Correlating Web and Email Attributes for Spam Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional spam detection methods face challenges in accurately distinguishing spam emails due to increasingly sophisticated techniques employed by spammers, leading to high rates of false positive and false negative detections.
Innovation Solution
A method that collects and analyzes attributes associated with web sites and email messages to determine if an email was sent in response to a submission, using a classifier generated from training data to improve spam detection accuracy by identifying correlations between web site and mail server attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional spam filters use message content to detect spam, then the detection method is simple and straightforward, but the detection accuracy deteriorates due to increasingly sophisticated spammer techniques
Solution Approach 1:
The patent transitions from analyzing only email message content (one dimension) to analyzing multiple dimensions including web site attributes, mail server attributes, and their correlations. This dimensional expansion enables more accurate spam detection by considering the relationship between email submission contexts and received messages across different attribute spaces.
Solution Approach 2:
The patent introduces web site attributes and mail server attributes as intermediary elements that mediate between the email submission action and the received email. These intermediaries provide additional contextual information that helps distinguish legitimate emails from spam by analyzing the correlation between submission contexts and message characteristics.
2Reliability
If spam filters rely on honeypots to collect spam content, then the filter creation process is conventional and straightforward, but the ability to detect sophisticated spam deteriorates
Solution Approach 1:
The patent performs preliminary analysis of web site attributes and mail server attributes before spam detection is needed. By pre-establishing the correlation between submission contexts and email characteristics, the system is better prepared to detect sophisticated spam that attempts to evade traditional honeypot-based filtering.
Solution Approach 2:
The patent changes the parameters used for spam detection from solely message content to include web site attributes, mail server attributes, and their correlations. This parameter expansion allows the system to adapt to sophisticated spam techniques by detecting anomalies in the relationship between submission contexts and received messages.
3Productivity
If email addresses are submitted to web sites and spam is sent to those addresses, then spammers can effectively distribute spam, but conventional filters cannot distinguish between legitimate and spam emails
Solution Approach 1:
The patent establishes a feedback mechanism by analyzing the correlation between web site attributes (where email addresses were submitted) and mail server attributes (that send emails to those addresses). This feedback loop enables the system to learn patterns of legitimate email delivery versus spam distribution, improving the ability to distinguish between the two while maintaining efficient email delivery.
Data Source
AI summary
A computer correlates web and email attributes to detect spam. A security module on a client collects attributes of a web site to which an email address was submitted and attributes of an email message sent to the email address that was previously submitted. The security module analyzes the attributes of the web site and the email message to determine whether the email message was sent to the email address responsive to the submission of the email address to the web site. Based on the analysis, the security module determines whether the email message is spam. A machine learning module on a security server establishes training data describing the attributes of the web site to which email addresses were submitted and attributes of legitimate emails received in response to the address submissions. The machine learning module generates an attributes classifier for the security module for spam detection.


