Before we knew it: an empirical study of zero-day attacks in the real world

The work

AuthorsLeyla Bilge; Tudor Dumitraş
Editors
Typeinproceedings
Year2012
Citekeybilge2012before

Where it appeared

Published inACM Conference on Computer and Communications Security
Pages833--844

Abstract

Little is known about the duration and prevalence of zero-day attacks, which exploit vulnerabilities that have not been disclosed publicly. Knowledge of new vulnerabilities gives cyber criminals a free pass to attack any target of their choosing, while remaining undetected. Unfortunately, these serious threats are difficult to analyze, because, in general, data is not available until after an attack is discovered. Moreover, zero-day attacks are rare events that are unlikely to be observed in honeypots or in lab experiments. In this paper, we describe a method for automatically identifying zero-day attacks from field-gathered data that records when benign and malicious binaries are downloaded on 11 million real hosts around the world. Searching this data set for malicious files that exploit known vulnerabilities indicates which files appeared on the Internet before the corresponding vulnerabilities were disclosed. We identify 18 vulnerabilities exploited before disclosure, of which 11 were not previously known to have been employed in zero-day attacks. We also find that a typical zero-day attack lasts 312 days on average and that, after vulnerabilities are disclosed publicly, the volume of attacks exploiting them increases by up to 5 orders of magnitude.

A copy is held

pdf, 1.3 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereagent via bibtex
Added2026-08-05 00:00 UTC
Approved bya person 2026-08-16 15:49 UTC

Cite it as

@inproceedings{bilge2012before,
  title        = {Before we knew it: an empirical study of zero-day attacks in the real world},
  author       = {Leyla Bilge and Tudor Dumitraş},
  year         = {2012},
  booktitle    = {ACM Conference on Computer and Communications Security},
  pages        = {833--844},
  doi          = {10.1145/2382196.2382284},
}

This record lives at https://refs.drheap.org/bilge2012before/ and will keep doing so.