b @bel: leveraging email delivery for spam mitigation

20
GIANLUCA STRINGHINI, MANUEL EGELE, AAPOSTOLIS ZARRAS, THORSTEN HOLZ, CHRISTOPHER KRUEGEL, AND GIOVANNI VIGNA PRESENTED BY RUI XIE B@BEL: Leveraging Email Delivery for Spam Mitigation

Upload: glynis

Post on 22-Feb-2016

60 views

Category:

Documents


0 download

DESCRIPTION

B @BEL: Leveraging Email Delivery for Spam Mitigation . Gianluca Stringhini , Manuel Egele , a Apostolis Zarras , Thorsten Holz , Christopher Kruegel , and Giovanni Vigna presented by rui xie. Problems on Spam. Wealthy economy behind spam 77% of emails are spam - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: B @BEL:  Leveraging Email Delivery for Spam Mitigation

GIANLUCA STRINGHINI, MANUEL EGELE, AAPOSTOLIS ZARRAS, THORSTEN HOLZ, CHRISTOPHER KRUEGEL, AND GIOVANNI

VIGNA

PRESENTED BY RUI XIE

B@BEL: Leveraging Email Delivery for Spam Mitigation

Page 2: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Problems on Spam Wealthy economy behind spam 77% of emails are spam 85% of spam are sent by botnets

Page 3: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Traditional Spam Detection Content Analysis Origin Analysis

Page 4: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Approach in Article Focusing on the way that client interact

with SMTP server

Page 5: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Overview Techniques System design Evaluation Limitations

Page 6: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Techniques SMTP dialects Feedback manipulation

Page 7: B @BEL:  Leveraging Email Delivery for Spam Mitigation

SMTP dialects

Page 8: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Feedback Manipulation

Page 9: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Botnet also use feedback Botmaster sends spam to bot Bot sends spam to SMTP server SMTP server sends spam to user or

replies bot no such user exists Bot replies bot master no such user

exists Bot master delete address of the user

from user list

Page 10: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Importance SMTP dialects

Spam detection Malware classification

Feedback manipulationSuccessful botnets are using bot feedback35% of the email addresses were

nonexistent

Page 11: B @BEL:  Leveraging Email Delivery for Spam Mitigation

System design Learning SMTP dialects Build a decision model Making a decision

Page 12: B @BEL:  Leveraging Email Delivery for Spam Mitigation

SMTP dialects state D =< Σ,S,s0,T, Fg,Fb >

Σ: input alphabetS : set of statess0: initial stateT : transitions Fg : good final statesFb : bad final states

Page 13: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Learning SMTP dialects

Page 14: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Collecting SMTP conversations Passive observation

Two dialects might look the same!

Active probing Intentionally sending incorrect replies, error

messages

Page 15: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Build a decision model

Page 16: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Making a decision

Passive matching Detect dialects by observing conversations

Active probing Send specific replies to “expose” differences

Page 17: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Evaluation Experiment has 621,919 SMTP

conversations Results

260,074 as spam218,675 as ham143,170 could not decide

Page 18: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Result in real life

Page 19: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Limitations Evading dialects detection

Implement a “faithful” SMTP engine Making spammers to look like a legitimate

client

Evading feedback manipulation

Page 20: B @BEL:  Leveraging Email Delivery for Spam Mitigation

Conclusion Focusing on the way that client interact

with SMTP serverSMTP dialects Feedback manipulation

Valuable tool for spam mitigation