Lightweight Detection of Spamming Botnets

被引:0
|
作者
Takesue, Masaru [1 ]
机构
[1] Hosei Univ, Dept Appl Informat, Tokyo 1848584, Japan
关键词
Spam; bot; botnet; clustering; fingerprint; spam-specific word;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A botnet is one of the largest problems against the Internet society because it is used to mount Distributed Denial of Service (DDoS), to steal users credentials, to send spam email, and so on. To cope with the problem, this paper presents a method of detecting spamming botnets, exploiting the information in a hash table of spams produced in our spam filter. To partition the spams based on the similarity of their messages, we cluster the spams in the hash table in three steps by 1) removing the collision (due to the hashing) in each bucket of the table, 2) merging the clusters obtained in step 1), using the fingerprints of message bodies, and 3) further merging the second-step clusters based on the spam-specific words in the Subject headers of spams. We identify a bot using the IP address in the first internal Received header that is prepended to the list of Received headers by the first internal server of a receiving organization. By simulation, we can cluster about 18,000 real-world spams in about 4,000 seconds with no misclustering on our commodity workstation. The active IP space for bots to send spams is almost the same as the one reported in the literature, except of a slight expansion.
引用
收藏
页码:1 / 6
页数:6
相关论文
共 50 条
  • [21] GSLDA: LDA-based group spamming detection in product reviews
    Zhuo Wang
    Songmin Gu
    Xiaowei Xu
    Applied Intelligence, 2018, 48 : 3094 - 3107
  • [22] BOTNETS DETECTION USING BACK TRACKING IN WIRED NETWORKS
    Vidiyala, Deepthi
    Guntupalli, Bindu
    Alluri, B. K. S. P. Kumar Raju
    2018 FOURTEENTH INTERNATIONAL CONFERENCE ON INFORMATION PROCESSING (ICINPRO) - 2018, 2018, : 1 - 5
  • [23] Spamming the globe
    Beardsley, C
    MECHANICAL ENGINEERING, 1997, 119 (02) : 6 - 6
  • [24] Ready for spamming?
    Highland, HJ
    COMPUTERS & SECURITY, 1996, 15 (01) : 4 - 7
  • [25] Avoiding Honeypot Detection in Peer-to-Peer Botnets
    Al-Hakbani, Meerah M.
    Dahshan, Mostafa H.
    2015 IEEE INTERNATIONAL CONFERENCE ON ENGINEERING AND TECHNOLOGY (ICETECH), 2015, : 13 - 19
  • [26] Autoencoder Ensemble Method for Botnets Detection on IOT Devices
    Arroyo, Steven E.
    Ho, Shen Shyang
    2022 21ST IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS, ICMLA, 2022, : 715 - 720
  • [27] A Survey on Botnets: Incentives, Evolution, Detection and Current Trends
    Vu, Simon Nam Thanh
    Stege, Mads
    El-Habr, Peter Issam
    Bang, Jesper
    Dragoni, Nicola
    FUTURE INTERNET, 2021, 13 (08):
  • [28] GSLDA: LDA-based group spamming detection in product reviews
    Wang, Zhuo
    Gu, Songmin
    Xu, Xiaowei
    APPLIED INTELLIGENCE, 2018, 48 (09) : 3094 - 3107
  • [29] A Unified Model for Unsupervised Opinion Spamming Detection Incorporating Text Generality
    Xu, Yinqing
    Shi, Bei
    Tian, Wentao
    Lam, Wai
    PROCEEDINGS OF THE TWENTY-FOURTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE (IJCAI), 2015, : 725 - 731
  • [30] User Preference-Based Spamming Detection with Coupled Behavioral Analysis
    Jiang, Frank
    Tang, Mingdong
    Quang Anh Tran
    SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE, 2016, 10066 : 466 - 477