首页> 外文会议>2010 10th IEEE/IPSJ International Symposium on Applications and the Internet >An Empirical Study of Spam : Analyzing Spam Sending Systems and Malicious Web Servers
【24h】

An Empirical Study of Spam : Analyzing Spam Sending Systems and Malicious Web Servers

机译:垃圾邮件的实证研究:分析垃圾邮件发送系统和恶意Web服务器

获取原文

摘要

Most recent spam emails are being sent by bots which often operate with others in the form of a botnet and in many cases, they contain URLs that navigate spam receivers to malicious Web servers for the purpose of carrying out various cyber attacks such as malware infection, phishing attacks, etc. In order to characterize the infrastructure of spam based attacks and identify botnets, previous research has been focused on clustering spam according to similarities based on email contents or URLs or their domain names. However, there is a fatal weakness in that the three criteria are easily influenced by changes in spam messages and trends. In this paper, we present a new spam clustering method based on IP addresses resolved from URLs within spam emails. By examining three weeks of spam gathered in our SMTP server, we observed that the accuracy of our clustering method is superior to that of domain name and URL based clustering methods, and we have obtained many useful results related to characteristics and clusters of spam that can be utilized for further analysis of spam based attacks.
机译:最新的垃圾邮件是由僵尸程序发送的,这些僵尸程序通常以僵尸网络的形式与他人合作,并且在许多情况下,它们包含的URL会将垃圾邮件接收者导航到恶意Web服务器,以进行各种网络攻击,例如恶意软件感染,为了表征基于垃圾邮件的攻击的基础结构并识别僵尸网络,以前的研究一直集中在根据基于电子邮件内容或URL或其域名的相似性来对垃圾邮件进行聚类。但是,存在致命的弱点,因为这三个标准很容易受到垃圾邮件消息和趋势变化的影响。在本文中,我们提出了一种新的垃圾邮件聚类方法,该方法基于从垃圾邮件中URL解析的IP地址。通过检查SMTP服务器中收集的三周垃圾邮件,我们发现我们的群集方法的准确性优于基于域名和URL的群集方法,并且我们获得了许多与垃圾邮件的特征和群集相关的有用结果用于进一步分析基于垃圾邮件的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号