• DocumentCode
    1909502
  • Title

    Detecting Spam Zombies by Monitoring Outgoing Messages

  • Author

    Duan, Zhenhai ; Chen, Peng ; Sanchez, Fernando ; Dong, Yingfei ; Stephenson, Mary ; Barker, James

  • Author_Institution
    Florida State Univ., Tallahassee, FL
  • fYear
    2009
  • fDate
    19-25 April 2009
  • Firstpage
    1764
  • Lastpage
    1772
  • Abstract
    Compromised machines are one of the key security threats on the Internet; they are often used to launch various security attacks such as DDoS, spamming, and identity theft. In this paper we address this issue by investigating effective solutions to automatically identify compromised machines in a network. Given that spamming provides a key economic incentive for attackers to recruit the large number of compromised machines, we focus on the subset of compromised machines that are involved in the spamming activities, commonly known as spam zombies. We develop an effective spam zombie detection system named SPOT by monitoring outgoing messages of a network. SPOT is designed based on a powerful statistical tool called Sequential Probability Ratio Test, which has bounded false positive and false negative error rates. Our evaluation studies based on a two- month email trace collected in a large U.S. campus network show that SPOT is an effective and efficient system in automatically detecting compromised machines in a network. For example, among the 440 internal IP addresses observed in the email trace, SPOT identifies 132 of them as being associated with compromised machines. Out of the 132 IP addresses identified by SPOT, 126 can be either independently confirmed (110) or highly likely (16) to be compromised. Moreover, only 7 internal IP addresses associated with compromised machines in the trace are missed by SPOT.
  • Keywords
    IP networks; Internet; electronic messaging; probability; security of data; statistical testing; unsolicited e-mail; DDoS; IP addresses; Internet; SPOT; U.S. campus network; compromised machines; identity theft; outgoing messages monitoring; security attacks; security threats; sequential probability ratio test; spam zombie detection system; spam zombies detection; spamming activity; statistical tool; Aggregates; Condition monitoring; Error analysis; Internet; Power generation economics; Probability; Recruitment; Sequential analysis; Statistical analysis; Unsolicited electronic mail;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2009, IEEE
  • Conference_Location
    Rio de Janeiro
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4244-3512-8
  • Electronic_ISBN
    0743-166X
  • Type

    conf

  • DOI
    10.1109/INFCOM.2009.5062096
  • Filename
    5062096