[Paper Review] Evaluating the Impact of AbuseHUB on Botnet Mitigation
This study evaluates AbuseHUB, a Dutch ISP-led abuse data-sharing platform, by analyzing botnet infection rates across member and non-member ISPs in the Netherlands and comparing them to global peers. Using normalized infection metrics from multiple data sources, the research finds that AbuseHUB members show significantly lower infection levels than non-members and top-tier global ISPs, demonstrating the platform's effectiveness in improving botnet mitigation through coordinated data sharing and automated cleanup.
This documents presents the final report of a two-year project to evaluate the impact of AbuseHUB, a Dutch clearinghouse for acquiring and processing abuse data on infected machines. The report was commissioned by the Netherlands Ministry of Economic Affairs, a co-funder of the development of AbuseHUB. AbuseHUB is the initiative of 9 Internet Service Providers, SIDN (the registry for the .nl top-level domain) and Surfnet (the national research and education network operator). The key objective of AbuseHUB is to improve the mitigation of botnets by its members. We set out to assess whether this objective is being reached by analyzing malware infection levels in the networks of AbuseHUB members and comparing them to those of other Internet Service Providers (ISPs). Since AbuseHUB members together comprise over 90 percent of the broadband market in the Netherlands, it also makes sense to compare how the country as a whole has performed compared to other countries. This report complements the baseline measurement report produced in December 2013 and the interim report from March 2015. We are using the same data sources as in the interim report, which is an expanded set compared to the earlier baseline report and to our 2011 study into botnet mitigation in the Netherlands.
Motivation & Objective
- To assess whether AbuseHUB reduces botnet infection rates among its member ISPs compared to non-members.
- To compare the Netherlands’ overall botnet performance against other countries to evaluate the national impact of AbuseHUB.
- To analyze the performance variation among AbuseHUB member ISPs to identify best practices.
- To evaluate the effectiveness of Anti-Botnet Initiatives (ABIs) in countries with such programs.
- To provide evidence-based recommendations for scaling abuse mitigation through data sharing and policy incentives.
Proposed method
- Collected and analyzed malware infection data from global and Netherlands-specific sources, including Shadowserver, Spamhaus, and sinkhole feeds.
- Mapped infected IP addresses to ISPs using geolocation and ASN resolution, then normalized infection counts by number of subscribers to enable fair comparison.
- Ranked ISPs and countries based on average daily unique infected IPs per million subscribers to account for network size differences.
- Compared AbuseHUB members against non-members and global ISPs using time-series analysis of infection trends from 2014–2015.
- Identified top 10 most infected non-member ISPs to assess the impact of non-membership on infection levels.
- Used scatter plots and normalized metrics to visualize performance differences across ISPs and botnet types.
Experimental results
Research questions
- RQ1Do AbuseHUB member ISPs exhibit significantly lower botnet infection rates than non-member ISPs in the Netherlands?
- RQ2How does the Netherlands compare to other countries in terms of botnet infection levels, particularly in relation to Anti-Botnet Initiatives (ABIs)?
- RQ3How do individual AbuseHUB member ISPs compare in performance, and which exhibit the most effective mitigation?
- RQ4What is the impact of data sharing and automated cleanup on reducing infection rates across the Dutch ISP market?
- RQ5To what extent do non-member ISPs contribute to overall infection levels, and can they be incentivized to join mitigation efforts?
Key findings
- AbuseHUB members had significantly lower infection rates than non-members, with average daily infected IPs per million subscribers 30–50% lower in 2015.
- The Netherlands ranked among the top 10 countries globally for low botnet infection levels, outperforming most peers, including countries with formal Anti-Botnet Initiatives.
- Top 10 most infected non-member ISPs in the Netherlands had infection rates up to 5 times higher than the average AbuseHUB member.
- Among AbuseHUB members, performance varied widely: some ISPs achieved infection levels below 10 infected IPs per million subscribers, while others remained above 50.
- The study found no evidence that ABIs in other countries led to better outcomes than the Dutch model, suggesting AbuseHUB’s impact is not solely due to national policy.
- Centralized cleanup tools and data sharing significantly reduce customer support costs and improve mitigation efficiency, as demonstrated by the German botfrei.de model.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.