[논문 리뷰] An In-depth Analysis of Spam and Spammers
이 논문은 기업 메일 서버에서 14개월 동안 수집한 40만封의 스팸 이메일을 바탕으로 스팸 특성과 스파머 행동에 대한 심층 분석을 제시한다. 분석 결과 스팸러들은 첨부 파일이 첨부된 다량의 이메일을 자동화된 도구를 통해 발송하며, 오픈 레이리 기반을 우선시하고 신원을 은폐하는 것으로 나타났다. 특히 4년 된 중도·고도의 이메일 사용자들은 경미한 사용자보다 훨씬 더 많은 스팸을 받는 반면, 14개월 된 계정은 DDoS 공격 기간을 제외하고는 대부분 스팸 없이 유지된다.
Electronic mail services have become an important source of communication for millions of people all over the world. Due to this tremendous growth, there has been a significant increase in spam traffic. Spam messes up user's inbox, consumes network resources and spread worms and viruses. In this paper we study the characteristics of spam and the technology used by spammers. In order to counter anti spam technology, spammers change their mode of operation, therefore continues evaluation of the characteristics of spam and spammers technology has become mandatory. These evaluations help us to enhance the existing anti spam technology and thereby help us to combat spam effectively. In order to characterize spam, we collected four hundred thousand spam mails from a corporate mail server for a period of 14 months from January 2006 to February 2007. For analysis we classified spam based on attachment and contents. We observed that spammers use software tools to send spam with attachment. The main features of this software are hiding sender's identity, randomly selecting text messages, identifying open relay machines, mass mailing capability and defining spamming duration. Spammers do not use spam software to send spam without attachment. From our study we observed that, four years old heavy users email accounts attract more spam than four years old light users mail accounts. Relatively new email accounts which are 14 months old do not receive spam. But in some special cases like DDoS attacks, we found that new email accounts receive spam and 14 months old heavy users email accounts have attracted more spam than 14 months old light users. We believe that this analysis could be useful to develop more efficient anti spam techniques.
연구 동기 및 목표
- 스파머의 진화하는 기술적 전략과 스팸 방지 조치를 회피하는 데 사용하는 기술을 이해하기 위해.
- 사용자 계정 연령과 사용 강도에 따른 스팸 배포 패턴을 특정하기 위해.
- 내용 및 첨부 파일 유형에 기반한 스팸 특성화를 통해 검출 성능 향상에 기여하기 위해.
- 실증적 분 析를 통해 보다 효과적인 스팸 방지 기술 개발에 기여하기 위해.
제안 방법
- 2006년 1월부터 2007년 2월까지 14개월 동안 기업 메일 서버에서 40만 건의 스팸 이메일을 수집하였다.
- 내용과 첨부 파일 유무에 따라 스팸을 분류하여 패턴을 파악하였다.
- 발신자 신원 은폐, 랜덤 메시지 생성, 다량 발송 기능 등 스팸 소프트웨어의 기능을 분석하였다.
- 경미한 사용자와 중도 사용자, 계정 연령(14개월 vs. 4년)에 따라 스팸 빈도를 평가하였다.
- DDoS 공격 기간 동안 신규 계정을 대상으로 한 스팸 공격와 같은 이질적 현상을 식별하였다.
- 통계적 비교를 통해 사용자 유형 간 스팸 노출 차이를 평가하였다.
실험 결과
연구 질문
- RQ1스파머가 사용하는 스팸 소프트웨어의 주요 기술적 특성은 무엇인가요?
- RQ2사용자 계정 연령과 사용 강도는 스팸 노출에 어떤 영향을 미치나요?
- RQ3낮은 활동 수준임에도 불구하고 일부 신규 생성 이메일 계정이 스팸을 받는 이유는 무엇인가요?
- RQ4오픈 레이리 기반은 스팸 배달 인프라에서 어떤 역할을 하나요?
- RQ5첨부 파일이 있는 메시지와 텍스트 전용 메시지 간 스팸 패턴은 어떻게 다릅니까?
주요 결과
- 스파머들은 첨부 파일이 첨부된 이메일을 자동화된 소프트웨어 도구를 통해 다량 발송하며, 발신자 신원 은폐 및 랜덤 메시지 생성 기능을 포함한다.
- 스팸 소프트웨어는 주로 첨부 파일이 있는 이메일 발송에 사용되며, 첨부 파일 없이 스팸을 발송하는 데에는 사용되지 않는다.
- 4년 된 중도 이메일 사용자는 4년 된 경미한 사용자보다 훨씬 더 많은 스팸을 받는다.
- 14개월 된 이메일 계정은 DDoS 공격 기간을 제외하고는 대부분 스팸 없이 유지된다.
- DDoS 공격 기간 동안 14개월 된 계정조차도 스팸 대상이 될 수 있으며, 이는 일시적인 노출 패턴을 시사한다.
- 본 연구는 계정 연령과 사용 행동이 스팸 노출에 강력한 예측 변수임을 확인하였으며, 장기간 활동성이 높은 계정이 주로 표적이 된다.
더 나은 연구,지금 바로 시작하세요
논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.
카드 등록 없음 · 무료 플랜 제공
이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.