首页> 外文会议>International Symposium on Digital Forensic and Security >Detection of compromised email accounts used for spamming in correlation with origin-destination delivery notification extracted from metadata
【24h】

Detection of compromised email accounts used for spamming in correlation with origin-destination delivery notification extracted from metadata

机译:与从元数据中提取的原始目的地传递通知相关联地检测用于垃圾邮件的受感染电子邮件帐户

获取原文

摘要

Fifty-four percent of the global email traffic in October 2016 was spam and phishing messages. Those emails were commonly sent from compromised email accounts. Previous research has primarily focused on detecting incoming junk mail but not locally generated spam messages. State-of-the-art spam detection methods generally require the content of the email to be able to classify it as either spam or a regular message. This content is not available within encrypted messages or is prohibited due to data privacy. The object of the research presented is to detect an anomaly with the Origin-Destination Delivery Notification method, which is based on the geographical origin and destination as well as the Delivery Status Notification of the remote SMTP server without the knowledge of the email content. The proposed method detects an abused account after a few transferred emails; it is very flexible and can be adjusted for every environment and requirement.
机译:2016年10月,全球电子邮件流量中有54%为垃圾邮件和网络钓鱼邮件。这些电子邮件通常是从受感染的电子邮件帐户发送的。先前的研究主要集中在检测传入的垃圾邮件,而不是本地生成的垃圾邮件。最新的垃圾邮件检测方法通常要求电子邮件的内容能够将其分类为垃圾邮件或常规邮件。此内容在加密消息中不可用,或者由于数据隐私而被禁止。提出的研究的目的是使用起源-目的地传递通知方法来检测异常,该方法基于地理位置和目的地以及远程SMTP服务器的传递状态通知,而无需了解电子邮件内容。所建议的方法是在转移了几封电子邮件后检测到滥用帐户;它非常灵活,可以针对每种环境和要求进行调整。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号