Spam and Zombie Detection System with Machine Learned Spot Algorithm

S. Manishankar, Sobin E. S · International Journal of Science and Research (IJSR) · 2014

Email world has grown so much that there is a wide increase in the number of email that fells in to the category of Spam and Zombie attack. There is always a need for trained system that predicts spam and Zombie attack, this paper deals with a novel approach of machine learning to build a tool which predicts an email spam or not with the help of SPOT detection with SPERT algorithm, paper also deals with Zombie attacks and DDOS attacks networks in an online manner. We consider ourselves situated in a network and ask the following question: How can we automatically identify the compromised machines in the network as outgoing messages pass the monitoring point sequentially? The approaches developed in the previous work cannot be applied here. The locally generated outgoing messages in a network normally cannot provide the aggregate large-scale spam view required by these approaches. Moreover, these approaches cannot support the online detection requirement in the environment we consider the nature of sequentially observing outgoing messages gives rise to the sequential detection problem. In this paper, we will develop a spam zombie detection system, named SPOT (4), by monitoring outgoing messages. SPOT is designed based on a statistical method called Sequential Probability Ratio Test (SPRT), developed by Wald in his seminal work. SPRT is a powerful statistical method that can be used to test between two hypotheses (in our case, a machine is compromised versus the machine is not compromised), as the events (in our case, outgoing messages) occur sequentially. This means that the SPOT detection system can identify a compromised machine quickly. Moreover, both the false positive and false negative probabilities of SPRT can be bounded by user-defined thresholds. Consequently, users of the SPOT system can select the desired thresholds to control the false positive and false negative rates of the system. In this paper, we develop the SPOT detection system to assist system administrators in automatically identifying the compromised m our evaluation studies spot is effective. 2. Existing Works on the Field Existing approach mainly depend upon two area One is effectively detecting the spam mails from the outgoing mails network/system. Commonly the Botnet attacks are showing some common characteristics. These studies provided important insights into the aggregate global characteristics of spamming botnets by clustering spam messages received at the provider into spam campaigns using embedded URLs and near-duplicate content clustering, respectively (5). The common approaches to the botnet attacks are quite different they are not consider about healing from a single network

Read the paper · More papers on PaperTik