Sciweavers

PAM
2009
Springer

Inferring Spammers in the Network Core

14 years 7 months ago
Inferring Spammers in the Network Core
Despite a large amount of effort devoted in the past years trying to limit unsolicited mail, spam is still a major global concern. Content-analysis techniques and blacklists, the most popular methods used to identify and block spam, are beginning to lose their edge in the battle. We argue here that one not only needs to look into the network-related characteristics of spam traffic, as has been recently suggested, but also to look deeper into the network core, to counter the increasing sophistication of spammers. At the same time, local knowledge available at a given server can often be irreplaceable in identifying specific spammers. To this end, in this paper we show how the local intelligence of mail servers can be gathered and correlated passively, scalably, and with low-processing cost at the ISP-level providing valuable network-wide information. First, we use a large network flow trace from a major national ISP, to demonstrate that the prefiltering decisions and thus spammer-re...
Dominik Schatzmann, Martin Burkhart, Thrasyvoulos
Added 20 May 2010
Updated 20 May 2010
Type Conference
Year 2009
Where PAM
Authors Dominik Schatzmann, Martin Burkhart, Thrasyvoulos Spyropoulos
Comments (0)