Root DNS Event. Proceedings of the ACM Internet Measurement Conference (Nov. 2016). [DOI] [PDF] ["Details"]
  • John Heidemann, Ricardo de O. Schmidt and Jan Harm Kuipers 2016. Anycast Latency: How Many Sites are Enough? Presentation at DNS-OARC Meeting. [PDF] ["Details"]
  • John Heidemann, Giovane C. M. Moura, Ricardo de O. Schmidt, and Wouter B. de Vries, Moritz Muller, Lan Wei and Christian Hesselman 2016. Anycast vs. DDoS: Evaluating Nov. 30. Presentation at DNS-OARC Meeting. [PDF] ["Details"]
  • Jelena Mirkovic, Genevieve Bartlett, John Heidemann, Hao Shi and Xiyue Deng 2016. Do You See Me Now? Sparsity in Passive Observations of Address Liveness (extended). Technical Report ISI-TR-2016-710. USC/Information Sciences Institute. [PDF] ["Details"]
  • Giovane C. M. Moura, Ricardo de O. Schmidt, John Heidemann, Wouter B. de Vries, Moritz Müller, Lan Wei and Christian Hesselman 2016. Anycast vs. DDoS: Evaluating the November 2015 Root DNS Event (extended). Technical Report ISI-TR-2016-709b. USC/Information Sciences Institute. [PDF] ["Details"]
  • Ricardo de O. Schmidt, John Heidemann and Jan Harm Kuipers 2016. Anycast Latency: How Many Sites Are Enough? Technical Report ISI-TR-2016-708. USC/Information Sciences Institute. [PDF] ["Details"]
  • Z. Hu, L. Zhu, J. Heidemann, A. Mankin, D. Wessels and P. Hoffman 2016. Specification for DNS over Transport Layer Security (TLS) . Technical Report 7858. Internet Request For Comments. [DOI] [PDF] ["Details"]
  • Abdul Qadeer, John Heidemann and Kensuke Fukuda 2016. Improving Long-term Accuracy of DNS Backscatter for Monitoring of Internet-Wide Malicious Activity (poster). Technical Report ISI-TR-2016-707. USC/Information Sciences Institute. [PDF] [Dataset] ["Details"]
  • Manaf Gharaibeh, Han Zhang, Christos Papadopoulos and John Heidemann 2016. Assessing Co-Locality of IP Blocks. Proceedings of the 19th IEEE Global Internet Symposium (San Francisco, CA, USA, Apr. 2016). [PDF] ["Details"]
  • Han Zhang, Manaf Gharaibeh, Spiros Thanasoulas and Christos Papadopoulos 2016. BotDigger: Detecting DGA Bots in a Single Network. Proceedings of the IEEE International Workshop on Traffic Monitoring and Analaysis (Louvain La Neuve, Belgium, Apr. 2016), 16–21. [DOI] ["Details"]
  • Liang Zhu, Zi Hu, John Heidemann, Duane Wessels, Allison Mankin and Nikita Somaiya 2016. T-DNS: Connection-Oriented DNS to Improve Privacy and Security (poster abstract). Technical Report ISI-TR-2016-706. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann 2016. New Opportunities for Research and Experiments in Internet Naming And Identification. Talk at Active Internet Measurement Workshop. [PDF] ["Details"]
  • Han Zhang, Manaf Gharaibeh, Spiros Thanasoulas and Christos Papadopoulos 2016. BotDigger: Detecting DGA Bots in a Single Network. Technical Report CS-16-101. Colorado State University . ["Details"]
  • Manaf Gharaibeh, Han Zhang, Christos Papadopoulos and John Heidemann 2015. Assessing Co-Locality of IP Blocks. Technical Report CS-15-103. Colorado State University Department of Computer Science . [PDF] ["Details"]
  • Kensuke Fukuda and John Heidemann 2015. Detecting Malicious Activity with DNS Backscatter. Proceedings of the ACM Internet Measurement Conference (Tokyo, Japan, Oct. 2015), 197–210. [DOI] [PDF] [Dataset] ["Details"]
  • Kensuke Fukuda and John Heidemann 2015. Detecting Malicious Activity with DNS Backscatter (extended). Technical Report ISI-TR-2015-704. USC/Information Sciences Institute. [PDF] [Dataset] ["Details"]
  • Abdulla Alwabel, John Healy, John Heidemann, Brian Luu, Yuri Pradkin and Rasoul Safavian. 2015. Evaluating Externally Visible Outages. Technical Report ISI-TR-701. USC/Information Sciences Institute. [PDF] ["Details"]
  • Liang Zhu, Zi Hu, John Heidemann, Duane Wessels, Allison Mankin and Nikita Somaiya 2015. Connection-Oriented DNS to Improve Privacy and Security. Proceedings of the 36thIEEE Symposium on Security and Privacy (San Jose, Californa, USA, May 2015), 171–186. [DOI] [PDF] [Code] [Dataset] ["Details"]
  • Xun Fan, Ethan Katz-Bassett and John Heidemann 2015. Assessing Affinity Between Users and CDN Sites. Proceedings of the 7th IEEE International Workshop on Traffic Monitoring and Analaysis (Barcelona, Spain, Apr. 2015). [DOI] [PDF] [Dataset] ["Details"]
  • Liang Zhu, Zi Hu, John Heidemann, Duane Wessels, Allison Mankin and Nikita Somaiya 2015. Connection-Oriented DNS to Improve Privacy and Security (extended). Technical Report ISI-TR-2015-695. USC/Information Sciences Institute. [PDF] [Code] ["Details"]
  • Liang Zhu, Zi Hu and John Heidemann 2015. Evaluation of Future DNSSEC Response Sizes at a Root and a TLD Server. [PDF] ["Details"]
  • John Heidemann 2014. Towards Understanding Internet Reliability. Presentation at DHS Cyber Security Division R&D Showcase and Technical Workshop. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2014. When the Internet Sleeps: Correlating Diurnal Networks With External Factors. Proceedings of the ACM Internet Measurement Conference (Vancouver, BC, Canada, Nov. 2014), 87–100. [DOI] [PDF] ["Details"]
  • John Heidemann 2014. Internet Populations (Good and Bad): Measurement, Estimation, and Correlation. Presentation at ICERM Workshop on Cybersecurity. [PDF] ["Details"]
  • Liang Zhu, Duane Wessels, Allison Mankin and John Heidemann 2014. Measuring DANE TLSA Deployment. Presentation at DNS-OARC Fall Workshop. [PDF] ["Details"]
  • Liang Zhu, Zi Hu, John Heidemann, Duane Wessels, Allison Mankin and Nikita Somaiya 2014. T-DNS: Connection-Oriented DNS to Improve Privacy and Security (extended). Technical Report ISI-TR-2014-693. USC/Information Sciences Institute. [PDF] [Code] ["Details"]
  • John Heidemann 2014. T-DNS: Connection-Oriented DNS to Improve Privacy and Security. Presentation at the Spring DNS-OARC Meeting. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2014. When the Internet Sleeps: Correlating Diurnal Networks With External Factors (extended). Technical Report ISI-TR-2014-691b. USC/Information Sciences Institute. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2014. When the Internet Sleeps: Correlating Diurnal Networks With External Factors (extended). Technical Report ISI-TR-2014-691. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann 2014. Sharing Network Data: Bright Gray Days Ahead. Keynote talk at Passive and Active Measurements Conference. [PDF] ["Details"]
  • Zi Hu, Liang Zhu, Calvin Ardi, Ethan Katz-Bassett, Harsha V. Madhyastha, John Heidemann and Minlan Yu 2014. The Need for End-to-End Evaluation of Cloud Availability. Proceedings of the Passive and Active Measurement Workshop (Marina del Rey, California, USA, Mar. 2014), 119–130. [DOI] [PDF] ["Details"]
  • Liang Zhu, Zi Hu, John Heidemann, Duane Wessels, Allison Mankin and Nikita Somaiya 2014. T-DNS: Connection-Oriented DNS to Improve Privacy and Security. Technical Report ISI-TR-2014-688. USC/Information Sciences Institute. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2014. Visualizing Sparse Internet Events: Network Outages and Route Changes. Computing. 96, 1 (Jan. 2014), 39–51. [DOI] [PDF] ["Details"]
  • Xue Cai, John Heidemann and Walter Willinger 2013. A Holistic Framework for Bridging Regional Threats to User QoE. Technical Report ISI-TR-2013-687. USC/Information Sciences Institute. [PDF] ["Details"]
  • Alefiya Hussain, Yuri Pradkin and John Heidemann 2013. Replay of Malicious Traffic in Network Testbeds. Proceedings of the 13th IEEE Conference on Technologies for Homeland Security (HST) (Waltham, Massachusetts, USA, Nov. 2013), (to appear). [PDF] ["Details"]
  • Matt Calder, Xun Fan, Zi Hu, Ethan Katz-Bassett, John Heidemann and Ramesh Govindan 2013. Mapping the Expansion of Google’s Serving Infrastructure. Proceedings of the ACM Internet Measurement Conference (Barcelona, Spain, Oct. 2013), 313–326. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2013. Trinocular: Understanding Internet Reliability Through Adaptive Probing. Proceedings of the ACM SIGCOMM Conference (Hong Kong, China, Aug. 2013), 255–266. [DOI] [PDF] ["Details"]
  • Matt Calder, Xun Fan, Zi Hu, Ethan Katz-Bassett, John Heidemann and Ramesh Govindan 2013. Mapping the Expansion of Google’s Serving Infrastructure. Technical Report TR 13-935. University of Southern California Computer Science Department. [PDF] ["Details"]
  • John Heidemann 2013. Evaluating Anycast in the Domain Name System. Presentation at DNS-OARC Meeting. [PDF] ["Details"]
  • Xun Fan, John Heidemann and Ramesh Govindan 2013. Evaluating Anycast in the Domain Name System. Proceedings of the IEEE Infocom (Turin, Italy, Apr. 2013), 1681–1689. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2013. Poster Abstract: Towards Active Measurements of Edge Network Outages. Proceedings of the Passive and Active Measurement Workshop (Hong Kong, China, Mar. 2013), 276–279. [DOI] [PDF] ["Details"]
  • John Heidemann 2013. Long-term Data Collection and Analysis of Outages at the Edge. Talk given at CAIDA Workshop on Active Internet Measurement Systems. [PDF] ["Details"]
  • John Heidemann 2013. Active Probing of Edge Networks: Outages During Hurricane Sandy. Talk given at NANOG57 as part of panel hosted by James Cowie. [PDF] ["Details"]
  • John Heidemann 2013. Active Probing of Edge Networks: Hurricane Sandy and Beyond. Talk given at FCC Workshop on Network Resiliency. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2013. Visualizing Sparse Internet Events: Network Outages and Route Changes. Computing. (Jan. 2013), to appear. [DOI] [PDF] ["Details"]
  • John Heidemann and Walter Willinger 2013. Internet Visualization. Computing. 96, 1 (2013), 1–2. [DOI] [PDF] ["Details"]
  • John Heidemann, Lin Quan and Yuri Pradkin 2012. A Preliminary Analysis of Network Outages During Hurricane Sandy. Technical Report ISI-TR-2008-685b. USC/Information Sciences Institute. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2012. Visualizing Sparse Internet Events: Network Outages and Route Changes. Proceedings of the First ACM Workshop on Internet Visualization (Boston, Mass., USA, Nov. 2012). [PDF] ["Details"]
  • John Heidemann 2012. Broadening DNS Research: beyond just DNS anonymization (work in progress). Talk at ISC/CAIDA Data Collaboration Workshop. [PDF] ["Details"]
  • Xue Cai, John Heidemann, Balachander Krishnamurthy and Walter Willinger 2012. An Organization-Level View of the Internet and its Implications (Extended). Technical Report ISI-TR-2009-679. USC/Information Sciences Institute. [PDF] ["Details"]
  • Xun Fan, John Heidemann and Ramesh Govindan 2012. Characterizing Anycast in the Domain Name System. Technical Report ISI-TR-2011-681. USC/Information Sciences Institute. [PDF] ["Details"]
  • Lin Quan, John Heidemann and Yuri Pradkin 2012. Detecting Internet Outages with Precise Active Probing (extended). Technical Report ISI-TR-2012-678b. USC/Information Sciences Institute. [PDF] ["Details"]
  • Xun Fan, John Heidemann and Ramesh Govindan 2011. Identifying and Characterizing Anycast in the Domain Name System. Technical Report ISI-TR-2011-671. USC/Information Sciences Institute. [PDF] ["Details"]
  • Lin Quan and John Heidemann 2011. Detecting Internet Outages with Active Probing (extended). Technical Report ISI-TR-2011-672. USC/Information Sciences Institute. [PDF] ["Details"]
  • Genevieve Bartlett, John Heidemann and Christos Papadopoulos 2011. Low-Rate, Flow-Level Periodicity Detection. Proceedings of the 14th IEEE Global Internet Symposium (Shanghai, China, Apr. 2011), 804–809. [DOI] [PDF] ["Details"]
  • Xun Fan and John Heidemann 2010. Selecting Representative IP Addresses for Internet Topology Studies. Proceedings of the ACM Internet Measurement Conference (Melbourne, Australia, Nov. 2010), 411–423. [DOI] [PDF] ["Details"]
  • Lin Quan and John Heidemann 2010. On the Characteristics and Reasons of Long-lived Internet Flows. Proceedings of the ACM Internet Measurement Conference (Melbourne, Australia, Nov. 2010), 444–450. [DOI] [PDF] ["Details"]
  • Gautam Thatte, Urbashi Mitra and John Heidemann 2010. Parametric Methods for Anomaly Detection in Aggregate Traffic. ACM/IEEE Transactions on Networking. 19, 2 (Aug. 2010), 512–525. [DOI] [PDF] ["Details"]
  • Xun Fan and John Heidemann 2010. Selecting Representative IP Addresses for Internet Topology Studies. Technical Report ISI-TR-2010-666. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann 2010. Mapping the Internet to Assist Cyber-Defense. Invited talk at Spring Electronic Crimes Task Force Meeting. [PDF] ["Details"]
  • Lin Quan and John Heidemann 2010. On the Characteristics and Reasons of Long-lived Internet Flows (extended). Technical Report ISI-TR-2010-667. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann and Christos Papadopoulos 2009. Uses and Challenges for Network Datasets. Proceedings of the IEEE Cybersecurity Applications and Technologies Conference for Homeland Security (CATCH) (Washington, DC, USA, Mar. 2009), 73–82. [DOI] [PDF] ["Details"]
  • Xue Cai and John Heidemann 2009. Understanding Address Usage in the Visible Internet. Technical Report ISI-TR-2009-656. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann 2009. USC/LANDER Passive and Active Data Collection. Lightning talk at CAIDA AIMS Workshop. [PDF] ["Details"]
  • John Heidemann, Yuri Pradkin, Ramesh Govindan, Christos Papadopoulos, Genevieve Bartlett and Joseph Bannister 2008. Census and Survey of the Visible Internet. Proceedings of the ACM Internet Measurement Conference (Vouliagmeni, Greece, Oct. 2008), 169–182. [PDF] ["Details"]
  • Xue Cai and John Heidemann 2008. Active Probing to Classify Internet Address Blocks (poster abstract). Proceedings of the ACM SIGCOMM Conference (Seattle, Washington, USA, Aug. 2008), to appear. [PDF] ["Details"]
  • Xue Cai and John Heidemann 2008. Active Probing to Classify Internet Address Blocks (poster abstract). Technical Report ISI-TR-2008-653. USC/Information Sciences Institute. [PDF] ["Details"]
  • John Heidemann and Yuri Pradkin 2007. Mapping the Internet Address Space (Poster). (Aug. 2007). [Code] [Dataset] ["Details"]
  • John Heidemann, Yuri Pradkin, Ramesh Govindan, Christos Papadopoulos and Joseph Bannister 2007. Exploring Visible Internet Hosts through Census and Survey. Technical Report ISI-TR-2007-640. USC/Information Sciences Institute. [PDF] [Code] [Dataset] ["Details"]
  • Alefiya Hussain, Genevieve Bartlett, Yuri Pryadkin, John Heidemann, Christos Papadopoulos and Joseph Bannister 2005. Experiences with a Continuous Network Tracing Infrastructure. Technical Report ISI-TR-2005-601. USC/Information Sciences Institute. [PDF] ["Details"]

For related publications, please see the ANT publications web page.

Software

See also ANT software.

  • antlink Manage a tree of git or other VC repositories with funky symlinks
  • ant_rdns_crawler The ANT RNDS crawler discovers reverse DNS names for the entire IPv4 space, quickly, politely, and correctly.
  • AuntieTuna Chrome browser extension to detect phishing websites
  • babarchive Manage babarchives, checksumed directory trees that can be validated
  • babarchive Manage babarchives, checksumed directory trees that can be validated
  • dag scrubber Dag Scrubber is our tool for scrubbing packets of user data and optionally doing IP address anonymization. It supports both pcap and ERF format ("dag", giving the legacy name).
  • dag trace generator The DAG Trace generator is a collection of tools for parsing a DAG formatted packet header trace. (Please see the enclosed README for instructions.)
  • digit Digit is a client query tool for T-DNS (DNS with TCP and TLS), designed to measure performance.
  • dnsanon extract DNS traffic from pcap to text with optionally anonymization
  • dnsanon_rssac Dnsanon_rssac is an implementation of RSSAC-002v2 processing for DNS statistics
  • dns-replay-client dns-replay-client reads DNS query stream, replays them against a real DNS server with correct timing and outputs the latency for each query (optional). Multiple dns-replay-client instances can work coordinately to generate aggregated DNS query replay stream, with a separated program: dns-replay-controller.
  • dns-replay-controller dns-replay-controller reads DNS query stream and distributes queries to replay clients
  • icmptrain Rapid probing of IPv4.
  • icmptrain-hadoop-reader A plugin for Hadoop that parses icmptrain output from our ipv4 censuses and surveys.
  • IP Hitlist Generation We have developed a set of map/reduce processing scripts that run in Hadoop to consume our Internet address censuses and output hitlists. (This scripts depend on our internal Hadoop configuration and so will require some modification to work elsewhere, but we make them available and encourage feedback about their use.)
  • LANDER Trace Software LANDER Trace Capture software handles for packet capture, scrubbing, and triggering user-provided scripts
  • lonlat2color For geolocation of IP address maps we needed to convert (lon, lat) to color in HSL and RGB color schemes. We provide Perl and Python implementations.
  • print_datafile A command-line tool that prints icmptrain output from our ipv4 censuses and surveys.
  • stream_merger Stream merger is a tool to merge multiple traffic streams by feeding them through a FIFO/Drop tail queue and adjusting packet timing due to queueing. Its input is several packet trace files. The output is a single merged packet trace.
  • mtracecap A utility for capturing packets concurrently on several network devices and saving output in a single file while making an effort to minimize packet reordering in the output. This tool allows breaking output into multiple files based on size and time and compressing it on the fly by piping to a separate compression process.
  • tdns-client-proxy Tdns-client-proxy is a client-side proxy for DNS, designed to run on a computer taking UDP in and sending it privately with T-DNS to a remote recursive resolver
  • tdns-server-proxy Tdns-server-proxy is a server-side proxy for DNS. It listens to incoming private T-DNS (with TCP and TLS) and turns it back into UDP queries to a local DNS resolver
  • T-DNS support for unbound patch Unbound patches add STARTTLS handling to incoming unbound queries (but not outgoing T-DNS)

Datasets

As of January 2016, LACREND provides more than 400 datasets (more than 25TB compressed or 113TB uncopmressed) to researchers, either through PREDICT or directly to researchers (see details about getting data). We have provided more than 1200 datasets to nearly 150 different researchers over the last 10 years.

Related Links

ANT: the Analysis of Network Traffic research group