DocumentCode
3071340
Title
Correlation Analysis between Spamming Botnets and Malware Infected Hosts
Author
Song, Jungsuk ; Shimamura, Jumpei ; Eto, Masashi ; Inoue, Daisuke ; Nakao, Koji
Author_Institution
Inf. Security Res. Center, Nat. Inst. of Inf. & Commun. Technol., Tokyo, Japan
fYear
2011
fDate
18-21 July 2011
Firstpage
372
Lastpage
375
Abstract
Many of recent cyber attacks are being launched by botnets for the purpose of carrying out large-scale cyber attacks such as spam emails, Distributed Denial of Service (DDoS), network scanning and so on. In many cases, these botnets consist of a lot of bots or zombie PCs which have been infected by a specific malware, and they try to propagate themselves into other victim systems through the Internet. In order to mitigate heavy damage of botnet based cyber attacks, it is needed to better understand the basic infrastructure of botnets as well as the underlying malwares of them. In this paper, we carried out correlation analysis between 10 spamming botnets identified by analyzing 3 weeks of spam emails in our previous work and malware infected hosts that observed at our darknets and honey pots. By comparing members (i.e., bots) of 10 spamming botnets with source hosts of dark net and honey pot traffic, we found that 7.2% ~ 37.5% of spamming botnets has been infected by four different malwares at least.
Keywords
Internet; computer crime; computer network security; computer viruses; unsolicited e-mail; Internet; correlation analysis; cyber attacks; darknets; distributed denial of service; honeypots; malware infected hosts; network scanning; spam emails; spamming botnets; victim systems; zombie PCs; Correlation; Grippers; IP networks; Internet; Malware; Unsolicited electronic mail; botnet; correlation analysis; darknet; honeypot; malware; spam;
fLanguage
English
Publisher
ieee
Conference_Titel
Applications and the Internet (SAINT), 2011 IEEE/IPSJ 11th International Symposium on
Conference_Location
Munich, Bavaria
Print_ISBN
978-1-4577-0531-1
Electronic_ISBN
978-0-7695-4423-6
Type
conf
DOI
10.1109/SAINT.2011.71
Filename
6004188
Link To Document