Identifying New Spam Domains by Hosting IPs: Improving Domain Blacklisting
نویسندگان
چکیده
This paper studies the possibility of using hosting IP addresses to identify potential spam domains. Current domain blacklisting may not be effective if spammers keep replacing blacklisted domains with newly registered domains. In this study, we cluster spam domains based on their hosting IP addresses and associated email subjects. We found some hosting IP addresses were heavily used by spammers to host a large number of domains and persisted for much longer period of time than related domains. Our results show that hosting IP blacklisting should be effective against many point-of-sale spam campaigns, such as pharmaceutical, sexual enhancement and luxury good spam, which mainly use static IP addresses to host their websites. The IP addresses remain active from several days to even a couple of months before replaced by a set of new IPs. Therefore, even when new spam domains appear from time to time, they can be immediately detected as spam domains by looking up the hosting IP address. The reported IP addresses are also useful for law enforcement investigators to identify ISPs that provide bulletproof hosting services to spammers. The detection and termination of spam domains and their hosts will severely impede spammers’ capability to generate revenue from spam.
منابع مشابه
Clustering Spam Domains and Destination Websites: Digital Forensics with Data Mining
Spam related cyber crimes have become a serious threat to society. Current spam research mainly aims to detect spam more effectively. We believe the identification and disruption of the supporting infrastructure used by spammers is a more effective way of stopping spam than filtering. The termination of spam hosts will greatly reduce the profit a spammer can generate and thwart his ability to s...
متن کاملEmpirically Characterizing Domain Abuse and the Revenue Impact of Blacklisting
Using ground truth sales data for over 40K unlicensed prescription pharmaceuticals sites, we present an economic analysis of two aspects of domain abuse in the online counterfeit drug market. First, we characterize the nature of domains abused by affiliate spammers to monetize what is evidently an overwhelming demand for these drugs. We found that the most successful affiliates are agile in ada...
متن کاملFast Flux Service Networks: Dynamics and Roles in Hosting Online Scams∗
This paper studies the dynamics of fast flux service networks and their role in online scam hosting infrastructures. By monitoring changes in DNS records of over 350 distinct fast flux domains collected from URLs in 115,000 spam emails at a large spam sinkhole, we measure the rate of change of DNS records, accumulation of new distinct IPs in the hosting infrastructure, and location of change bo...
متن کاملImproving Spam Blacklisting Through Dynamic Thresholding and Speculative Aggregation
Unsolicited bulk e-mail (UBE) or spam constitutes a significant fraction of all e-mail connection attempts and routinely frustrates users, consumes resources, and serves as an infection vector for malicious software. In an effort to scalably and effectively reduce the impact of these e-mails, e-mail system designers have increasingly turned to blacklisting. Blacklisting (blackholing, block list...
متن کاملOn the Effects of Registrar-level Intervention
Virtually all Internet scams make use of domain name resolution as a critical part of their execution (e.g., resolving a spam-advertised URL to its Web site). Consequently, defenders have initiated a range of efforts to intervene within the DNS ecosystem to block such activity (e.g., by blacklisting “known bad” domain names at the client). Recently, there has been a push for domain registrars t...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010