A system for detecting a remotely controlled e-mail spam host. The system
includes an E-mail spammer detection unit and a host traffic profiling
unit. The E-mail spammer detection unit identifies E-mail Spammers based
on SMTP traffic characteristics. The host profiling unit extracts traffic
components from the plurality of Internet traffic associated with an
E-mail Spammer; interprets the extracted traffic components and
determines whether the E-mail Spammer is a compromised host. The system
may also include a botnet controller detection unit that analyzes traffic
associated with compromised E-mail Spammers and identifies the botnet
Controller remotely controlling the compromised E-mail Spammer.