Skip to main content
QUICK REVIEW

[Paper Review] Analyzing the Social Structure and Dynamics of E-mail and Spam in Massive Backbone Internet Traffic

Farnaz Moradi, Tomas Olovsson|arXiv (Cornell University)|Aug 19, 2010
Complex Network Analysis Techniques16 references3 citations
TL;DR

This study analyzes massive SMTP traffic from a 10 Gbps backbone link to construct e-mail social networks and compare the structural and temporal dynamics of legitimate (ham) and spam e-mail traffic. Contrary to prior assumptions, the authors find that e-mail networks are not scale-free due to the disruptive influence of spam, which exhibits non-social, non-power-law degree distributions—offering new network-level signatures for early spam detection.

ABSTRACT

E-mail is probably the most popular application on the Internet, with everyday business and personal communications dependent on it. Spam or unsolicited e-mail has been estimated to cost businesses significant amounts of money. However, our understanding of the network-level behavior of legitimate e-mail traffic and how it differs from spam traffic is limited. In this study, we have passively captured SMTP packets from a 10 Gbit/s Internet backbone link to construct a social network of e-mail users based on their exchanged e-mails. The focus of this paper is on the graph metrics indicating various structural properties of e-mail networks and how they evolve over time. This study also looks into the differences in the structural and temporal characteristics of spam and non-spam networks. Our analysis on the collected data allows us to show several differences between the behavior of spam and legitimate e-mail traffic, which can help us to understand the behavior of spammers and give us the knowledge to statistically model spam traffic on the network-level in order to complement current spam detection techniques.

Motivation & Objective

  • . To analyze the structural and temporal properties of large-scale e-mail networks derived from real backbone traffic.
  • . To investigate whether e-mail networks exhibit scale-free characteristics, as previously assumed in smaller studies.
  • . To identify distinguishing network-level features between legitimate (ham) and spam e-mail traffic.
  • . To evaluate the impact of time window selection on network topology and spam detection potential.
  • . To provide network-level indicators for improving spam detection by complementing existing filtering techniques.

Proposed method

  • . Passively captured SMTP packets from a 10 Gbps Internet backbone link at Chalmers University.
  • . Constructed undirected and directed e-mail networks using e-mail addresses as nodes and transmissions as edges.
  • . Classified e-mails into ham and spam using SpamAssassin, a well-trained spam filtering tool.
  • . Generated three networks: (1) legitimate e-mail (ham), (2) delivered spam, and (3) combined delivered and rejected spam.
  • . Analyzed graph metrics including degree distribution, average path length, clustering coefficient, and strongly connected components (SCCs).
  • . Evaluated network evolution over time using different time windows (e.g., 12-hour, daily, weekly) to assess stability and detectability of spam patterns.

Experimental results

Research questions

  • RQ1. Is the e-mail network scale-free, as previously claimed in studies based on limited datasets?
  • RQ2. How do the structural properties (e.g., degree distribution, clustering, path length) of ham and spam networks differ?
  • RQ3. What is the impact of time window selection on the detectability of spam behavior in network topology?
  • RQ4. How do the size and distribution of strongly connected components (SCCs) differ between ham and spam networks?
  • RQ5. Can network-level features of spam traffic be used to detect spammers closer to the source, improving current spam filtering?

Key findings

  • . E-mail networks are not scale-free; the degree distribution of the full e-mail network deviates from a power-law due to the overwhelming presence of spam.
  • . Legitimate (ham) e-mail traffic exhibits scale-free behavior with a power-law degree distribution, confirming social network characteristics.
  • . Spam traffic does not follow a power-law degree distribution, especially in out-degree, due to automated, non-social mass-sending behavior.
  • . The giant strongly connected component (GSCC) exists in both ham and spam networks, but the SCC size distribution differs: power-law in ham, non-power-law in spam and rejected traffic.
  • . A 12-hour time window during working hours is sufficient to detect non-power-law behavior in spam, enabling faster and more efficient network-level spam detection.
  • . The temporal evolution shows ham networks become more connected over time, while spam networks show minimal change in GSCC size, indicating stable, non-evolving spam propagation patterns.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.