Characterizing botnets from email spam records

  • Authors:
  • Li Zhuang;John Dunagan;Daniel R. Simon;Helen J. Wang;J. D. Tygar

  • Affiliations:
  • UC Berkeley;Ivan Osipkov Geoff Hulten, Microsoft Research;Ivan Osipkov Geoff Hulten, Microsoft Research;Ivan Osipkov Geoff Hulten, Microsoft Research;UC Berkeley

  • Venue:
  • LEET'08 Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We develop new techniques to map botnet membership using traces of spam email. To group bots into botnets we look for multiple bots participating in the same spam email campaign. We have applied our technique against a trace of spam email from Hotmail Web mail services. In this trace, we have successfully identified hundreds of botnets. We present new findings about botnet sizes and behavior while also confirming other researcher's observations derived by different methods [1, 15].