Spam related cyber crimes have become a serious threat to society. Current spam research mainly aims to detect spam more effectively. We believe the prosecution of spammers is a more effective way of stopping spam emails than filtering, therefore more research is needed to help forensic investigators to collect useful evidence. This research proposes an algorithm for clustering spam domains extracted from spam emails based on the hosting IP addresses and tracing the domains over a period of time. The results reveal several facts that merit law enforcement attention: many seemingly unrelated spam campaigns are actually related; spammers have a sophisticated mechanism for combating URL blacklisting by registering many new domain names every day and flushing out old domains; the domains are hosted at different IP addresses across several networks, mostly in China where legislation is not as tight as in US; old IP addresses are replaced by new ones from time to time, but still show strong correlation among them. These facts lead to the conclusion that spam-related cyber crimes are operated by well-organized criminal syndicates that have sufficient manpower to distribute a huge volume of spam through bots, purchase a large number of domain names and hosting servers and maintain websites to sell counterfeit products online. Traditional law enforcements technology has not scaled well in cases involving millions of data elements. This paper demonstrates an effective use of data mining to respond to this challenge.
Spam related cyber crimes, including phishing, malware and online fraud, are a serious threat to society. Spam filtering has been the major weapon against spam for many years but failed to reduce the number of spam emails. To hinder spammers’ capability of sending spam, their supporting infrastructure needs to be disrupted. Terminating spam hosts will greatly reduce spammers’ profit and thwart their ability to commit spam-related cyber crimes. This research proposes an algorithm for clustering spam domains based on the hosting IP addresses and related email subjects. The algorithm can also detect significant hosts over a period of time. Experimental results show that when domain names are investigated, many seemingly unrelated spam emails are actually related. By using wildcard DNS records and constantly replacing old domains with new domains, spammers can effectively defeat URL or domain based blacklisting. Spammers also refresh hosting IP addresses occasionally, but less frequently than domains. The identified domains and their hosting IP addresses can be used by cyber-crime investigators as leads to trace the identities of spammers and shut down the related spamming infrastructure. This paper demonstrates how data mining can help to detect spam domains and their hosts for anti-spam forensic purposes.Keywords: spam, forensics, clustering, data mining
In this paper, a fuzzy-matching clustering algorithm is introduced to group subjects found in spam emails which are generated by malware. A modified scoring strategy is applied in dynamic programming to find subjects that are similar to each other. A recursive seed selection strategy allows the algorithm to detect similar patterns even when the spammer creates a variation of the original pattern. A sliding threshold based on string length helps to minimize false-positives. The algorithm proves to be effective in detecting and grouping spam emails using templates. It also helps spam investigators to collect and sort large amount of malware-generated spam more efficiently without looking at the email content.
Storm Worm is a prolific web-spread Trojan virus that infects computers and turns them into nodes (called bots) of a botnet. The bots then can be used to distribute spam messages, launch DOS attacks, host phishing web sites, etc. This paper investigated Storm Worm bots that were used to propagate the virus during a four-month period of time. We found certain network blocks, because of their vulnerability, were more likely to contain Storm Worm bots.
In recent years, spam email has become a major tool for criminals to conduct illegal business on the Internet. Therefore, in this paper we describe a new research approach that uses data mining techniques to study spam emails with the focus on law enforcement forensic analysis. After we retrieve useful attributes from spam emails, we use a connected components clustering algorithm to form relationships between messages. These initial clusters are then refined by using a weighted edges model where membership in the cluster requires the weight to exceed a chosen threshold. The results of the cluster membership are validated by WHOIS data, by the IP address of the computer hosting the advertised sites, and through comparison of graphical images of website fetches. This technique has been successful in identifying relationships between spam campaigns that were not identified by human researchers, enabling additional data to be brought into a single investigation.
This paper studies the possibility of using hosting IP addresses to identify potential spam domains. Current domain blacklisting may not be effective if spammers keep replacing blacklisted domains with newly registered domains. In this study, we cluster spam domains based on their hosting IP addresses and associated email subjects. We found some hosting IP addresses were heavily used by spammers to host a large number of domains and persisted for much longer period of time than related domains. Our results show that hosting IP blacklisting should be effective against many point-of-sale spam campaigns, such as pharmaceutical, sexual enhancement and luxury good spam, which mainly use static IP addresses to host their websites. The IP addresses remain active from several days to even a couple of months before replaced by a set of new IPs. Therefore, even when new spam domains appear from time to time, they can be immediately detected as spam domains by looking up the hosting IP address. The reported IP addresses are also useful for law enforcement investigators to identify ISPs that provide bulletproof hosting services to spammers. The detection and termination of spam domains and their hosts will severely impede spammers’ capability to generate revenue from spam.
This paper surveys three months of spam data and investigates the hosting strategy of spam domains that are used to sell pharmaceutical, luxury goods and sexual enhancement tools. Thousands of domains have been found and most of them use wildcard DNS records to support non-existing machine names. The hosting IP addresses are much fewer than the number of domains, with a large number of domains hosted on a limited number of hosts. The majority of these heavily-used hosts reside in networks outside the USA. These hosts are stable and have good connectivity and availability. As a result, many domains on these hosts are alive for the entire three-month investigation period. The hosting IP addresses began to move in late March. The new IP addresses, however, are still in the same network range as the old IP addresses. The result suggests that further investigation on spam web hosting will be beneficial in disrupting the spamming network.
This paper surveys three months of spam data and investigates the hosting strategy of spam domains that are used to sell pharmaceutical, luxury goods and sexual enhancement tools. Thousands of domains have been found and most of them use wildcard DNS records to support non-existing machine names. The hosting IP addresses are much fewer than the number of domains, with a large number of domains hosted on a limited number of hosts. The majority of these heavily-used hosts reside in networks outside the USA. These hosts are stable and have good connectivity and availability. As a result, many domains on these hosts are alive for the entire three-month investigation period. The hosting IP addresses began to move in late March. The new IP addresses, however, are still in the same network range as the old IP addresses. The result suggests that further investigation on spam web hosting will be beneficial in disrupting the spamming network.
This paper studies the possibility of using hosting IP addresses to identify potential spam domains. Current domain blacklisting may not be effective if spammers keep replacing blacklisted domains with newly registered domains. In this study, we cluster spam domains based on their hosting IP addresses and associated email subjects. We found some hosting IP addresses were heavily used by spammers to host a large number of domains and persisted for much longer period of time than related domains. Our results show that hosting IP blacklisting should be effective against many point-of-sale spam campaigns, such as pharmaceutical, sexual enhancement and luxury good spam, which mainly use static IP addresses to host their websites. The IP addresses remain active from several days to even a couple of months before replaced by a set of new IPs. Therefore, even when new spam domains appear from time to time, they can be immediately detected as spam domains by looking up the hosting IP address. The reported IP addresses are also useful for law enforcement investigators to identify ISPs that provide bullet- proof hosting services to spammers. The detection and termination of spam domains and their hosts will severely impede spammers' capability to generate revenue from spam.