首页> 外文会议>IEEE Conference on Computer Communications Workshops (INFOCOM 2010) >Correlating Spam Activity with IP Address Characteristics
【24h】

Correlating Spam Activity with IP Address Characteristics

机译:将垃圾邮件活动与IP地址特征相关联

获取原文
获取原文并翻译 | 示例

摘要

It is well known that spam bots mostly utilize compromised machines with certain address characteristics, such as dynamically allocated addresses, machines in specific geographic areas and IP ranges from AS' with more tolerant spam policies. Such machines tend to be less diligently administered and may exhibit less stability, more volatility, and shorter uptimes. However, few studies have attempted to quantify how such spam bot address characteristics compare with non-spamming hosts. Quantifying these characteristics may help provide important information for comprehensive spam mitigation. We use two large datasets, namely a commercial blacklist and an Internet-wide address visibility study to quanitify address characteristics of spam and non-spam networks. We find that spam networks exhibit significantly less availability and uptime, and higher volatility than non-spam networks. In addition, we conduct a collateral damage study of a common practice where an ISP blocks the entire /24 subnet if spammers are detected in that range. We find that such a policy blacklists a significant portion of legitimate mail servers belonging to the same subnet.
机译:众所周知,垃圾邮件漫游器大多利用具有特定地址特征的受感染机器,例如动态分配的地址,特定地理区域中的机器以及来自AS'的IP范围,并具有更宽容的垃圾邮件策略。这样的机器往往不那么勤奋地管理,并且可能表现出较小的稳定性,较大的波动性和较短的正常运行时间。但是,很少有研究试图量化此类垃圾邮件漫游器地址特征与非垃圾邮件主机相比的特征。量化这些特征可能有助于为全面缓解垃圾邮件提供重要信息。我们使用两个大型数据集,即商业黑名单和Internet范围内的地址可见性研究来量化垃圾邮件和非垃圾邮件网络的地址特征。我们发现,与非垃圾邮件网络相比,垃圾邮件网络的可用性和正常运行时间明显更少,并且波动性更高。此外,我们还进行了附带破坏研究,该研究是一种常见做法,如果在该范围内检测到垃圾邮件发送者,则ISP会阻止整个/ 24子网。我们发现,这样的策略将属于同一子网的合法邮件服务器的很大一部分列入了黑名单。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号