• DocumentCode
    3318534
  • Title

    Detecting Abnormal Changes in E-mail Traffic Using Hierarchical Fuzzy Systems

  • Author

    Lim, Mark Jyn-Huey ; Negnevitsky, Michael ; Hartnett, Jacky

  • Author_Institution
    Tasmania Univ., Hobart
  • fYear
    2007
  • fDate
    23-26 July 2007
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    E-mail traffic analysis is an area of work that focuses on extracting information about the behaviour of e-mail users based on the sender, receiver, and date/time information taken from the header section of e-mail messages. Such work has applications for law enforcement where investigators and analysts require techniques to assist them with finding unusual or suspicious patterns from large amounts of communication log data. This paper describes work using hierarchical fuzzy systems to detect abnormal changes in e-mail traffic behaviour, through the fusion of e-mail traffic behaviour measurements. The paper focuses on the use of three different hierarchical fuzzy system architectures, to determine the effect that input variable groupings have on the abnormality ratings given to the communication links of suspect e-mail accounts. The case study demonstrates the use of the three hierarchical fuzzy system architectures for analysing suspect e-mail accounts belonging to the Enron e-mail corpus.
  • Keywords
    electronic mail; information retrieval; law administration; security of data; terrorism; Enron e-mail corpus; e-mail traffic abnormal change detection; forensic tool; hierarchical fuzzy system architecture; information extraction; law enforcement; terrorist attack; Australia; Data analysis; Data mining; Digital forensics; Electronic mail; Fuzzy systems; Information analysis; Law enforcement; Mobile communication; Terrorism;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Fuzzy Systems Conference, 2007. FUZZ-IEEE 2007. IEEE International
  • Conference_Location
    London
  • ISSN
    1098-7584
  • Print_ISBN
    1-4244-1209-9
  • Electronic_ISBN
    1098-7584
  • Type

    conf

  • DOI
    10.1109/FUZZY.2007.4295556
  • Filename
    4295556