skip to main content
10.1007/978-3-642-00975-4_22guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

Dynamics of Online Scam Hosting Infrastructure

Published: 28 March 2009 Publication History

Abstract

This paper studies the dynamics of scam hosting infrastructure, with an emphasis on the role of fast-flux service networks. By monitoring changes in DNS records of over 350 distinct spam-advertised domains collected from URLs in 115,000 spam emails received at a large spam sinkhole, we measure the rates and locations of remapping DNS records, and the rates at which "fresh" IP addresses are used. We find that, unlike the short-lived nature of the scams themselves, the infrastructure that hosts these scams has relatively persistent features that may ultimately assist detection.

References

[1]
Alexa. Alexa the Web Information Company (2008), http://www.alexa.com/
[2]
Anderson, D.S., Fleizach, C., Savage, S., Voelker, G.M.: Spamscatter: Characterizing Internet Scam Hosting Infrastructure. In: USENIX Security Symposium (August 2007)
[3]
Dagon, D., Zou, C., Lee, W.: Modeling Botnet Propagation Using Time Zones. In: The 13th Annual Network and Distributed System Security Symposium (NDSS 2006), San Diego, CA (February 2006)
[4]
Holz, T., Corecki, C., Rieck, K., Freiling, F.C.: Measuring and Detecting Fast-Flux Service Networks. In: NDSS (February 2008)
[5]
ICANN Security and Stability Advisory Committee. SSAC Advisory on Fast Flux Hosting and DNS (March 2008), http://www.icann.org/committees/security/sac025.pdf
[6]
Jung, J., Sit, E.: An Empirical Study of Spam Traffic and the Use of DNS Black Lists. In: Internet Measurement Conference, Taormina, Italy (October 2004)
[7]
Konte, M., Feamster, N., Jung, J.: Fast Flux Service Networks: Dynamics and Roles in Online Scam Hosting Infrastructure. Technical Report GT-CS-08-07 (September 2008), http://www.cc.gatech.edu/~feamster/papers/fastflux-tr08.pdf
[8]
Passerini, E., Paleari, R., Martignoni, L., Bruschi, D.: FluXOR: detecting and monitoring fast-flux service networks. In: Zamboni, D. (ed.) DIMVA 2008. LNCS, vol. 5137, pp. 186- 206. Springer, Heidelberg (2008)
[9]
Pathak, A., Hu, Y.C., Mao, Z.M.: Peeking into Spammer Behavior from a Unique Vantage Point. In: First USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET), San Francisco, CA (April 2008)
[10]
Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: A Multifaceted Approach to Understanding the Botnet Phenomenon. In: ACM SIGCOMM/USENIX Internet Measurement Conference, Brazil (October 2006)
[11]
Ramachandran, A., Feamster, N.: Understanding the Network-Level Behavior of Spammers. In: SIGCOMM (September 2006)
[12]
Spam Trackers, http://spamtrackers.eu/wiki/index.php?title=Main_Page
[13]
The Honeynet Project. Know Your Enemy: Fast-Flux Service Networks (July 2007), http://www.honeynet.org/papers/ff/
[14]
Xie, Y., Yu, F., Achan, K., Gillum, E., Goldszmidt, M., Wobber, T.: How dynamic are IP addresses? In: ACM SIGCOMM, Kyoto, Japan (August 2007)
[15]
Zdrnja, B., Brownlee, N.,Wessels, D.: Passive monitoring of DNS anomalies. In: Hämmerli, B.M., Sommer, R. (eds.) DIMVA 2007. LNCS, vol. 4579, pp. 129-139. Springer, Heidelberg (2007)

Cited By

View all

Recommendations

Comments

Information & Contributors

Information

Published In

cover image Guide Proceedings
PAM '09: Proceedings of the 10th International Conference on Passive and Active Network Measurement
March 2009
229 pages
ISBN:9783642009747
  • Editors:
  • Sue B. Moon,
  • Renata Teixeira,
  • Steve Uhlig

Publisher

Springer-Verlag

Berlin, Heidelberg

Publication History

Published: 28 March 2009

Qualifiers

  • Article

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 06 Jan 2025

Other Metrics

Citations

Cited By

View all

View Options

View options

Media

Figures

Other

Tables

Share

Share

Share this Publication link

Share on social media