Internet Bad Neighborhoods: The spam case

G. Moura, R. Sadre, A. Pras
{"title":"Internet Bad Neighborhoods: The spam case","authors":"G. Moura, R. Sadre, A. Pras","doi":"10.5555/2147671.2147681","DOIUrl":null,"url":null,"abstract":"A significant part of current attacks on the Internet comes from compromised hosts that, usually, take part in botnets. Even though bots themselves can be distributed all over the world, there is evidence that most of the malicious hosts are, in fact, concentrated in small fractions of the IP address space, on certain networks. Based on that, the Bad Neighborhood concept was introduced. The general idea of Bad Neighborhoods is to rate a subnetwork by the number of malicious hosts that have been observed in that subnetwork. Even though Bad Neighborhoods were successfully employed in mail filtering, the very concept was not investigated in further details. Therefore, in this work we provide a closer look on it, by proposing four definitions for spam-based Bad Neighborhoods that take into account the way spammers operate. We apply the definitions to real world data sets and show that they provide valuable insight into the behavior of spammers and the networks hosting them. Among our findings, we show that 10% of the Bad Neighborhoods are responsible for the majority of spam.","PeriodicalId":178441,"journal":{"name":"2011 7th International Conference on Network and Service Management","volume":"69 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"19","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 7th International Conference on Network and Service Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5555/2147671.2147681","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 19

Abstract

A significant part of current attacks on the Internet comes from compromised hosts that, usually, take part in botnets. Even though bots themselves can be distributed all over the world, there is evidence that most of the malicious hosts are, in fact, concentrated in small fractions of the IP address space, on certain networks. Based on that, the Bad Neighborhood concept was introduced. The general idea of Bad Neighborhoods is to rate a subnetwork by the number of malicious hosts that have been observed in that subnetwork. Even though Bad Neighborhoods were successfully employed in mail filtering, the very concept was not investigated in further details. Therefore, in this work we provide a closer look on it, by proposing four definitions for spam-based Bad Neighborhoods that take into account the way spammers operate. We apply the definitions to real world data sets and show that they provide valuable insight into the behavior of spammers and the networks hosting them. Among our findings, we show that 10% of the Bad Neighborhoods are responsible for the majority of spam.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
互联网不良社区:垃圾邮件案例
目前对互联网的攻击有很大一部分来自通常参与僵尸网络的受损主机。尽管机器人本身可以分布在世界各地,但有证据表明,大多数恶意主机实际上集中在某些网络上的一小部分IP地址空间中。在此基础上,提出了Bad Neighborhood的概念。坏邻居的一般思想是根据在该子网中观察到的恶意主机的数量对该子网进行评级。尽管Bad Neighborhoods成功地应用于邮件过滤,但这个概念并没有得到进一步的详细研究。因此,在这项工作中,我们通过提出基于垃圾邮件的坏社区的四个定义,考虑到垃圾邮件发送者的运作方式,对其进行了更深入的研究。我们将这些定义应用于真实世界的数据集,并展示了它们对垃圾邮件发送者和承载它们的网络的行为提供了有价值的见解。在我们的研究结果中,我们发现10%的坏邻居是大多数垃圾邮件的罪魁祸首。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Criticality avoidance: A new paradigm for congestion control based on science of phase transition Internet Bad Neighborhoods: The spam case Increasing data center network visibility with cisco NetFlow-Lite Enforcing security with behavioral fingerprinting A service management architecture component model
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1