• DocumentCode
    3002828
  • Title

    Do Word Clues Suffice in Detecting Spai and Phishing?

  • Author

    Rowe, Neil C. ; Barnes, David S. ; McVicker, Michael ; Egan, Melissa ; Betancourt, Richard ; Toledo, Rommel ; Horner, Douglas P. ; Davis, Duane T. ; Guiterrez, Louis ; Martell, Craig H.

  • Author_Institution
    Naval Postgraduate Sch., Monterey
  • fYear
    2007
  • fDate
    20-22 June 2007
  • Firstpage
    14
  • Lastpage
    21
  • Abstract
    Some commercial antispam and anti-phishing products prohibit email from "blacklisted" sites that they claim send spam and phishing email, while allowing email claiming to be from "whitelisted" sites they claim are known not to send it. This approach tends to unfairly discriminate against smaller and less-known sites, and would seem to be anti-competitive. An open question is whether other clues to spam and phishing would suffice to identify it. We report on experiments we have conducted to compare different clues for automated detection tools. Results show that word clues were by far the best clues for spam and phishing, although a little bit better performance could be obtained by supplementing word clues with a few others like the time of day the email was sent and inconsistency in headers. We also compared different approaches to combining clues to spam such as Bayesian reasoning, case-based reasoning, and neural networks; Bayesian reasoning performed the best. Our conclusion is that Bayesian reasoning on word clues is sufficient for antispam software and that blacklists and whitelists are unnecessary.
  • Keywords
    security of data; unsolicited e-mail; anti-phishing products; commercial antispam; phishing; spam; word clues; Bayesian methods; Broadcast technology; Broadcasting; Conferences; Humans; Internet; Neural networks; Robustness; Testing; Unsolicited electronic mail; clues; spain phishing; testing; words;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
  • Conference_Location
    West Point, NY
  • Print_ISBN
    1-4244-1304-4
  • Electronic_ISBN
    1-4244-1304-4
  • Type

    conf

  • DOI
    10.1109/IAW.2007.381908
  • Filename
    4267536