Network Forensics Analysis on Email Scam Botnet

JIN Jiandong,YANG Jia,ZHOU Changling,LI Xiaonan,MA Hao
DOI: https://doi.org/10.3724/sp.j.1249.2020.99078
2020-01-01
Abstract:Using botnet to send spam is a common attack method of cyber blackmailers and extortionist. In recent years, with the widespread application of blockchain, a new type of extortion scam spam using bitcoin to achieve anonymous transfer have gradually emerged, which poses a great threat to cyber security. This paper aims to a university email system for spam botnet detection. We design a network forensics framework, which can identify extortion scam email and spam-sending botnet. Furthermore, this framework can also analyze the bitcoin money laundering network used by attacker. Experiment on real-world datasets shows that compared to some classic spam filtering models, our method has a higher recall rate on extortion scam email, while provides further analysis on botnet cluster and money laundering network.
What problem does this paper attempt to address?