NSF: network-based spam filtering based on on-line blacklisting against spamming botnets

  • Authors:
  • Byungseung Kim;Hyogon Kim;Saewoong Bahk

  • Affiliations:
  • Samsung Electronics Co., Ltd., Suwon, Gyeonggi-do, Korea;Korea University, Seoul, Korea;Seoul National University, Seoul, Korea

  • Venue:
  • GLOBECOM'09 Proceedings of the 28th IEEE conference on Global telecommunications
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Although many anti-spam techniques have been developed, they have difficulty in detecting spams whose contents are altered to evade detection and in tracking spammers that are comprised of botnets. There have been a few works to resolve these limitations, but most of them are not appropriate to be deployed at a gateway for online detection. In this paper, we find network-based characteristics that spammers cannot easily distort. Based on the characteristics, we develop an algorithm applying the metrics to a large volume of traffic in real time. The scheme is efficient enough to run at the ingress point as it only needs to inspect the transport information contained in TCP/IP headers of SMTP connections.