[論文レビュー] An In-depth Analysis of Spam and Spammers
本論文は、企業のメールサーバーから14か月にわたり収集した40万封のスパムメールを用いて、スパムの特徴とスパマーの行動に関する詳細な分析を提示している。スパマーは自動化されたツールを用いて添付ファイル付きの大量メールを送信し、オープンリレーマシンを優先的に利用し、身元を隠す。また、重いユーザー(4年間使用)は軽いユーザーよりも顕著に多くのスパムを受け取るが、14か月間のアカウントはDOS攻撃の際を除き、ほとんどスパムを受け取らない。
Electronic mail services have become an important source of communication for millions of people all over the world. Due to this tremendous growth, there has been a significant increase in spam traffic. Spam messes up user's inbox, consumes network resources and spread worms and viruses. In this paper we study the characteristics of spam and the technology used by spammers. In order to counter anti spam technology, spammers change their mode of operation, therefore continues evaluation of the characteristics of spam and spammers technology has become mandatory. These evaluations help us to enhance the existing anti spam technology and thereby help us to combat spam effectively. In order to characterize spam, we collected four hundred thousand spam mails from a corporate mail server for a period of 14 months from January 2006 to February 2007. For analysis we classified spam based on attachment and contents. We observed that spammers use software tools to send spam with attachment. The main features of this software are hiding sender's identity, randomly selecting text messages, identifying open relay machines, mass mailing capability and defining spamming duration. Spammers do not use spam software to send spam without attachment. From our study we observed that, four years old heavy users email accounts attract more spam than four years old light users mail accounts. Relatively new email accounts which are 14 months old do not receive spam. But in some special cases like DDoS attacks, we found that new email accounts receive spam and 14 months old heavy users email accounts have attracted more spam than 14 months old light users. We believe that this analysis could be useful to develop more efficient anti spam techniques.
研究の動機と目的
- スパマーの進化する戦術と、スパム防止措置を回避するために使用する技術を理解すること。
- ユーザーのアカウント年数と使用強度に基づいたスパム配布のパターンを特定すること。
- コンテンツおよび添付ファイルの種別に基づいてスパムを特徴づけることにより、検出の改善を図ること。
- 実証的分析を通じて、より効果的なスパム防止技術の開発を支援すること。
提案手法
- 2006年1月から2007年2月までの14か月間にわたり、企業のメールサーバーから40万通のスパムメールを収集した。
- コンテンツおよび添付ファイルの有無に基づいてスパムを分類し、パターンを特定した。
- 送信者身元の隠蔽、ランダムなメッセージ生成、大量送信機能といったスパムソフトウェアの特徴を分析した。
- ユーザーのアカウントタイプ(軽いユーザー vs. 重いユーザー)およびアカウント年齢(14か月 vs. 4年)ごとにスパム頻度を評価した。
- DDoS攻撃中に新規アカウントを標的にするスパムなどの異常を同定した。
- 統計的比較を用いて、ユーザーのカテゴリごとのスパム露出の差を評価した。
実験結果
リサーチクエスチョン
- RQ1スパマーが使用するスパムソフトウェアの主な技術的特徴は何か?
- RQ2ユーザーのアカウント年齢および使用強度は、スパム露出にどのように影響するか?
- RQ3低活動であるにもかかわらず、新規に作成されたメールアカウントがスパムを受信する理由は何か?
- RQ4オープンリレーマシンはスパム配信インfraに果たす役割は何か?
- RQ5添付ファイル付きとテキストのみのメッセージでは、スパムのパターンにどのような違いがあるか?
主な発見
- スパマーは、送信者身元の隠蔽とランダムなメッセージ生成を特徴とする自動化されたソフトウェアツールを用いて、添付ファイル付きの大量メールを送信している。
- スパムソフトウェアは主に添付ファイル付きメールの送信に使用されており、添付ファイルなしのスパム送信には使用されていない。
- 4年間使用している重いユーザーは、4年間使用している軽いユーザーよりも顕著に多くのスパムを受け取っている。
- 14か月のメールアカウントは、まれな事例(DDoS攻撃時など)を除き、ほとんどスパムを受信していない。
- DDoS攻撃中には、14か月のアカウントですらスパム標的となることがあり、一時的な露出パターンがあることが示された。
- 本研究では、アカウント年齢と使用行動がスパム露出の強力な予測要因であることが確認され、長期間にわたり活発に使用されるアカウントが主な標的となっている。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。