Journal of Networks, Vol 5, No 1 (2010), 98-105, Jan 2010
doi:10.4304/jnw.5.1.98-105

Measuring the botnet using the second character of bots

Zhitang Li, Jun Hu, ZhengBing Hu, Bingbing Wang, Liang Tang, Xin Yi

Abstract


Botnets have become one of the most serious threats to the Internet. They are now the key platform for many Internet attacks, such as spam, distributed denial-of-service(DDoS), and we call these attacks “the second character of bots”. In this paper, we focus on characterizing spamming botnets by leveraging both spam payload and spam nodes traffic properties. Measurement of botnets is an important and challenging work. However, most existing approaches work only on specific botnet command and control (c&c) protocols (e.g., IRC) and structures (e.g., centralized). In this paper, we present two measurement frameworks (MFNL and MFAL) that based on the second character of bots to measure the size of the botnet. We have easily implemented our prototype system and evaluated it using many real network traces, and we also compare these two approaches from several points.


Keywords


botnet;SMTP;spam;size;MFNL;MFAL

References



Full Text: PDF


Journal of Networks (JNW, ISSN 1796-2056)

Copyright @ 2006-2011 by ACADEMY PUBLISHER – All rights reserved.