 |
Tu Ouyang, Soumya Ray, Michael Rabinovich, Mark Allman. Can Network Characteristics Detect Spam Effectively in a Stand-Alone Enterprise? Passive and Active Measurement Conference, March 2011.
PDF | Data
Abstract:
Previous work has shown
that the network dynamics experienced by both the initial packet and
an entire connection carrying an email can be leveraged to classify
the email as spam or ham. In the case of packet properties, the prior
work has investigated their efficacy based on models of traffic
collected from around the world. In this paper, we first revisit the
techniques when only using information from a single enterprise's
vantage point and find packet properties to be less useful. We
also show that adding flow characteristics to a model of packet
features adds modest discriminating power, and some flow features'
information is captured by packet features.
BibTeX:
@inproceedings{ORRA11,
author = "Tu Ouyang and Soumya Ray and Michael Rabinovich and Mark Allman",
title = "{Can Network Characteristics Detect Spam Effectively in a Stand-Alone Enterprise?}",
booktitle = "Passive and Active Measurement Conference",
year = 2011,
month = mar,
}
|
|