11.2 Spam Flashcards
1
Q
Spam definition
A
Unwanted commercial email
2
Q
Most spam ends up in your spam folder. T/F
A
T
3
Q
Problem with spam
A
- Filters: have to separate good from bad
- Storage
- Security problems
4
Q
Filter
A
prevent message from reaching inbox
5
Q
Filer problem: How to differentiate spam from “ham”
A
- Content based
- IP address of sender (blacklisting)
- Behavior features (how the mail is sent)
6
Q
BGP “Agility” Surprise
A
- Hijack IP prefix
- send spam
- withdraw
makes ip blacklists useless
7
Q
Things determinable from a single-packet receiver
A
distance between sender and receiver
Density
Local time of day
AS of senders IP
8
Q
Things determinable from a single-message
A
# of recipients length of message
9
Q
Things determinable from aggregates
A
variation in message length
10
Q
SNARE
A
70% detection rate
0.1% false positive rate
uses network level features