Chih-Cherng Chin

Introduction I submitted a paper titled "Follow the spam: a botnet detection and notification mechanism" (in Chinese) to this year's TANET conference (TANET 2010), and it has been accepted. In that paper, I pointed out the problem with botnet mitigation measures which focus on taking C&C servers offline, described the detection strategy of "follow the spam," and made a general sketch of how I detect and report botnets. So far I have only implemented half of the "follow the spam" strategy. Hope someone else will implement the other half.

My previous work was an open relay detection and notification system (presented at TANET 2006 conference), which was able to uncover more than 1200 open relays (confirmed by ORDB) each month at the time.
