Mitigating Spam Using Spatio-Temporal Reputation

dc.contributor.authorWest, Andrew G.
dc.contributor.authorAviv, Adam J.
dc.contributor.authorLee, Insup
dc.contributor.authorLee, Insup
dc.date2023-05-17T03:31:32.000
dc.date.accessioned2023-05-22T13:01:50Z
dc.date.available2023-05-22T13:01:50Z
dc.date.issued2010-01-01
dc.date.submitted2010-02-05T13:12:47-08:00
dc.description.abstractIn this paper we present Preventive Spatio-Temporal Aggregation (PRESTA), a reputation model that combines spatial and temporal features to produce values that are behavior predictive and useful in partial-knowledge situations. To evaluate its effectiveness, we applied PRESTA in the domain of spam detection. Studying the temporal properties of IP blacklists, we found that 25% of IP addresses once listed on a blacklist were re-listed within 10 days. Further, during our evaluation period over 45% of IPs de-listed were re-listed. By using the IP address assignment hierarchy to define spatial groupings and leveraging these temporal statistics, PRESTA produces reputation values that correctly classify up to 50% of spam email not identified by blacklists alone, while maintaining low false-positive rates. When used in conjunction with blacklists, an average of 93% of spam emails are identified, and we find the system is consistent in maintaining this blockage rate even during periods of decreased blacklist performance. PRESTA spam filtering can be employed as an intermediate filter (perhaps in-network) prior to context-based analysis. Further, our spam detection system is scalable; computation can occur in near real-time and over 500,000 emails can be scored an hour.
dc.description.commentsUniversity of Pennsylvania Department of Computer and Information Science Technical Report No. MS-CIS-10-04.
dc.identifier.urihttps://repository.upenn.edu/handle/20.500.14332/7883
dc.legacy.articleid1962
dc.legacy.fulltexturlhttps://repository.upenn.edu/cgi/viewcontent.cgi?article=1962&context=cis_reports&unstamped=1
dc.source.issue916
dc.source.journalTechnical Reports (CIS)
dc.source.statuspublished
dc.titleMitigating Spam Using Spatio-Temporal Reputation
dc.typeReport
digcom.contributor.authorWest, Andrew G.
digcom.contributor.authorAviv, Adam J.
digcom.contributor.authorChang, Jian
digcom.contributor.authorisAuthorOfPublication|email:lee@cis.upenn.edu|institution:University of Pennsylvania|Lee, Insup
digcom.identifiercis_reports/916
digcom.identifier.contextkey1134273
digcom.identifier.submissionpathcis_reports/916
digcom.typereport
dspace.entity.typePublication
relation.isAuthorOfPublication45a9eed5-3211-4c36-b40d-6394302dfdce
relation.isAuthorOfPublication45a9eed5-3211-4c36-b40d-6394302dfdce
relation.isAuthorOfPublication.latestForDiscovery45a9eed5-3211-4c36-b40d-6394302dfdce
upenn.schoolDepartmentCenterTechnical Reports (CIS)
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
MS_CIS_10_04_1.pdf
Size:
327.63 KB
Format:
Adobe Portable Document Format
Collection