Lightweight Detection of Spamming Botnets

被引:0
|
作者
Takesue, Masaru [1 ]
机构
[1] Hosei Univ, Dept Appl Informat, Tokyo 1848584, Japan
关键词
Spam; bot; botnet; clustering; fingerprint; spam-specific word;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A botnet is one of the largest problems against the Internet society because it is used to mount Distributed Denial of Service (DDoS), to steal users credentials, to send spam email, and so on. To cope with the problem, this paper presents a method of detecting spamming botnets, exploiting the information in a hash table of spams produced in our spam filter. To partition the spams based on the similarity of their messages, we cluster the spams in the hash table in three steps by 1) removing the collision (due to the hashing) in each bucket of the table, 2) merging the clusters obtained in step 1), using the fingerprints of message bodies, and 3) further merging the second-step clusters based on the spam-specific words in the Subject headers of spams. We identify a bot using the IP address in the first internal Received header that is prepended to the list of Received headers by the first internal server of a receiving organization. By simulation, we can cluster about 18,000 real-world spams in about 4,000 seconds with no misclustering on our commodity workstation. The active IP space for bots to send spams is almost the same as the one reported in the literature, except of a slight expansion.
引用
收藏
页码:1 / 6
页数:6
相关论文
共 50 条
  • [41] Hardware Isolation Technique for IRC-Based Botnets Detection
    Hategekimana, Festus
    Tbatou, Adil
    Bobda, Christophe
    Kamhoua, Charles
    Kwiat, Kevin
    2015 INTERNATIONAL CONFERENCE ON RECONFIGURABLE COMPUTING AND FPGAS (RECONFIG), 2015,
  • [42] BOTNETs: A Network Security Issue From Definition to Detection and Prevention
    Iftikhar, Umar
    Asrar, Kashif
    Waqas, Maria
    Ali, Syed Abbas
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 432 - 436
  • [43] Hawkeye : Finding Spamming Accounts
    Li, Chia-Heng
    Hsu, Fu-Hau
    Wang, Chuan-Sheng
    Chen, Shih-Jen
    Chen, Yao-Hsin
    Hwang, Yan-Ling
    2014 16TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2014,
  • [44] SHIELDNET: An Adaptive Detection Mechanism against Vehicular Botnets in VANETs
    Garip, Mevlut Turker
    Lin, Jonathan
    Reiher, Peter
    Gerla, Mario
    2019 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2019,
  • [45] Zombies and botnets
    Choo, Kim-Kwang
    TRENDS AND ISSUES IN CRIME AND CRIMINAL JUSTICE, 2007, (333): : 1 - 6
  • [46] Information Technology for Botnets Detection Based on Their Behaviour in the Corporate Area Network
    Lysenko, Sergii
    Savenko, Oleg
    Bobrovnikova, Kira
    Kryshchuk, Andrii
    Savenko, Bohdan
    COMPUTER NETWORKS (CN 2017), 2017, 718 : 166 - 181
  • [47] BotScoop: Scalable detection of DGA based botnets using DNS traffic
    Khehra, Gulbadan
    Sofat, Sanjeev
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [48] Detection of fast-flux botnets through DNS traffic analysis
    Soltanaghaei, E.
    Kharrazi, M.
    SCIENTIA IRANICA, 2015, 22 (06) : 2389 - 2400
  • [49] BOTNETS of Things
    Schneier, Bruce
    TECHNOLOGY REVIEW, 2017, 120 (02) : 89 - 91
  • [50] Of Bees and Botnets
    Sarvepalli, Vijay
    SWARM INTELLIGENCE (ANTS 2018), 2018, 11172 : 433 - 434