Forensic Analysis of E-mail Date and Time Spoofing
Preeti Mishra, Emmanuel S. Pilli, R. C. Joshi · 2012
There are no adequate and proactive mechanisms for securing E-mail systems. E-mail date and time spoofing is one of the major problems of E-mail security. The effects of E-mail spoofing can be limited by the appropriate configuration of E-mail servers and improved user awareness of the problem. The only real countermeasure is the use of digitally signed messages that allow a recipient to authenticate the identity of the sender. This paper presents E-mail forensics to detect E-mail Date and Time spoofing. We have created data set of spoofed and legitimate E-mails. We propose an algorithm to perform the forensic analysis of E-mail time and date spoofing, by reading the header information and analyzing the fields related to date and time. We have given a policy to check sent-date and received-date fields of every E-mail. If the sent-date and sent-time differs from the received date and received-time by some predefined margin, the E-mail has been spoofed. The algorithm is validated on the data set created in our lab.