• DocumentCode
    460842
  • Title

    A New Approach for Detecting Abnormal Email Traffic in Backbone Network

  • Author

    Zhang, Ni ; Fang, Binxing ; Guo, Li ; Jiang, Yu

  • Author_Institution
    Inst. of Comput. Technol., Chinese Acad. of Sci., Beijing
  • Volume
    1
  • fYear
    2006
  • fDate
    Nov. 2006
  • Firstpage
    586
  • Lastpage
    591
  • Abstract
    This paper develops a new approach for detecting abnormal email traffic in backbone network by using an extended finite state automata (EFSA) model. Our idea is that bad email server configuration, network attack, and spamware usually generate special or abnormal packets, which are often reflected by the characterization of email traffic. Therefore, we process these traffic data by selecting some indicating parameters on the basis of the EFSA model, and then investigate abnormal traffic by identifying abnormal values. We apply our mechanism to email traffic data captured at one of the largest commercial Internet service provider (ISP) in China. Our initial results are quite unexpected and interesting, which include uncommon command packet number distribution, unexpected event sequence combinations, and surprising protocol errors. In terms of the number of command packet, the number of abnormal email accounts for 10.5%. Based on event sequence analysis, we believe that the SMTP port scan happened at the time of data collection
  • Keywords
    electronic mail; finite state machines; telecommunication congestion control; transport protocols; Internet service provider; SMTP port scan; abnormal email account; abnormal email traffic detection; abnormal packet; backbone network; bad email server configuration; command packet; data collection; email traffic characterization; email traffic data processing; event sequence analysis; event sequence combination; extended finite state automata; network attack; protocol error; spamware; Automata; Character generation; Electronic mail; Network servers; Protocols; Spine; Statistics; Telecommunication traffic; Traffic control; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security, 2006 International Conference on
  • Conference_Location
    Guangzhou
  • Print_ISBN
    1-4244-0605-6
  • Electronic_ISBN
    1-4244-0605-6
  • Type

    conf

  • DOI
    10.1109/ICCIAS.2006.294203
  • Filename
    4072156