Detection of compromised email accounts used for spamming in correlation with origin-destination delivery notification extracted from metadata
Title | Detection of compromised email accounts used for spamming in correlation with origin-destination delivery notification extracted from metadata |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Schäfer, C. |
Conference Name | 2017 5th International Symposium on Digital Forensic and Security (ISDFS) |
Publisher | IEEE |
ISBN Number | 978-1-5090-5835-8 |
Keywords | authentication, compromised email account, compromised email account detection, data privacy, delivery status notification, encrypted phishing, geographical origin, hacked, Human Behavior, human factors, incoming junk mail detection, IP networks, metadata, ODDN, Origin-Destination Delivery Notification, origin-destination delivery notification extracted, pattern classification, phishing, phishing messages, Postal services, pubcrawl, remote SMTP server, Servers, spam, spam messages, unsolicited e-mail, Unsolicited electronic mail |
Abstract | Fifty-four percent of the global email traffic in October 2016 was spam and phishing messages. Those emails were commonly sent from compromised email accounts. Previous research has primarily focused on detecting incoming junk mail but not locally generated spam messages. State-of-the-art spam detection methods generally require the content of the email to be able to classify it as either spam or a regular message. This content is not available within encrypted messages or is prohibited due to data privacy. The object of the research presented is to detect an anomaly with the Origin-Destination Delivery Notification method, which is based on the geographical origin and destination as well as the Delivery Status Notification of the remote SMTP server without the knowledge of the email content. The proposed method detects an abused account after a few transferred emails; it is very flexible and can be adjusted for every environment and requirement. |
URL | https://ieeexplore.ieee.org/document/7916494 |
DOI | 10.1109/ISDFS.2017.7916494 |
Citation Key | schafer_detection_2017 |
- ODDN
- Unsolicited electronic mail
- unsolicited e-mail
- spam messages
- spam
- Servers
- remote SMTP server
- pubcrawl
- Postal services
- phishing messages
- Phishing
- pattern classification
- origin-destination delivery notification extracted
- Origin-Destination Delivery Notification
- authentication
- metadata
- IP networks
- incoming junk mail detection
- Human Factors
- Human behavior
- hacked
- geographical origin
- encrypted phishing
- delivery status notification
- data privacy
- compromised email account detection
- compromised email account