Computer Laboratory Home Page Search A-Z Directory Help
University of Cambridge Home Security Seminar
3 February 2004: Richard Clayton
Computer Laboratory > Security Group > Seminars > 3 February 2004: Richard Clayton

SECURITY SEMINAR SERIES

Title: Extrusion detection
Speaker: Richard Clayton, Computer Lab
Date: Tuesday, 3 February 2004, 16:15
Place: Lecture Theatre 2, William Gates Building

Abstract:

End users are often unaware that their systems have been compromised and are being used to relay bulk unsolicited email (spam). However, automated processing of the email logs recorded on the "smarthost" provided by an ISP for their customer's outgoing email can be used to detect this activity. These logs do not contain any of the content of the email, or even the subject lines. However, the variability and obfuscation of sender and receiver that is used by spammers to avoid detection at the destination creates distinctive patterns at the source that permits legitimate email traffic to be distinguished from spam. Some relatively simple heuristics result in the detection of low numbers of "false positives" despite tuning to ensure few "false negatives".