4 ms·
Hi guys, I worked with Julie in writing this article. I'd be happy to answer any questions you have about the work. I was indeed inspired by the Drake equation
by waitwhatwhoa 16y ago
Hi guys, I worked with Julie in writing this article. I'd be happy to answer any questions you have about the work. I was indeed inspired by the Drake equation in coming up with this interpretation of our results :)
If you'd like to learn more about this experiment, the Wired article is based off of: http://cseweb.ucsd.edu/~savage/papers/CACMSpam09.pdf http://cseweb.ucsd.edu/~savage/papers/CACMSpam09.pdf
- jamesshamenski 16y agoWas this a technically difficult operation to undertake? How long did it take to plan and execute? i'm assuming that it's not that tedious of a task to scale and automate. In going through this exercise were you able to come up with ideas to combat spam more effectively?
- waitwhatwhoa 16y agoI wouldn't say it was incredibly technically difficult, the worst parts were probably reverse engineering the somewhat funky custom encoding that the botmaster was using for the C&C communication, and then writing the custom router software to allow us to rewrite live tcp flows (we used click: http://read.cs.ucla.edu/click/click http://read.cs.ucla.edu/click/click). We first started experimenting with the storm botnet about six months before doing this experiment. Once we realized what their architecture allowed us to do (MITM on the botnet's C&C), it probably only took a month or two to put together the infrastructure needed to conduct the experiment. Scaling to more nodes would have been relatively trivial, as the VMs running the Storm nodes were completely unmodified and we could have easily brought more online behind our flow-modifying router if necessary. A colleague of mine did come up with one idea called "botnet judo" (paper here: http://www.cs.ucsd.edu/~voelker/pubs/judo-ndss10.pdf http://www.cs.ucsd.edu/~voelker/pubs/judo-ndss10.pdf) whereby we run spamming bots within a contained environment that "seems" to have SMTP connectivity but actually just sinkholes all the spam, and then we developed highly effective and specific regular expressions from each bot's spam corpus.
- jamesshamenski 16y agoWow, that's really great. Thanks for the insight! Was this project done as a thesis paper or was there an alternative purpose for undertaking such a long project? I'm pretty impressed with the execution of your team.
- waitwhatwhoa 16y agoI wouldn't consider it "a thesis paper," but this project will eventually be part of my PhD thesis. Overall I would just say that we just seized the opportunity and wrote a decent paper. I, too, am impressed with our team and certainly would be nowhere without it. Glad you've enjoyed our work!
- lsc 16y agohave you considered doing something to, uh, "educate" the "victims?" I mean, spam will exist for as long as it is profitable. Not that I have any idea how to educate those sorts.
- waitwhatwhoa 16y agoThat's an interesting question. Interacting with people in an unsolicited manner is very hard from a legal/ethical standpoint, so using a method like this to "reach out" wouldn't fly. On the other hand, user education about the profit motive is certainly something that could bear fruit, and so the first step to educating them is figuring out what the numbers look like in the first place :). That's what we're up to, and trying to find ways to keep spam from being profitable is something we took a look at in our upcoming paper at this May's IEEE Symposium on Security and Privacy.