• DocumentCode
    3071340
  • Title

    Correlation Analysis between Spamming Botnets and Malware Infected Hosts

  • Author

    Song, Jungsuk ; Shimamura, Jumpei ; Eto, Masashi ; Inoue, Daisuke ; Nakao, Koji

  • Author_Institution
    Inf. Security Res. Center, Nat. Inst. of Inf. & Commun. Technol., Tokyo, Japan
  • fYear
    2011
  • fDate
    18-21 July 2011
  • Firstpage
    372
  • Lastpage
    375
  • Abstract
    Many of recent cyber attacks are being launched by botnets for the purpose of carrying out large-scale cyber attacks such as spam emails, Distributed Denial of Service (DDoS), network scanning and so on. In many cases, these botnets consist of a lot of bots or zombie PCs which have been infected by a specific malware, and they try to propagate themselves into other victim systems through the Internet. In order to mitigate heavy damage of botnet based cyber attacks, it is needed to better understand the basic infrastructure of botnets as well as the underlying malwares of them. In this paper, we carried out correlation analysis between 10 spamming botnets identified by analyzing 3 weeks of spam emails in our previous work and malware infected hosts that observed at our darknets and honey pots. By comparing members (i.e., bots) of 10 spamming botnets with source hosts of dark net and honey pot traffic, we found that 7.2% ~ 37.5% of spamming botnets has been infected by four different malwares at least.
  • Keywords
    Internet; computer crime; computer network security; computer viruses; unsolicited e-mail; Internet; correlation analysis; cyber attacks; darknets; distributed denial of service; honeypots; malware infected hosts; network scanning; spam emails; spamming botnets; victim systems; zombie PCs; Correlation; Grippers; IP networks; Internet; Malware; Unsolicited electronic mail; botnet; correlation analysis; darknet; honeypot; malware; spam;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications and the Internet (SAINT), 2011 IEEE/IPSJ 11th International Symposium on
  • Conference_Location
    Munich, Bavaria
  • Print_ISBN
    978-1-4577-0531-1
  • Electronic_ISBN
    978-0-7695-4423-6
  • Type

    conf

  • DOI
    10.1109/SAINT.2011.71
  • Filename
    6004188