Evaluating the Impact of AbuseHUB on Botnet Mitigation

Report (2016)
Author(s)

M.J.G. van Eeten (TU Delft - Organisation & Governance)

Q.B. Lone (TU Delft - Organisation & Governance)

Giovane C. M. Moura (TU Delft - Organisation & Governance)

Hadi Asghari (TU Delft - Organisation & Governance)

M.T. Korczynski (TU Delft - Organisation & Governance)

Research Group
Organisation & Governance
Copyright
© 2016 M.J.G. van Eeten, Q.B. Lone, Giovane C. M. Moura, H. Asghari, M.T. Korczynski
More Info
expand_more
Publication Year
2016
Language
English
Copyright
© 2016 M.J.G. van Eeten, Q.B. Lone, Giovane C. M. Moura, H. Asghari, M.T. Korczynski
Research Group
Organisation & Governance
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

This documents presents the final report of a two-year project to evaluate the impact of AbuseHUB, a Dutch clearinghouse for acquiring and processing abuse data on infected machines. The report was commissioned by the Netherlands Ministry of Economic Affairs, a co-funder of the development of AbuseHUB. AbuseHUB is the initiative of 9 Internet Service Providers, SIDN (the registry for the .nl top-level domain) and Surfnet (the national research and education network operator). The key objective of AbuseHUB is to improve the mitigation of botnets by its members.
We set out to assess whether this objective is being reached by analyzing malware infection levels in the networks of AbuseHUB members and comparing them to those of other Internet Service Providers (ISPs). Since AbuseHUB members together comprise over 90 percent of the broadband market in the Netherlands, it also makes sense to compare how the country as a whole has performed compared to other countries. This report complements the baseline measurement report produced in December 2013 and the interim report from March 2015. We are using the same data sources as in the interim report, which is an expanded set compared to the earlier baseline report and to our 2011 study into botnet mitigation in the Netherlands.

Files

1612.03101.pdf
(pdf | 0.926 Mb)
License info not available