Combating Snowshoe Spam with Fire
Olivier van der Toorn <o.i.vandertoorn@utwente.nl> November 13, 2018
University of Twente, Design and Analysis of Communication Systems ICT OPEN 2018
Combating Snowshoe Spam with Fire Olivier van der Toorn - - PowerPoint PPT Presentation
Combating Snowshoe Spam with Fire Olivier van der Toorn <o.i.vandertoorn@utwente.nl> November 13, 2018 University of Twente, Design and Analysis of Communication Systems ICT OPEN 2018 Overview Introduction Methodology Results
Olivier van der Toorn <o.i.vandertoorn@utwente.nl> November 13, 2018
University of Twente, Design and Analysis of Communication Systems ICT OPEN 2018
Introduction Methodology Results Conclusions
1
2
2
2
3
3
3
How can we detect snowshoe spam through active DNS measurements?
4
5
6
6
7
7
7
8
8
9
9
Precision = True Positives True Positives + False Positives
10
(110 false positives out of 10851 ham domains)
11
12
12
12
13
13
10 20 30 40 50 40% 60% 80% 100%
11.2 16.6
Number of A records CDF blacklisted benign
14
10 20 30 40 50 40% 60% 80% 100%
11.2 16.6
Number of A records CDF blacklisted benign
20 40 60 80 100 90% 92% 94% 96% 98% 100%
77.0
Number of MX records CDF blacklisted benign
15
16
10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 1961 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 1961 1144 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 1961 1144 1095 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 1961 1144 1095 968 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
16
28984 1961 1144 1095 968 928 10 20 30 40 50 60 70 80 Detection in advance (days) 1 10 100 1000 10000 100000 Number of detected domains
17
18
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names
18
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names
18
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names Blacklisted Detected
19
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names Blacklisted Detected
19
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names Blacklisted Detected
20
2017-05-24 2017-06-23 2017-07-23 Observation dates daadzgam.com realdrippy.com coachspoke.com stillscratch.com homerope.com quittradition.com Domain names Blacklisted Detected
21
0.0 0.5 1.0 1.5 2.0 2.5 3.0 3.5 4.0 4.5 5.0 Additional score of the RBL 100 200 300 400 500 600 700 Emails marked as spam
21
0.0 0.5 1.0 1.5 2.0 2.5 3.0 3.5 4.0 4.5 5.0 Additional score of the RBL 100 200 300 400 500 600 700 Emails marked as spam
22 120 320 335
21
0.0 0.5 1.0 1.5 2.0 2.5 3.0 3.5 4.0 4.5 5.0 Additional score of the RBL 100 200 300 400 500 600 700 Emails marked as spam
22 120 320 335 352 441 497 554
21
0.0 0.5 1.0 1.5 2.0 2.5 3.0 3.5 4.0 4.5 5.0 Additional score of the RBL 100 200 300 400 500 600 700 Emails marked as spam
22 120 320 335 352 441 497 554 626 629
22
23
23
23
24