A Novel Method to Detect Junk Mail Traffic

  • Authors:
  • Qiang Li;Baoliang Mu

  • Affiliations:
  • -;-

  • Venue:
  • HIS '09 Proceedings of the 2009 Ninth International Conference on Hybrid Intelligent Systems - Volume 03
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

This paper proposes a junk mail or spam detection technique called ASCI (Abnormal SMTP Command Identification), which allows network administrators to cut off some spam traffic on email delivery. Our insight is that spamware usually generate special or abnormal packets deviating SMTP protocol for high throughout, while good users never do it. This characterization can be used to detect spam. ASCI is applied to two different volumes of email traffic data captured respectively near an email gateway and at a country-edged core router of a large commercial Internet Service Provider in China. Experimental results indicate that the method is effective and practical, with at least 11.4% reduction of email traffic for unwanted traffic