首页> 外文会议>IEEE International Symposium on Software Reliability Engineering Workshops >Detection of Compromised Email Accounts Used by a Spam Botnet with Country Counting and Theoretical Geographical Travelling Speed Extracted from Metadata
【24h】

Detection of Compromised Email Accounts Used by a Spam Botnet with Country Counting and Theoretical Geographical Travelling Speed Extracted from Metadata

机译:通过国家/地区计数和从元数据中提取的理论地理旅行速度来检测垃圾邮件僵尸网络使用的受损电子邮件帐户

获取原文

摘要

Seventy six percent of sent spam and phishing emails have their origins in botnets. They use compromised email accounts to send junk mail through other SMTP servers to their destinations. Commonly, research is focused on the rapid detection of compromised accounts to protect the integrity of other systems. One possible way to do this is to scan the email content or limit the amount of messages that can be sent from an IP address or an account during a specified time period. An anomaly is properly detected if the limit is reached or spam emails are identified. The objective of the presented research is to detect the anomaly with geo location and country counting without the knowledge of the email content. A second method, called Theoretical Geographical Travelling Speed, was developed to raise the detection rate without false negatives. The proposed method is seven times faster than the default rate limited to the detection of a compromised account.
机译:发送的垃圾邮件和网络钓鱼电子邮件中有百分之七十六来自于僵尸网络。他们使用受感染的电子邮件帐户通过其他SMTP服务器将垃圾邮件发送到目的地。通常,研究集中在快速检测受感染帐户以保护其他系统的完整性。一种可行的方法是扫描电子邮件内容或限制在指定时间段内可以从IP地址或帐户发送的邮件数量。如果达到限制或识别出垃圾邮件,则可以正确检测到异常。本研究的目的是在不了解电子邮件内容的情况下,通过地理位置和国家/地区计数来检测异常。开发了第二种方法,称为理论地理行进速度,以提高检测率,而不会产生假阴性。所提出的方法比限于检测到受感染帐户的默认速率快7倍。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号