TY - GEN
T1 - Dynamics of online scam hosting infrastructure
AU - Konte, Maria
AU - Feamster, Nick
AU - Jung, Jaeyeon
PY - 2009
Y1 - 2009
N2 - This paper studies the dynamics of scam hosting infrastructure, with an emphasis on the role of fast-flux service networks. By monitoring changes in DNS records of over 350 distinct spam-advertised domains collected from URLs in 115,000 spam emails received at a large spam sinkhole, we measure the rates and locations of remapping DNS records, and the rates at which "fresh" IP addresses are used. We find that, unlike the short-lived nature of the scams themselves, the infrastructure that hosts these scams has relatively persistent features that may ultimately assist detection.
AB - This paper studies the dynamics of scam hosting infrastructure, with an emphasis on the role of fast-flux service networks. By monitoring changes in DNS records of over 350 distinct spam-advertised domains collected from URLs in 115,000 spam emails received at a large spam sinkhole, we measure the rates and locations of remapping DNS records, and the rates at which "fresh" IP addresses are used. We find that, unlike the short-lived nature of the scams themselves, the infrastructure that hosts these scams has relatively persistent features that may ultimately assist detection.
UR - http://www.scopus.com/inward/record.url?scp=67649946711&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=67649946711&partnerID=8YFLogxK
U2 - 10.1007/978-3-642-00975-4_22
DO - 10.1007/978-3-642-00975-4_22
M3 - Conference contribution
AN - SCOPUS:67649946711
SN - 9783642009747
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 219
EP - 228
BT - Passive and Active Network Measurement - 10th International Conference, PAM 2009, Proceedings
T2 - 10th International Conference on Passive and Active Network Measurement, PAM 2009
Y2 - 1 April 2009 through 3 April 2009
ER -