• DocumentCode
    2446767
  • Title

    Network-level characteristics of spamming: An empirical analysis

  • Author

    Kokkodis, Marios ; Faloutsos, Michalis ; Markopoulou, Athina

  • Author_Institution
    Dept. of CS&E, Univ. of California, Riverside, Riverside, CA, USA
  • fYear
    2011
  • fDate
    17-20 Oct. 2011
  • Firstpage
    25
  • Lastpage
    30
  • Abstract
    Has the behavior of spammers changed over the last few years? To answer this question, we conduct a study from three recent data sources. Specifically, we focus on the following broad questions: (a) how are email addresses harvested, (b) where is spam coming from, and (c) how does spam evolve over time. First, we discuss whether spammers still use email harvesting: 34% of the honeypot accounts we publicised received spam after 72 days on average. Interestingly, we find that simple email address obfuscation is quite effective against harvesting. Second, we identify significant skew in the spatial distribution of the origin of spam in both the IP-level and AS-level of granularity. We find that 20% of the active IPs are responsible for 80% of the total volume of spam and that 10% of the spamming ASes are responsible for the 90% of the volume. Finally, we study the temporal characteristics of the spamming IPs and find that spam activity has spread to new /8 subnetworks since 2006. Considering these spatio-temporal trends, the future of anti-spam is mixed: the current skewed spatial distribution of spam sources could be helpful in filtering spam, but the fact that spam sources are spreading in the IP space is a worrisome sign.
  • Keywords
    IP networks; Internet; information filtering; security of data; unsolicited e-mail; AS-level; IP-level; anti-spam; email address; email harvesting; honeypot account; network-level characteristics; spam activity; spam filtering; spam source; spamming IP; Distribution functions; Educational institutions; HTML; IP networks; Servers; Unsolicited electronic mail;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2011 19th IEEE International Conference on
  • Conference_Location
    Vancouver, BC
  • Print_ISBN
    978-1-4577-1392-7
  • Type

    conf

  • DOI
    10.1109/ICNP.2011.6089060
  • Filename
    6089060