Abstract
In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.
| Original language | English |
|---|---|
| Pages (from-to) | 2188-2190 |
| Number of pages | 3 |
| Journal | IEICE Transactions on Communications |
| Volume | E93-B |
| Issue number | 8 |
| DOIs | |
| Publication status | Published - 2010 Aug |
Keywords
- Botnet
- Detection
- False positive
- Identification
- Spamming
ASJC Scopus subject areas
- Software
- Computer Networks and Communications
- Electrical and Electronic Engineering
Fingerprint
Dive into the research topics of 'Identifying IP blocks with spamming bots by spatial distribution'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS