Quantitative Analysis of Ecient Antispam Techniques
Anders Wiehe, Stephen Dirk Bjørn Wolthusen · 2006
While dynamic content-based ltering mecha- nisms for the identication of unsolicited commercial email (UCE, or more commonly \spam) have proven to be eec- tive, these techniques require considerable computational resources. It is therefore highly desirable to reduce the number of emails that must be subjected to a content-based analysis. In this paper, a number of ecient techniques based on lower protocol level properties are analyzed using a large real-world data set. We show that combinations of several network-based lters can provide a computationally ecient pre-ltering mechanism at acceptable false-positive rates. In this paper, a survey and analysis of ltering techniques based on lower protocol level properties is therefore pre- sented. To this end, section II discusses the experimental setup used in gathering baseline data and also briefly covers the main low-level and content-based ltering approaches. Section III then provides an analysis of ltering sensitivity and selectivity of each low-level technique while section IV subsequently discusses the implications of these results for optimized conguration of ltering mechanisms as well as the limitations of the data set used. Finally, section V pro- vides a brief overview over related work and analyses while section VI describes ongoing and planned research in the area of hybrid anti-spam ltering techniques.