DocumentCode :
460842
Title :
A New Approach for Detecting Abnormal Email Traffic in Backbone Network
Author :
Zhang, Ni ; Fang, Binxing ; Guo, Li ; Jiang, Yu
Author_Institution :
Inst. of Comput. Technol., Chinese Acad. of Sci., Beijing
Volume :
1
fYear :
2006
fDate :
Nov. 2006
Firstpage :
586
Lastpage :
591
Abstract :
This paper develops a new approach for detecting abnormal email traffic in backbone network by using an extended finite state automata (EFSA) model. Our idea is that bad email server configuration, network attack, and spamware usually generate special or abnormal packets, which are often reflected by the characterization of email traffic. Therefore, we process these traffic data by selecting some indicating parameters on the basis of the EFSA model, and then investigate abnormal traffic by identifying abnormal values. We apply our mechanism to email traffic data captured at one of the largest commercial Internet service provider (ISP) in China. Our initial results are quite unexpected and interesting, which include uncommon command packet number distribution, unexpected event sequence combinations, and surprising protocol errors. In terms of the number of command packet, the number of abnormal email accounts for 10.5%. Based on event sequence analysis, we believe that the SMTP port scan happened at the time of data collection
Keywords :
electronic mail; finite state machines; telecommunication congestion control; transport protocols; Internet service provider; SMTP port scan; abnormal email account; abnormal email traffic detection; abnormal packet; backbone network; bad email server configuration; command packet; data collection; email traffic characterization; email traffic data processing; event sequence analysis; event sequence combination; extended finite state automata; network attack; protocol error; spamware; Automata; Character generation; Electronic mail; Network servers; Protocols; Spine; Statistics; Telecommunication traffic; Traffic control; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security, 2006 International Conference on
Conference_Location :
Guangzhou
Print_ISBN :
1-4244-0605-6
Electronic_ISBN :
1-4244-0605-6
Type :
conf
DOI :
10.1109/ICCIAS.2006.294203
Filename :
4072156
Link To Document :
بازگشت