Bad neighborhoods on the internet

Giovane C M Moura, Ramin Sadre, Aiko Pras

Publikation: Bidrag til tidsskriftTidsskriftartikelForskningpeer review

10 Citationer (Scopus)

Abstract

Analogous to the real world, sources of malicious activities on the Internet tend to be concentrated in certain networks instead of being evenly distributed. In this article we formally define and frame such areas as Internet Bad Neighborhoods. By extending the reputation of malicious IP addresses to their neighbors, the bad neighborhood approach ultimately enables attack prediction from unforeseen addresses. We investigate spam and phishing bad neighborhoods, and show how their underlying business models, counter-intuitively, influences the location of the neighborhoods (both geographically and in the IP addressing space). We also show how bad neighborhoods are highly concentrated at a few Internet Service Providers and discuss how our findings can be employed to improve current network and spam filters and incentivize botnet mitigation initiatives.

OriginalsprogEngelsk
Artikelnummer6852094
TidsskriftIEEE Communications Magazine
Vol/bind52
Udgave nummer7
Sider (fra-til)132-139
Antal sider8
ISSN0163-6804
DOI
StatusUdgivet - jul. 2014

Fingeraftryk

Dyk ned i forskningsemnerne om 'Bad neighborhoods on the internet'. Sammen danner de et unikt fingeraftryk.

Citationsformater