Abstract
In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.
Original language | English |
---|---|
Pages (from-to) | 2188-2190 |
Number of pages | 3 |
Journal | IEICE Transactions on Communications |
Volume | E93-B |
Issue number | 8 |
DOIs | |
Publication status | Published - 2010 Aug |
Keywords
- Botnet
- Detection
- False positive
- Identification
- Spamming
ASJC Scopus subject areas
- Software
- Computer Networks and Communications
- Electrical and Electronic Engineering