SMTP Aggregate Bot-Network Detection via IP Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional spam detection methods are ineffective in identifying bot-network controlled computers due to their association with short-lived IP addresses and low volumes of spam, making it difficult to detect and prevent spam from these networks.

Innovation Solution

A method and system that determine the IP-address-aggregate associated with an email sender's IP address, categorize it based on Simple Mail Transfer Protocol (SMTP) traffic characteristics, and assign a bot-likelihood score using historical data to predict the likelihood of the IP address being part of a bot-network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional address-based filtering (blacklisting) is used, then spam from known sources can be blocked, but it is ineffective against bot-networks using short-lived IP addresses that do not generate enough traffic to establish a reputation

Engineering Contradiction:
Improvespam detection accuracyVSAvoidability to detect new bot-networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the detection approach by analyzing IP addresses in aggregates (groups) rather than individually. It divides the problem into: (1) collecting SMTP characteristics from multiple IP addresses within an aggregate, (2) categorizing aggregates based on shared characteristics, and (3) determining bot-likelihood at the aggregate level. This segmentation allows detection of bot-networks even when individual IP addresses have insufficient data, as the collective behavior of the aggregate reveals patterns that individual addresses hide.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-categorizing IP-address-aggregates into IP-address-aggregate-categories based on historical SMTP traffic characteristics before actual spam detection is needed. During operation, new IP addresses can be quickly evaluated by comparing their characteristics against pre-established categories, enabling rapid detection without requiring extensive historical data for each individual IP address.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If volume-based filtering is used, then high-volume spam sources can be identified, but bot-networks transmit low volumes of spam for short periods to remain inconspicuous

Engineering Contradiction:
Improvespam volumeVSAvoidbot-network detection effectiveness
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent merges multiple SMTP traffic characteristics (message count, message size, timing patterns, protocol compliance metrics) into a composite analysis at the IP-address-aggregate level. By combining these diverse characteristics and analyzing them collectively across multiple IP addresses in an aggregate, the system can detect bot-networks even when each individual address generates low volumes of spam, as the aggregated patterns reveal the coordinated behavior of bot-networks.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If analysis is performed on individual IP addresses, then specific spam sources can be identified, but bot-networks use short-lived dynamic addresses that do not generate enough traffic to establish a reputation

Engineering Contradiction:
ImproveIP address identification accuracyVSAvoidnetwork traffic volume per IP address
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the detection approach by analyzing IP addresses in aggregates (groups) rather than individually. It divides the problem into: (1) collecting SMTP characteristics from multiple IP addresses within an aggregate, (2) categorizing aggregates based on shared characteristics, and (3) determining bot-likelihood at the aggregate level. This segmentation allows detection of bot-networks even when individual IP addresses have insufficient data, as the collective behavior of the aggregate reveals patterns that individual addresses hide.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IP-address-aggregate serves as an intermediary construct between individual IP addresses and bot-network detection. Instead of directly analyzing individual short-lived IP addresses or making binary bot/non-bot determinations, the system uses IP-address-aggregates as an intermediate level of analysis that accumulates sufficient data to reveal patterns while maintaining the ability to trace back to individual addresses when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8438638B2Bot-network detection based on simple mail transfer protocol (SMTP) characteristics of e-mail senders within IP address aggregates
Publication Date: 2013.05.07 AT&T INTELLECTUAL PROPERTY I L P
  • US8438638B2 patent drawing
  • US8438638B2 patent drawing
  • US8438638B2 patent drawing

AI summary

A method and system for determining whether an IP address is part of a bot-network are provided. The IP-address-aggregate associated with the IP address of an e-mail sender is determined. The IP-address-aggregate is associated with an IP-address-aggregate-category based on the current SMTP traffic characteristics of the IP-address-aggregate and the known SMTP traffic characteristics of an IP-address-aggregate-category. A bot-likelihood score of the IP-address-aggregate-category is then associated with IP-address-aggregate. IP-address-aggregate-categories can be established based on historical SMTP traffic characteristics of the IP-address-aggregates. The IP-address-aggregates are grouped based on SMTP characteristics, and the IP-address-aggregate-categories are defined based on a selection of IP-address-aggregates with similar SMTP traffic characteristics that are diagnostic of spam bots vs. non-botnet-controllers spammers. Bot likelihood scores are determined for the resulting IP-address-aggregate-categories based on historically known bot IP addresses.