@inproceedings{122b1aa09db24a108506575c91a0d36d,
title = "Botnet spam campaigns can be long lasting: Evidence, implications, and analysis",
abstract = "Accurately identifying spam campaigns launched by a large number of bots in a botnet allows for accurate spam campaign signature generation and hence is critical to defeating spamming botnets. The straight-forward approach of clustering all spam containing the same label such as an URL into a campaign can be easily defeated by techniques such as simple obfuscations of URLs. In this paper, we perform a comprehensive study of content-agnostic characteristics of spam campaigns, e.g., duration and source-network distribution of spammers, in order to ascertain whether and how they can assist the simple label-based clustering methods in identifying campaigns and generating campaign signatures. In particular, from a five-month trace collected by a relay sinkhole, we manually identified and then analyzed seven URL-based botnet spam campaigns consisting of 52 million spam messages sent over 2.09 million SMTP connections originated from over 150,000 non-proxy spamming hosts and destined to about 200,000 end domains. Our analysis shows that the spam campaigns, when observed from large destination domains, exhibit durations far longer than the five-day period as reported in a recent study. We analyze the implications of this finding on spam campaign signature generation. We further study other characteristics of these long-lasting campaigns. Our analysis reveals several new findings regarding workload distribution, sending patterns, and coordination among the spamming machines.",
keywords = "Botnet, Burstiness, Distributedness, Open relay, Spam campaign",
author = "Abhinav Pathak and Feng Qian and Hu, {Y. Charlie} and Mao, {Z. Morley} and Supranamaya Ranjan",
year = "2009",
doi = "10.1145/1555349.1555352",
language = "English (US)",
isbn = "9781605585116",
series = "SIGMETRICS/Performance'09 - Proceedings of the 11th International Joint Conference on Measurement and Modeling of Computer Systems",
number = "1",
pages = "13--24",
booktitle = "SIGMETRICS/Performance'09 - Proceedings of the 11th International Joint Conference on Measurement and Modeling of Computer Systems",
edition = "1",
note = "11th International Joint Conference on Measurement and Modeling of Computer Systems, SIGMETRICS/Performance'09 ; Conference date: 15-06-2009 Through 19-06-2009",
}