DocumentCode
623978
Title
SpamTracer: How stealthy are spammers?
Author
Vervier, Pierre-Antoine ; Thonnard, Olivier
Author_Institution
Eurecom, Sophia Antipolis, France
fYear
2013
fDate
14-19 April 2013
Firstpage
3477
Lastpage
3482
Abstract
The Internet routing infrastructure is vulnerable to the injection of erroneous routing information resulting in BGP hijacking. Some spammers, also known as fly-by spammers, have been reported using this attack to steal blocks of IP addresses and use them for spamming. Using stolen IP addresses may allow spammers to elude spam filters based on sender IP address reputation and remain stealthy. This remains a open conjecture despite some anecdotal evidences published several years ago. In order to confirm the first observations and reproduce the experiments at large scale, a system called SpamTracer has been developed to monitor the routing behavior of spamming networks using BGP data and IP/AS traceroutes. We then propose a set of specifically tailored heuristics for detecting possible BGP hijacks. Through an extensive experimentation on a six months dataset, we did find a limited number of cases of spamming networks likely hijacked. In one case, the network owner confirmed the hijack. However, from the experiments performed so far, we can conclude that the fly-by spammers phenomenon does not seem to currently be a significant threat.
Keywords
Internet; protocols; security of data; telecommunication network routing; unsolicited e-mail; BGP data; BGP hijacking; IP/AS traceroutes; Internet routing infrastructure; SpamTracer; fly-by spammers; sender IP address reputation; spam filters; spamming networks routing behavior; stealthy spammer; stolen IP addresses; Conferences; Feeds; IP networks; Internet; Monitoring; Routing; Unsolicited electronic mail;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM, 2013 Proceedings IEEE
Conference_Location
Turin
ISSN
0743-166X
Print_ISBN
978-1-4673-5944-3
Type
conf
DOI
10.1109/INFCOM.2013.6567184
Filename
6567184
Link To Document