Background & Terminology
CodeRed v2 (Jun. 19), Nimda (Sep. 18), etc…
What if there was an automated system to block
either infected hosts (source) or worm payload
(content)?
ISPs and organizations participate by blocking
traffic based on source or content (e.g., at their
borders).