挖掘僵尸网络以及它们的演变模式
Mining Botnets and Their Evolution Patterns
-
摘要: 僵尸网络是一个受感染的计算机组成的网络,这些计算机在感染如木马病毒这样的恶意程序后被黑客掌控.这些受感染的机器被组织起来进行各种各样的攻击,其中包括垃圾邮件攻击,分布式拒绝服务攻击和附带木马攻击.目前僵尸网络已经成为网络基础建设最为严重的威胁之一.我们介绍了一种发现受感染的机器的方法,并通过大量的邮件日志描述它们行为的特性.我们报告了大量的不同特性的垃圾邮件活动,同时介绍了一种统计的方法将它们组合起来.我们也报告了垃圾邮件活动的长期演变模式.Abstract: The botnet is the network of compromised computers that have fallen under the control of hackers after being infected by malicious programs such as trojan viruses. The compromised machines are mobilized to perform various attacks including mass spamming, distributed denial of service (DDoS) and additional trojans. This is becoming one of the most serious threats to the Internet infrastructure at present. We introduce a method to uncover compromised machines and characterize their behaviors using large email logs. We report various spam campaign variants with different characteristics and introduce a statistical method to combine them. We also report the long-term evolution patterns of the spam campaigns.