Sciweavers

INFOCOM
2009
IEEE

Detecting Spam Zombies by Monitoring Outgoing Messages

13 years 11 months ago
Detecting Spam Zombies by Monitoring Outgoing Messages
—Compromised machines are one of the key security threats on the Internet; they are often used to launch various security attacks such as DDoS, spamming, and identity theft. In this paper we address this issue by investigating effective solutions to automatically identify compromised machines in a network. Given that spamming provides a key economic incentive for attackers to recruit the large number of compromised machines, we focus on the subset of compromised machines that are involved in the spamming activities, commonly known as spam zombies. We develop an effective spam zombie detection system named SPOT by monitoring outgoing messages of a network. SPOT is designed based on a powerful statistical tool called Sequential Probability Ratio Test, which has bounded false positive and false negative error rates. Our evaluation studies based on a twomonth email trace collected in a large U.S. campus network show that SPOT is an effective and efficient system in automatically detecti...
Zhenhai Duan, Peng Chen, Fernando Sanchez, Yingfei
Added 24 May 2010
Updated 24 May 2010
Type Conference
Year 2009
Where INFOCOM
Authors Zhenhai Duan, Peng Chen, Fernando Sanchez, Yingfei Dong, M. Stephenson, J. Barker
Comments (0)