Catching spam before it arrives: domain specific dynamic blacklists
نویسندگان
چکیده
The arrival of any piece of unsolicited and unwanted email (spam) into a user’s email inbox is a problem. It results in real costs to organisations and possibly an increasing reluctance to use email by some users. Currently most spam prevention techniques rely on methods that examine the whole email message at the mail server. This paper describes research that aims to deny spam entry into the internal network in the first place. Examination of live amalgamated audit logs from a Linux kernel firewall, the PortSentry intrusion detection system and the Sendmail mail transfer agents has shown that it is possible that automated mailing programs send characteristic probes to the network gateway just before launching an avalanche of mail. Similarly it seems possible to detect precursor activity from some potential zombie machines. A real time system that could detect such activity needs to be certain that a particular IP address is about to send spam before blocking all of its packets at the network gateway. The architecture for a system that establishes certainty that a particular IP address is about to or has started sending spam is described in this paper. The eventual aim is to recognise precursor activity from spammers in real time, establish certainty that this IP address is about to send or is currently sending spam packets and to then deny packets from this IP address at a range of communicating gateways
منابع مشابه
Understanding Cross-Channel Abuse with SMS-Spam Support Infrastructure Attribution
Recent convergence of telephony with the Internet offers malicious actors the ability to craft cross-channel attacks that leverage both telephony and Internet resources. Bulk messaging services can be used to send unsolicited SMS messages to phone numbers. While the long-term properties of email spam tactics have been extensively studied, such behavior for SMS spam is not well understood. In th...
متن کاملMitigating Spam Using Spatio-Temporal Reputation
In this paper we present Preventive Spatio-Temporal Aggregation (PRESTA), a reputation model that combines spatial and temporal features to produce values that are behavior predictive and useful in partialknowledge situations. To evaluate its effectiveness, we applied PRESTA in the domain of spam detection. Studying the temporal properties of IP blacklists, we found that 25% of IP addresses onc...
متن کاملA Distributed Content Independent Method for Spam Detection
The amount of spam has skyrocketed in the recent past. Traditionally, spam was sent by single source mass mailers (spammers), making it relatively easy to screen out through the use of blacklists. Recently spammers started using botnets to send out the spam, rendering the blacklists ineffective. Although, content-based spam filters provide temporary relief, this is a never-ending cat-andmouse g...
متن کاملEmpirically Characterizing Domain Abuse and the Revenue Impact of Blacklisting
Using ground truth sales data for over 40K unlicensed prescription pharmaceuticals sites, we present an economic analysis of two aspects of domain abuse in the online counterfeit drug market. First, we characterize the nature of domains abused by affiliate spammers to monetize what is evidently an overwhelming demand for these drugs. We found that the most successful affiliates are agile in ada...
متن کاملStatistical Analysis of DNS Abuse in gTLDs Final Report
Commissioned by the Competition, Consumer Trust, and Consumer Choice Review Team with the support of ICANN, this study is focused on measuring rates of common forms of abusive activities in the domain name system. We conduct a comprehensive study examining malicious behavior in the global DNS and compare abuse rates in new and legacy gTLDs. We combine data sets from many sources, including zone...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006