pith. sign in

arxiv: 1903.11400 · v1 · pith:GLP7BMHPnew · submitted 2019-03-27 · 💻 cs.CR

Botnet fingerprinting method based on anomaly detection in SMTP conversations

classification 💻 cs.CR
keywords detectionduringbotnetsemailfingerprintingnetworkpresentssmtp
0
0 comments X
read the original abstract

The paper presents the results obtained during research on detection of unsolicited e-mails which are sent by botnets. The distinction from most of the existing solutions is the fact that the presented approach is based on the analysis of network traffic - the sequence and syntax of SMTP commands observed during email delivery process. The paper presents several improvements for detection of unsolicited email sources from different botnets (fingerprinting), which can be used during network forensic investigation.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.