DocumentCode
3002828
Title
Do Word Clues Suffice in Detecting Spai and Phishing?
Author
Rowe, Neil C. ; Barnes, David S. ; McVicker, Michael ; Egan, Melissa ; Betancourt, Richard ; Toledo, Rommel ; Horner, Douglas P. ; Davis, Duane T. ; Guiterrez, Louis ; Martell, Craig H.
Author_Institution
Naval Postgraduate Sch., Monterey
fYear
2007
fDate
20-22 June 2007
Firstpage
14
Lastpage
21
Abstract
Some commercial antispam and anti-phishing products prohibit email from "blacklisted" sites that they claim send spam and phishing email, while allowing email claiming to be from "whitelisted" sites they claim are known not to send it. This approach tends to unfairly discriminate against smaller and less-known sites, and would seem to be anti-competitive. An open question is whether other clues to spam and phishing would suffice to identify it. We report on experiments we have conducted to compare different clues for automated detection tools. Results show that word clues were by far the best clues for spam and phishing, although a little bit better performance could be obtained by supplementing word clues with a few others like the time of day the email was sent and inconsistency in headers. We also compared different approaches to combining clues to spam such as Bayesian reasoning, case-based reasoning, and neural networks; Bayesian reasoning performed the best. Our conclusion is that Bayesian reasoning on word clues is sufficient for antispam software and that blacklists and whitelists are unnecessary.
Keywords
security of data; unsolicited e-mail; anti-phishing products; commercial antispam; phishing; spam; word clues; Bayesian methods; Broadcast technology; Broadcasting; Conferences; Humans; Internet; Neural networks; Robustness; Testing; Unsolicited electronic mail; clues; spain phishing; testing; words;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
Conference_Location
West Point, NY
Print_ISBN
1-4244-1304-4
Electronic_ISBN
1-4244-1304-4
Type
conf
DOI
10.1109/IAW.2007.381908
Filename
4267536
Link To Document