Identifying IP blocks with spamming bots by spatial distribution

Sangki Yun, Byungseung Kim, Saewoong Bahk, Hyogon Kim

Research output: Contribution to journalArticle

1 Citation (Scopus)

Abstract

In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.

Original languageEnglish
Pages (from-to)2188-2190
Number of pages3
JournalIEICE Transactions on Communications
VolumeE93-B
Issue number8
DOIs
Publication statusPublished - 2010 Aug 1

Fingerprint

Spamming
Spatial distribution
Inspection
Intellectual property core
Botnet

Keywords

  • Botnet
  • Detection
  • False positive
  • Identification
  • Spamming

ASJC Scopus subject areas

  • Electrical and Electronic Engineering
  • Computer Networks and Communications
  • Software

Cite this

Identifying IP blocks with spamming bots by spatial distribution. / Yun, Sangki; Kim, Byungseung; Bahk, Saewoong; Kim, Hyogon.

In: IEICE Transactions on Communications, Vol. E93-B, No. 8, 01.08.2010, p. 2188-2190.

Research output: Contribution to journalArticle

Yun, Sangki ; Kim, Byungseung ; Bahk, Saewoong ; Kim, Hyogon. / Identifying IP blocks with spamming bots by spatial distribution. In: IEICE Transactions on Communications. 2010 ; Vol. E93-B, No. 8. pp. 2188-2190.
@article{1b23486f8da2449ca3301ef0333a6f2e,
title = "Identifying IP blocks with spamming bots by spatial distribution",
abstract = "In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.",
keywords = "Botnet, Detection, False positive, Identification, Spamming",
author = "Sangki Yun and Byungseung Kim and Saewoong Bahk and Hyogon Kim",
year = "2010",
month = "8",
day = "1",
doi = "10.1587/transcom.E93.B.2188",
language = "English",
volume = "E93-B",
pages = "2188--2190",
journal = "IEICE Transactions on Communications",
issn = "0916-8516",
publisher = "Maruzen Co., Ltd/Maruzen Kabushikikaisha",
number = "8",

}

TY - JOUR

T1 - Identifying IP blocks with spamming bots by spatial distribution

AU - Yun, Sangki

AU - Kim, Byungseung

AU - Bahk, Saewoong

AU - Kim, Hyogon

PY - 2010/8/1

Y1 - 2010/8/1

N2 - In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.

AB - In this letter, we develop a behavioral metric with which spamming botnets can be quickly identified with respect to their residing IP blocks. Our method aims at line-speed operation without deep inspection, so only TCP/IP header fields of the passing packets are examined. However, the proposed metric yields a high-quality receiver operating characteristics (ROC), with high detection rates and low false positive rates.

KW - Botnet

KW - Detection

KW - False positive

KW - Identification

KW - Spamming

UR - http://www.scopus.com/inward/record.url?scp=77955406539&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=77955406539&partnerID=8YFLogxK

U2 - 10.1587/transcom.E93.B.2188

DO - 10.1587/transcom.E93.B.2188

M3 - Article

AN - SCOPUS:77955406539

VL - E93-B

SP - 2188

EP - 2190

JO - IEICE Transactions on Communications

JF - IEICE Transactions on Communications

SN - 0916-8516

IS - 8

ER -