Skip to main content
QUICK REVIEW

[论文解读] An In-depth Analysis of Spam and Spammers

Dhinaharan Nagamalai, Beatrice Cynthia Dhinakaran|arXiv (Cornell University)|Dec 8, 2010
Spam and Phishing Detection参考文献 4被引用 11
一句话总结

本文基于14个月内在企业邮件服务器上收集的40万封垃圾邮件,对垃圾邮件特征及垃圾邮件发送者行为进行了深入分析。研究发现,垃圾邮件发送者使用自动化工具发送带附件的群发邮件,优先利用开放中继机器,并隐藏身份;与轻度用户相比,使用频率较高的用户(4年期)显著接收更多垃圾邮件,而14个月期的账户在大多数情况下基本无垃圾邮件,仅在分布式拒绝服务(DDoS)攻击期间例外。

ABSTRACT

Electronic mail services have become an important source of communication for millions of people all over the world. Due to this tremendous growth, there has been a significant increase in spam traffic. Spam messes up user's inbox, consumes network resources and spread worms and viruses. In this paper we study the characteristics of spam and the technology used by spammers. In order to counter anti spam technology, spammers change their mode of operation, therefore continues evaluation of the characteristics of spam and spammers technology has become mandatory. These evaluations help us to enhance the existing anti spam technology and thereby help us to combat spam effectively. In order to characterize spam, we collected four hundred thousand spam mails from a corporate mail server for a period of 14 months from January 2006 to February 2007. For analysis we classified spam based on attachment and contents. We observed that spammers use software tools to send spam with attachment. The main features of this software are hiding sender's identity, randomly selecting text messages, identifying open relay machines, mass mailing capability and defining spamming duration. Spammers do not use spam software to send spam without attachment. From our study we observed that, four years old heavy users email accounts attract more spam than four years old light users mail accounts. Relatively new email accounts which are 14 months old do not receive spam. But in some special cases like DDoS attacks, we found that new email accounts receive spam and 14 months old heavy users email accounts have attracted more spam than 14 months old light users. We believe that this analysis could be useful to develop more efficient anti spam techniques.

研究动机与目标

  • 理解垃圾邮件发送者不断演变的战术及其用于规避反垃圾邮件措施的技术。
  • 基于用户账户年龄和使用强度,识别垃圾邮件分发的模式。
  • 根据内容和附件类型对垃圾邮件进行特征分析,以提升检测能力。
  • 通过实证分析,为开发更有效的反垃圾邮件技术提供依据。

提出的方法

  • 在14个月期间(2006年1月至2007年2月),从企业邮件服务器收集40万封垃圾邮件。
  • 根据内容和附件存在情况对垃圾邮件进行分类,以识别模式。
  • 分析垃圾邮件软件的功能特征,如发件人身份混淆、随机消息生成及群发能力。
  • 评估不同用户账户类型(轻度用户与重度用户)以及账户年龄(14个月与4年)下的垃圾邮件频率。
  • 识别异常情况,如DDoS攻击期间针对新账户的垃圾邮件攻击。
  • 使用统计比较方法评估不同用户类别间垃圾邮件暴露差异。

实验结果

研究问题

  • RQ1垃圾邮件发送者所使用的垃圾邮件软件的主要技术特征是什么?
  • RQ2用户账户年龄和使用强度如何影响垃圾邮件暴露?
  • RQ3为何一些新创建的电子邮件账户即使活动量低,仍会收到垃圾邮件?
  • RQ4开放中继机器在垃圾邮件投递基础设施中扮演什么角色?
  • RQ5带附件的垃圾邮件与纯文本邮件的垃圾邮件模式有何不同?

主要发现

  • 垃圾邮件发送者使用自动化软件工具发送带附件的群发邮件,具备发件人身份混淆和随机消息生成功能。
  • 垃圾邮件软件主要用于发送带附件的邮件;极少用于发送无附件的垃圾邮件。
  • 使用4年且为重度邮件用户的用户,其接收到的垃圾邮件显著多于使用4年但为轻度用户的用户。
  • 14个月期的电子邮件账户在绝大多数情况下基本无垃圾邮件,仅在极少数情况下(如DDoS攻击)例外。
  • 在DDoS攻击期间,甚至14个月期的账户也可能成为垃圾邮件目标,表明存在临时暴露模式。
  • 本研究证实,账户年龄和使用行为是垃圾邮件暴露的强预测因子,长期高活跃账户为主要目标。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。