• Documents
  • Authors
  • Tables
  • Other Seers ▼
    RefSeer AckSeer CollabSeer SeerSeer
  • Log in
  • Sign up
  • MetaCart

CiteSeerX logo

Advanced Search Include Citations
Advanced Search Include Citations | Disambiguate

Studying Spamming Botnets Using Botlab

Cached

  • Download as a PDF

Download Links

  • [www.usenix.org]
  • [cs.washington.edu]
  • [research.microsoft.com]
  • [www.research.microsoft.com]
  • [www.cs.washington.edu]
  • [www.cs.washington.edu]
  • [www.cs.washington.edu]
  • [www.cs.washington.edu]

  • Save to List
  • Add to Collection
  • Correct Errors
  • Monitor Changes
by John P. John , Alexander Moshchuk , Steven D. Gribble , Arvind Krishnamurthy
Citations:32 - 1 self
  • Summary
  • Active Bibliography
  • Co-citation
  • Clustered Documents
  • Version History

BibTeX

@MISC{John_studyingspamming,
    author = {John P. John and Alexander Moshchuk and Steven D. Gribble and Arvind Krishnamurthy},
    title = {Studying Spamming Botnets Using Botlab},
    year = {}
}

Bookmark

citeulike Connotea Bibsonomy Del.icio.us Digg Reddit

OpenURL

 

Abstract

In this paper we present Botlab, a platform that continually monitors and analyzes the behavior of spamoriented botnets. Botlab gathers multiple real-time streams of information about botnets taken from distinct perspectives. By combining and analyzing these streams, Botlab can produce accurate, timely, and comprehensive data about spam botnet behavior. Our prototype system integrates information about spam arriving at the University of Washington, outgoing spam generated by captive botnet nodes, and information gleaned from DNS about URLs found within these spam messages. We describe the design and implementation of Botlab, including the challenges we had to overcome, such as preventing captive nodes from causing harm or thwarting virtual machine detection. Next, we present the results of a detailed measurement study of the behavior of the most active spam botnets. We find that six botnets are responsible for 79 % of spam messages arriving at the UW campus. Finally, we present defensive tools that take advantage of the Botlab platform to improve spam filtering and protect users from harmful web sites advertised within botnet-generated spam.

Citations

523 Tor: The secondgeneration onion router - Dingledine, Mathewson, et al.
374 Lottery Scheduling: Flexible Proportional-Share Resource Management - Waldspurger, Weihl
159 Understanding the network-level behavior of spammers - Ramachandran, Feamster - 2006
103 A multifaceted approach to understanding the botnet phenomenon - Rajab, Zarfoss, et al. - 2006
66 Bothunter: Detecting malware infection through IDS-driven dialog correlation - Gu, Porras, et al. - 2006
64 Spamalytics: an Empirical Analysis of Spam Marketing Conversion - Kanich, Kreibich, et al. - 2008
55 Spamscatter: Characterizing internet scam hosting infrastructure - Anderson, Fleizach, et al. - 2007
55 Peer-to-peer botnets: Overview and case study - Grizzard, Sharma, et al. - 2007
47 Wide-scale botnet detection and characterization - Karasaridis, Rexroad, et al. - 2007
41 Automated Classification and Analysis of Internet Malware - Bailey, Oberheide, et al. - 2007
40 Rishi: Identify bot contaminated host by IRC nickname evaluation - Goebel, Holz - 2007
38 containment in the Potemkin virtual honeyfarm - Scalability - 2005
38 Toward Automated Dynamic Malware Analysis Using CWSandbox - Holz, Freiling, et al.
28 Measuring and detecting fast-flux service networks. InProceedings oftheNetworkandDistributedSystemSecuritySymposium - Holz, Gorecki, et al. - 2008
26 An Advanced Hybrid Peer-to-Peer Botnet - Wang, Sparks, et al.
24 A case study of the Rustock rootkit and spam bot - Chiang, Lloyd - 2007
20 Characterizing Botnets from Email Spam Records - Zhuang, Dunagan, et al. - 2008
19 The Heisenbot Uncertainty Problem: Challenges in Separating Bots from Chaff - Kanich, Levchenko, et al. - 2008
19 On the spam campaign trail - Kreibich, Kanich, et al. - 2008
15 Leveraging bittorrent for end host measurements - Idal, Piatek, et al. - 2007
13 Analysis of the storm and nugache trojans - P2P is here - Stover, Dittrich, et al. - 2007
11 Know Your Enemy - Project - 2002
6 Peeking into Spammer Behavior from a Unique Vantage Point - Pathak, Hu - 2008
4 Command and control structures in malware: From Handler/Agent to P2P - Dittrich, Dietrich - 2007
4 Internet Security Trends. http://www. ironport.com/securitytrends - Ironport - 2008
2 Release: Srizbi now leads the spam pack. http://www.marshal.com/trace/traceitem.asp? article=567 - Press
2 April Storms Day Campaign. http: //asert.arbornetworks.com/2008/03/ april-storms-day-campaign - Nazario - 2008
2 and Xuxian Jiang and Roussi Roussev and Chad Verbowski and Shuo - Wang, Beck - 2006
2 Fang Yu and Kannan Achan and Rina Panigrahy and Geoff Hulten and Ivan Osipkov. Spamming Botnets: Signatures and Characteristics - Xie - 2008
2 Characterizing the irc-based botnet phenonmenon - Zhuge, Holz, et al. - 2007
1 Provos and Panayiotis Mavrommatis and Moheeb Rajab and Fabian Monrose. All Your iFrames Point to Us - Niels - 2008
The National Science Foundation
  • About CiteSeerX
  • Submit Documents
  • Privacy Policy
  • Help
  • Data
  • Source
  • Contact Us

Developed at and hosted by The College of Information Sciences and Technology

© 2007-2010 The Pennsylvania State University