SMTP Aggregate Bot-Network Detection via IP Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional spam detection methods are ineffective in identifying bot-network controlled computers due to their association with short-lived IP addresses and low volumes of spam, making it difficult to detect and prevent spam from these networks.
Innovation Solution
A method and system that determine the IP-address-aggregate associated with an email sender's IP address, categorize it based on Simple Mail Transfer Protocol (SMTP) traffic characteristics, and assign a bot-likelihood score using historical data to predict the likelihood of the IP address being part of a bot-network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional address-based filtering (blacklisting) is used, then spam from known sources can be blocked, but it is ineffective against bot-networks using short-lived IP addresses that do not generate enough traffic to establish a reputation
Solution Approach 1:
The patent segments the detection approach by analyzing IP addresses in aggregates (groups) rather than individually. It divides the problem into: (1) collecting SMTP characteristics from multiple IP addresses within an aggregate, (2) categorizing aggregates based on shared characteristics, and (3) determining bot-likelihood at the aggregate level. This segmentation allows detection of bot-networks even when individual IP addresses have insufficient data, as the collective behavior of the aggregate reveals patterns that individual addresses hide.
Solution Approach 2:
The patent performs preliminary action by pre-categorizing IP-address-aggregates into IP-address-aggregate-categories based on historical SMTP traffic characteristics before actual spam detection is needed. During operation, new IP addresses can be quickly evaluated by comparing their characteristics against pre-established categories, enabling rapid detection without requiring extensive historical data for each individual IP address.
2Quantity of substance
If volume-based filtering is used, then high-volume spam sources can be identified, but bot-networks transmit low volumes of spam for short periods to remain inconspicuous
Solution Approach 1:
The patent merges multiple SMTP traffic characteristics (message count, message size, timing patterns, protocol compliance metrics) into a composite analysis at the IP-address-aggregate level. By combining these diverse characteristics and analyzing them collectively across multiple IP addresses in an aggregate, the system can detect bot-networks even when each individual address generates low volumes of spam, as the aggregated patterns reveal the coordinated behavior of bot-networks.
3Measurement precision
If analysis is performed on individual IP addresses, then specific spam sources can be identified, but bot-networks use short-lived dynamic addresses that do not generate enough traffic to establish a reputation
Solution Approach 1:
The patent segments the detection approach by analyzing IP addresses in aggregates (groups) rather than individually. It divides the problem into: (1) collecting SMTP characteristics from multiple IP addresses within an aggregate, (2) categorizing aggregates based on shared characteristics, and (3) determining bot-likelihood at the aggregate level. This segmentation allows detection of bot-networks even when individual IP addresses have insufficient data, as the collective behavior of the aggregate reveals patterns that individual addresses hide.
Solution Approach 2:
The IP-address-aggregate serves as an intermediary construct between individual IP addresses and bot-network detection. Instead of directly analyzing individual short-lived IP addresses or making binary bot/non-bot determinations, the system uses IP-address-aggregates as an intermediate level of analysis that accumulates sufficient data to reveal patterns while maintaining the ability to trace back to individual addresses when needed.
Data Source
AI summary
A method and system for determining whether an IP address is part of a bot-network are provided. The IP-address-aggregate associated with the IP address of an e-mail sender is determined. The IP-address-aggregate is associated with an IP-address-aggregate-category based on the current SMTP traffic characteristics of the IP-address-aggregate and the known SMTP traffic characteristics of an IP-address-aggregate-category. A bot-likelihood score of the IP-address-aggregate-category is then associated with IP-address-aggregate. IP-address-aggregate-categories can be established based on historical SMTP traffic characteristics of the IP-address-aggregates. The IP-address-aggregates are grouped based on SMTP characteristics, and the IP-address-aggregate-categories are defined based on a selection of IP-address-aggregates with similar SMTP traffic characteristics that are diagnostic of spam bots vs. non-botnet-controllers spammers. Bot likelihood scores are determined for the resulting IP-address-aggregate-categories based on historically known bot IP addresses.


