On Wed, 1 Aug 2001, Steven M. Bellovin wrote:
I ran a little script on the totals reported by www.incidents.org, calculating the ratio between successive samples. (The latest graph I could find, as of 1615 EDT, ended at 1400 EDT.) There was a period of steady exponential growth in there, but it seems to be tailing off. That's consistent with another report posted here.
Does anyone have any theories as to why its tailing, are the thousands of vulnerable machines being patched all of a sudden? If not then why is traffic decreasing so fast when the worm just keeps searching?
A couple of conjectures.... What is the correllation between infection rate and population-where-it-is- still-daylight? (Its middle of the night in Europe, no?) What is the likelyhood that people who din't know they were running IIS have turned it off. How about nets blocking port 80?