Spam mail discrimination system based on behavior of DNS servers associated with URLs

Shuji Suwa, Nariyoshi Yamai, Kiyohiko Okayama, Motonori Nakamura, Keita Kawano, Gada

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Citation (Scopus)

Abstract

As one of anti-spam technologies, DNSBL based on the URLs or their corresponding IP addresses in the messages is well used. However, some spam mails cannot be filtered by conventional DNSBLs since the spammers create websites using various techniques such as botnet, fast-flux and Wildcard DNS record. To discriminate such spam mails, we ananalyzed DNS record characteristics corresponding to the domain name in the URLs in actual spam mails. According to this analysis, in this paper we propose a spam mail discrimination system based on the behavior of DNS servers. Since the behavior checking process is likely to wait for a timeout, the system queries some records to a DNS server simultaneously and decides whether the mail is spam or not on receiving the first reply. In addition, the system also introduces a blacklist for the IP addresses of the DNS servers.

Original languageEnglish
Title of host publicationProceedings - 2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet, SAINT 2012
Pages381-386
Number of pages6
DOIs
Publication statusPublished - 2012
Event2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet, SAINT 2012 - Izmir, Turkey
Duration: Jul 16 2012Jul 20 2012

Publication series

NameProceedings - 2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet, SAINT 2012

Other

Other2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet, SAINT 2012
Country/TerritoryTurkey
CityIzmir
Period7/16/127/20/12

Keywords

  • DNS
  • URL
  • e-mail
  • spam

ASJC Scopus subject areas

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Spam mail discrimination system based on behavior of DNS servers associated with URLs'. Together they form a unique fingerprint.

Cite this