DocumentCode :
1717237
Title :
Detecting spamming activities by network monitoring with Bloom filters
Author :
Po-Ching Lin ; Ping-Hai Lin ; Pin-Ren Chiou ; Chien-Tsung Liu
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Chung Cheng Univ., Chaiyi, Taiwan
fYear :
2013
Firstpage :
163
Lastpage :
168
Abstract :
Spam delivery is common in the Internet. Most modern spam-filtering solutions are deployed on the receiver side. They are good at filtering spam for end users, but spam messages still keep wasting Internet bandwidth and the storage space of mail servers. This work is therefore intended to detect and nip spamming bots in the bud. We use the Bro intrusion detection system to monitor the SMTP sessions in a university campus, and track the number and the uniqueness of the recipients´ email addresses in the outgoing mail messages from each individual internal host as the features for detecting spamming bots. Due to the huge number of email addresses observed in the SMTP sessions, we store and manage them efficiently in the Bloom filters. According to the SMTP logs over a period of six months from November 2011 to April 2012, we found totally 65 dedicated spamming bots in the campus and observed 1.5 million outgoing spam messages from them.We also found account cracking events on 14 legitimate mail servers, on which some user accounts are cracked and abused for spamming. The method can effectively detect and curb the spamming bots with the precision and the recall up to 0.97 and 0.96.
Keywords :
Internet; computer network security; data structures; e-mail filters; educational institutions; unsolicited e-mail; Bloom filters; Bro intrusion detection system; Internet bandwidth; SMTP logs; SMTP session monitoring; account cracking events; bot spamming activity detection; internal host; legitimate mail servers; mail server storage space; network monitoring; outgoing mail messages; precision value; recall value; recipient e-mail addresses; spam delivery; spam message filtering; spamming bot detection; university campus; Electronic publishing; Encyclopedias; Industries; Internet; Monitoring; Postal services; Bloom filters; botnet; detection; network monitoring; spamming activities;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Communication Technology (ICACT), 2013 15th International Conference on
Conference_Location :
PyeongChang
ISSN :
1738-9445
Print_ISBN :
978-1-4673-3148-7
Type :
conf
Filename :
6488163
Link To Document :
بازگشت