DocumentCode
3108290
Title
Forensic Value of Backscatter from Email Spam
Author
Fuhrman, Christopher P.
Author_Institution
Dept. of Software & IT Eng., Ecole de Technol. Super. (ETS), Montreal, QC
fYear
2008
fDate
9-9 Oct. 2008
Firstpage
46
Lastpage
52
Abstract
Email backscatter is a side effect of email spam, viruses or worms. When a spam or malware-laden email is sent, it nearly always has a forged sender address. If this email fails to reach its recipient, e.g., because the recipientpsilas mailbox is full or the recipient has set up an out-of-the-office auto-responder, the recipientpsilas mail system may attempt to generate and send an automated message replying to the forged sender. This unsolicited message sent to the forged sender is an email backscatter. On massive email spam runs where the same address (or domain) is forged as the sender, there can be significant amounts of backscatter email to the forged address. We consider potential forensic value in the analysis of email backscatter, for example, the times when certain compromised machines were used to send spams. We present results of an analysis performed with our Backscatter Email Analysis Tool (BEAT) of a massive backscatter incident that occurred in mid April, 2008.
Keywords
computer viruses; unsolicited e-mail; backscatter email analysis tool; email spam; forensic value; unsolicited message; viruses; worms; Backscatter; Computer worms; Digital forensics; Electronic mail; Performance analysis; Postal services; Protocols; Unsolicited electronic mail; Viruses (medical); Web and internet services; Email backscatter; delivery status notification; email spam; forged sender in emails; spam-run forensics; zombie monitoring;
fLanguage
English
Publisher
ieee
Conference_Titel
Digital Forensics and Incident Analysis, 2008. WDFIA '08. Third International Annual Workshop on
Conference_Location
Malaga
Print_ISBN
978-0-7695-3362-9
Type
conf
DOI
10.1109/WDFIA.2008.10
Filename
4651707
Link To Document