A proposed technique for tracing origin of spam on the Usenet

Dirk Bertels · 2006

The Usenet, a worldwide distributed decentralized conferencing system, is widely targeted by spammers who use a variety of techniques in order to obscure their identity. One of these techniques is called path preload, in which the path header is spoofed by means of attaching a false section at the beginning of this path. The process of detecting and confirming path preload is laborious and requires a thorough understanding of the Usenet. A technique which downloads a particular article from several servers, and compares their path headers is explored as to its usefulness regarding path preload detection. This document begins with a general background on the Usenet, highlighting those aspects that are relevant to the research, especially the topics of Usenet headers and spam. This leads to a description of the proposed technique and the development of a tool capable of implementing this technique. The tool essentially downloads a spam article from different servers, and analyses their headers. A map is constructed from the data gathered showing the servers that the articles traverse in order to reach their destiny. Since each article is downloaded from more than one location, some commonality may be found in these trajectories. If this commonality occurs at the beginning of the trajectory, the article is said to have a common path. Once a common path is established, a more heuristic approach is taken in order to establish some preliminary conclusions as to whether this common path is likely to be path preload or not. This approach requires some knowledge about various aspects of the Usenet and involves additional anti-spam techniques alongside the common path technique. Several sessions have been conducted and the results outlined, analysed, and discussed at the end of this document, followed by some thoughts on possible future advances and further improvements.

Read the paper · More papers on PaperTik