Measuring the Botnet Using the Second Character of Bots.

Zhitang Li,Jun Hu,Zhengbing Hu,Bingbing Wang,Liang Tang,Xin Yi
DOI: https://doi.org/10.4304/jnw.5.1.98-105
2010-01-01
Journal of Networks
Abstract:Botnets have become one of the most serious threats to the Internet. They are now the key platform for many Internet attacks, such as spa m, distributed denial-of-service(DDoS), and we call these attacks “the second character of bots”. I n this paper, we focus on characterizing spamming botnets by leveraging both spam payload and spam nodes traffic properties. M easurement of botnets is an important and challenging work. H owever, most existing approaches work only o n specific botnet command and control (c&c) protocols (e.g., IRC) and structures (e.g., centralized). I n this paper, we present two measurement frameworks (MFNL and MFAL) that based on the second character of bots to measure the size of the botnet. W e have easily implemented our prototype system and evaluated it using many real network traces , and we also compare these two app r oaches from several points.
What problem does this paper attempt to address?