Dynamics of online scam hosting infrastructure

TitleDynamics of online scam hosting infrastructure
Publication TypeJournal Articles
Year of Publication2009
AuthorsKonte M, Feamster N, Jung J
JournalPassive and Active Network Measurement
Pagination219 - 228
Date Published2009///

This paper studies the dynamics of scam hosting infrastructure, with an emphasis on the role of fast-flux service networks. By monitoring changes in DNS records of over 350 distinct spam-advertised domains collected from URLs in 115,000 spam emails received at a large spam sinkhole, we measure the rates and locations of remapping DNS records, and the rates at which “fresh” IP addresses are used. We find that, unlike the short-lived nature of the scams themselves, the infrastructure that hosts these scams has relatively persistent features that may ultimately assist detection.