Identifying IP blocks with spamming bots by spatial distribution

Sangki Yun, Byungseung Kim, Saewoong Bahk, Hyogon Kim

Research output: Contribution to journalArticlepeer-review

1 Citation (Scopus)


In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.

Original languageEnglish
Pages (from-to)2188-2190
Number of pages3
JournalIEICE Transactions on Communications
Issue number8
Publication statusPublished - 2010 Aug


  • Botnet
  • Detection
  • False positive
  • Identification
  • Spamming

ASJC Scopus subject areas

  • Software
  • Computer Networks and Communications
  • Electrical and Electronic Engineering


Dive into the research topics of 'Identifying IP blocks with spamming bots by spatial distribution'. Together they form a unique fingerprint.

Cite this