Identifying IP blocks with spamming bots by spatial distribution

Sangki Yun, Byungseung Kim, Saewoong Bahk, Hyogon Kim

    Research output: Contribution to journalArticlepeer-review

    1 Citation (Scopus)

    Abstract

    In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.

    Original languageEnglish
    Pages (from-to)2188-2190
    Number of pages3
    JournalIEICE Transactions on Communications
    VolumeE93-B
    Issue number8
    DOIs
    Publication statusPublished - 2010 Aug

    Keywords

    • Botnet
    • Detection
    • False positive
    • Identification
    • Spamming

    ASJC Scopus subject areas

    • Software
    • Computer Networks and Communications
    • Electrical and Electronic Engineering

    Fingerprint

    Dive into the research topics of 'Identifying IP blocks with spamming bots by spatial distribution'. Together they form a unique fingerprint.

    Cite this