作者: Michael Collins , Timothy J. Shimeall , Sidney Faber , Jeff Janies , Rhiannon Weaver
DOI: 10.21236/ADA633445
关键词:
摘要: The increased use of botnets as an attack tool and the awareness attackers have blocking lists leads to question whether we can effectively predict future bot locations. To that end, introduce a network quality term uncleanliness: indicator propensity for hosts in be compromised by outside parties. We hypothesize unclean networks will demonstrate two properties: spatial temporal uncleanliness. Spatial uncleanliness is tendency cluster more densely within networks. Temporal contain extended periods. test these properties collating data from multiple indicators (spamming, phishing, scanning botnet IRC log monitoring). evidence both further show cross-relationship between various datasets, showing activity predicts spamming scanning, while phishing appears unrelated other indicators.