EDBT 2026 Demo / reviewers in the wild / expert
Mengjun Xie
dblp:51/4251
· DBLP profile ↗
34ranked-venue papers
8as first author
5since 2021 · last 2024
0000-0001-5089-9614ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 3 since 2021Computer networks · 11 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 7 · 1 first-authorSystems, architecture and hardware · 3Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Comprehensive Survey on Basic Safety Message Attacks and Their Detection
Mengjun Xie |
ICDF2C (2) | 2 |
| 2023 | ForensiQ: A Knowledge Graph Question Answering System for IoT Forensics
Mengjun Xie |
ICDF2C (2) | 2 |
| 2022 | A comprehensive analysis of the impact of online media and newsprint on advertising sales in the information society
Keyan Xu, Mengjun Xie, Yasser Alshehri, Noha Alnazzawi |
Soft Comput. | 2 |
| 2022 | Correction to: A comprehensive analysis of the impact of online media and newsprint on advertising sales in the information society
Keyan Xu, Mengjun Xie, Yasser Alshehri, Noha Alnazzawi |
Soft Comput. | 2 |
| 2021 | ReLF: Scalable Remote Live Forensics for AndroidabstractThe world has witnessed the proliferation of mobile technologies as well as smartphone-related cybercrimes in recent years. However, due to high mobility of smartphones and tablets and transient nature of those attacks, previous forensic approaches become inadequate to retrieve forensic data and respond to cybersecurity incidents in time, especially when the investigation involves a large number of mobile devices. In this paper, we propose ReLF11Source code available at https://github.com/nexus-lab?q=relf, a remote live forensics system for Android smartphones and tablets. ReLF enables forensic investigators to effectively triage operating Android devices and acquire a wide range of forensic artifacts at scale. Compared to existing Android forensic tools that are publicly available, ReLF provides a much more comprehensive set of collectible artifacts and better OS compatibility. Our evaluation results demonstrate that the ReLF client only introduces minor energy overhead to Android devices and that the ReLF server can well handle a large number of Android devices with increasing workload. We also showcase how ReLF can be used in real-world forensic investigation through case studies. Mengjun Xie, Jiang Bian 0001 |
TrustCom | 2 |
| 2020 | Developing and Validating a Computable Phenotype for the Identification of Transgender and Gender Nonconforming Individuals and Subgroups
Yi Guo 0005, Xing He 0003, Tianchen Lyu, Hansi Zhang, Yonghui Wu 0001, Xi Yang 0015, Zhaoyi Chen, Merry J. Markham, François Modave, Mengjun Xie, William R. Hogan, Christopher A. Harle, Elizabeth Shenkman, Jiang Bian 0001 |
AMIA | 10 |
| 2020 | L-PowerGraph: a lightweight distributed graph-parallel communication mechanism
Yue Zhao 0014, Kenji Yoshigoe, Mengjun Xie, Jiang Bian 0001, Ke Xiong 0001 |
J. Supercomput. | 3 |
| 2019 | Isoflat: Flat Provider Network Multiplexing and Firewalling in OpenStack CloudabstractNetworking is one of the key enablers of cloud computing and its security is essential for multi-tenant clouds. As a widely used open source solution to cloud computing, OpenStack allows computing resources to connect to the physical network infrastructure through provider networks for performance and reliability considerations. However, OpenStack users are stuck with either VLAN provider networks that are complex to configure and manage or flat networks that are not isolated and have the limitation on interface multiplexing. To address this problem, in this paper, we propose a new mechanism called Isoflat, which extends OpenStack's ability for creating flat provider networks with both configuration simplicity and flexible isolation capability. Our evaluation results show that a provider network with Isoflat can achieve similar network performance as a flat or VLAN provider network. Our results also show that the Isoflat firewall has much less impact on throughput performance than security group. Mengjun Xie, Li Yang 0001 |
ICC | 2 |
| 2019 | Network Intrusion Detection System as a Service on OpenStack CloudabstractCloud computing has become a major computing paradigm and data processing approach in almost all sectors. To ensure normal business operation and data security, performing traffic monitoring and detecting suspicious network packets and possible network intrusions have become a daily job for tenant administrators. Using existing tools, a tenant administrator can set up a Network Intrusion Detection System (NIDS) on a virtual machine (VM) instance in the tenant and mirror the traffic from other instances in the tenant to the NIDS instance via Tap as a Service (TaaS) or a Switched Port Analyzer (SPAN) port. However, this type of mechanisms can consume significant resources (e.g., CPU and bandwidth) in the cloud environment. In this work, we propose a new lightweight approach, namely Network Intrusion Detection System as a Service (NIDSaaS), for OpenStack cloud. Our preliminary experimental results show that our NIDSaaS approach consumes much less CPU compared to the existing TaaS approach. Mengjun Xie, Li Yang 0001 |
ICNP | 3 |
| 2019 | Powering Hands-on Cybersecurity Practices with Cloud ComputingabstractCybersecurity education and training have gained increasing attention in all sectors due to the prevalence and quick evolution of cyberattacks. A variety of platforms and systems have been proposed and developed to accommodate the growing needs of hands-on cybersecurity practice. However, those systems are either lacking sufficient flexibility (e.g., tied to a specific virtual computing service provider, little customization support) or difficult to scale. In this work, we present a cloud-based platform named EZSetup for hands-on cybersecurity practice at scale and our experience of using it in class. EZSetup is customizable and cloud-agnostic. Users can create labs through an intuitive Web interface and deploy them onto one or multiple clouds. We have used NSF funded Chameleon cloud and our private OpenStack cloud to develop, test and deploy EZSetup. We have developed 14 network and security labs using the tool and included six labs in an undergraduate network security course in spring 2019. Our survey results show that students have very positive feedback on using EZSetup and computing clouds for hands-on cybersecurity practice. Mengjun Xie |
ICNP | 3 |
| 2016 | A Distributed Graph-Parallel Computing System with Lightweight Communication OverheadabstractIn order to process complex and large-scale graph data numerous distributed graph-parallel computing platforms have been proposed. However, excessive communications among computing nodes in these systems not only aggravate the network I/O workload of the underlying computing hardware systems but may also cause a decrease in runtime performance and scalability. In this paper, we propose and implement a system called Ligraph, which computes large-scale graph data in distributed mode with lightweight communication overhead. Ligraph is similar to PowerGraph system with three new features: (1) a Gather partial sum difference based computing model; (2) a corresponding lightweight Gather communication mechanism; (3) for PageRank-like algorithms Ligraph additionally employs a lightweight synchronizing communication mechanism and an edge direction-aware graph partition strategy proposed by our former work LightGraph, which is specially designed for PageRank-like algorithms. We have conducted extensive experiments using real-world data sets, and our results verified the effectiveness of Ligraph on reducing the communication overhead and improving the runtime performance and the scalability compared with PowerGraph and LightGraph. For example, compared with PowerGraph under Random partition scenario Ligraph can not only reduce up to 35.2 percent of the communication overhead but also cut up to 21.8 percent of the runtime for PageRank algorithm while processing Twitter data set. Our experiment results also demonstrate that compared with several other representative existing systems Ligraph also outperforms them in graph computing rate. Yue Zhao 0014, Kenji Yoshigoe, Jiang Bian 0001, Mengjun Xie, Zhe Xue |
IEEE Trans. Big Data | 4 |
| 2015 | Mining Twitter as a First Step toward Assessing the Adequacy of Gender Identification Terms on Intake Forms
Amanda Hicks, William R. Hogan, Michael W. Rutherford, Bradley A. Malin, Mengjun Xie, Christiane Fellbaum, Zhijun Yin, Daniel Fabbri, Josh Hanna, Jiang Bian 0001 |
AMIA | 5 |
| 2015 | A Measurement Study on Media Streaming over Wi-Fi in Named Data NetworkingabstractNamed Data Networking (NDN), aka Content Centric Networking (CCN), excels in content distribution especially multimedia distribution, which can consume significant network bandwidth. With the market penetration of mobile devices and advancement of wireless technologies, media streaming over Wi-Fi becomes increasingly popular but it does not scale well in today's IP based networking. A natural question therefore is how to leverage NDN to improve and optimize media streaming over Wi-Fi. As a first step towards this problem, we set up a 5-node Wi-Fi media streaming test bed based on Wi-Fi Direct technology and use it to collect the bandwidth and CPU usage data when streaming media in NDN as well as in IP networking. We test 4 streaming scenarios in which a live video is streamed from one publisher to multiple consumers over Wi-Fi Direct and present our measurement results in this paper. Our experimental results indicate that the bandwidth consumption between a content publisher and its forwarder (i.e., Access point) over Wi-Fi can be effectively and dramatically reduced by NDN, offering much better scalability than IP. However, CPU usage can become much higher in NDN than in IP, which deserves further investigation and optimization. Samiuddin Mohammed, Mengjun Xie |
MASS | 2 |
| 2014 | Social network analysis of biomedical research collaboration networks in a CTSA institution
Jiang Bian 0001, Mengjun Xie, Umit Topaloglu, Teresa Hudson, Hari Eswaran, William R. Hogan |
J. Biomed. Informatics | 2 |
| 2014 | Pre-execution data prefetching with I/O scheduling
Yue Zhao 0014, Kenji Yoshigoe, Mengjun Xie |
J. Supercomput. | 3 |
| 2013 | Understanding biomedicai research collaborations through social network analysis: A case studyabstractA recent surge of research on social networks and their characteristics has attracted an increasing amount of interests from the community of biomedicine and biomedical informatics. Social network analysis (SNA) methods have been regarded as an effective tool to assess inter- and intra-institution research collaborations in the Clinical Translational Science Award (CTSA) community. In this paper, we present a case study of SNA on the research collaboration networks (RCNs) at the University of Arkansas for Medical Sciences (UAMS) - a CTSA institution. We have applied graph theoretical analyses to the RCNs prior to and after the CTSA award at UAMS. By virtue of quantitative measures, we have obtained valuable insights into the network dynamics and topological characteristics of the research environment. Moreover, through observing the temporal evolution of the RCNs at UAMS, we are able to demonstrate the effectiveness of the CTSA program and its important role in promoting trans-disciplinary collaborative research within an institution. Jiang Bian 0001, Mengjun Xie, Umit Topaloglu, Teresa Hudson, William R. Hogan |
BIBM | 2 |
| 2013 | SIM: A smartphone-based identity management framework and its application to Arkansas trauma image repositoryabstractSecure and convenient user identity management is particularly important to the success of EMR, EHR, and PHR systems. Unfortunately, widely-used identity management mechanisms that solely rely on username/password are inadequate to meet the strong security and privacy requirements for protecting sensitive user information and medical data. Two-factor authentication approaches that are more convenient and user friendly than existing solutions have been given top priority in the healthcare sector where the majority of healthcare practitioners and patients are not tech-savvy. In this paper, we present a smartphone-based identity management framework-SIM-to enhance the security and usability of user identity management in healthcare information systems. SIM leverages the popularity and computational power of smartphone. Within the SIM framework, a person employs a smartphone to centrally store and manage her identity credentials and authenticates herself to healthcare applications using two-factor authentication without typing any identity credentials. Moreover, SIM provides patients with a patient-controlled authorization mechanism to help patients manage the accesses to their PHRs in a secure and convenient manner. Using an existing EMR system-Arkansas Trauma Image Repository-as an example, we demonstrate that SIM can be applied to a real-world healthcare information system to enhance its protection of user credentials and sensitive information. Mengjun Xie, Umit Topaloglu, Thomas Powell 0003, Jiang Bian 0001 |
BIBM | 1 |
| 2013 | CamTalk: A Bidirectional Light Communications Framework for Secure Communications on Smartphones
Mengjun Xie, Kenji Yoshigoe, Jiang Bian 0001 |
SecureComm | 1 |
| 2012 | Enhancing cache robustness for content-centric networkingabstractWith the advent of content-centric networking (CCN) where contents can be cached on each CCN router, cache robustness will soon emerge as a serious concern for CCN deployment. Previous studies on cache pollution attacks only focus on a single cache server. The question of how caching will behave over a general caching network such as CCN under cache pollution attacks has never been answered. In this paper, we propose a novel scheme called CacheShield for enhancing cache robustness. CacheShield is simple, easy-to-deploy, and applicable to any popular cache replacement policy. CacheShield can effectively improve cache performance under normal circumstances, and more importantly, shield CCN routers from cache pollution attacks. Extensive simulations including trace-driven simulations demonstrate that CacheShield is effective for both CCN and today's cache servers. We also study the impact of cache pollution attacks on CCN and reveal several new observations on how different attack scenarios can affect cache hit ratios unexpectedly. Mengjun Xie, Indra Widjaja, Haining Wang 0001 |
INFOCOM | 1 |
| 2012 | Secure instant messaging in enterprise-like networks
Mengjun Xie, Zhenyu Wu 0003, Haining Wang 0001 |
Comput. Networks | 1 |
| 2012 | On Energy Security of Server SystemsabstractPower management has become increasingly important for server systems. Numerous techniques have been proposed and developed to optimize server power consumption and achieve energy proportional computing. However, the security perspective of server power management has not yet been studied. In this paper, we investigate energy attacks, a new type of malicious exploits on server systems. Targeted solely at abusing server power consumption, energy attacks exhibit very different attacking behaviors and cause very different victim symptoms from conventional cyberspace attacks. First, we unveil that today's server systems with improved power saving technologies are more vulnerable to energy attacks. Then, we demonstrate a realistic energy attack on a stand-alone server system in three steps: 1) by profiling energy cost of an open web service under different operation conditions, we identify the vulnerabilities that subject a server to energy attacks; 2) exploiting the discovered attack vectors, we design an energy attack that can be launched anonymously from remote; and 3) we execute the attack and measure the extent of its damage in a systematic manner. Finally, we highlight the challenges in defending against energy attacks, and we propose an effective defense scheme to meet the challenges and evaluate its effectiveness. Zhenyu Wu 0003, Mengjun Xie, Haining Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | A methodology for empirical analysis of brain connectivity through graph miningabstractGraph theoretical analysis has been applied to both structural and functional brain connectivity networks and has helped researchers conceive the effects of neurological and neuropsychiatric diseases including Alzhemier and Schizophrenia. However, existing graph theoretical approaches to brain connectivity networks simply assume that temporal correlations between brain regions are stable during the entire timeseries under consideration, and only focus on high-level network topological characteristics such as degree distribution. To advance the understanding of brain connectivity networks at a fine granularity, we propose a new method that can help discover connectivity-oriented insights from a time series of brain connectivity networks. In particular, our method is capable of identifying (1) strong correlations, which are represented as frequent edges in brain connectivity networks, for each individual subject, and (2) frequent substructures, which are connected components appearing frequently in brain connectivity networks, for a group of subjects. We apply the method to a data set of 38 subjects that were involved in a study of early life stress on depression development. Our findings have been echoed by the domain experts in terms of their clinical implications. Jiang Bian 0001, Josh M. Cisler, Mengjun Xie, George Andrew James, Remzi Seker, Clinton D. Kilts |
SMC | 3 |
| 2011 | Humans and Bots in Internet Chat: Measurement, Analysis, and Automated ClassificationabstractThe abuse of chat services by automated programs, known as chat bots, poses a serious threat to Internet users. Chat bots target popular chat networks to distribute spam and malware. In this paper, we first conduct a series of measurements on a large commercial chat network. Our measurements capture a total of 16 different types of chat bots ranging from simple to advanced. Moreover, we observe that human behavior is more complex than bot behavior. Based on the measurement study, we propose a classification system to accurately distinguish chat bots from human users. The proposed classification system consists of two components: 1) an entropy-based classifier; and 2) a Bayesian-based classifier. The two classifiers complement each other in chat bot detection. The entropy-based classifier is more accurate to detect unknown chat bots, whereas the Bayesian-based classifier is faster to detect known chat bots. Our experimental evaluation shows that the proposed classification system is highly effective in differentiating bots from humans. Steven Gianvecchio, Mengjun Xie, Zhenyu Wu 0003, Haining Wang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2011 | Design and Implementation of a Fast Dynamic Packet FilterabstractThis paper presents Swift, a packet filter for high-performance packet capture on commercial off-the-shelf hardware. The key features of the Swift include: 1) extremely low filter update latency for dynamic packet filtering, and 2) gigabits-per-second high-speed packet processing. Based on complex instruction set computer (CISC) instruction set architecture (ISA), Swift achieves the former with an instruction set design that avoids the need for compilation and security checking, and the latter by mainly utilizing single instruction, multiple data (SIMD). We implement Swift in the Linux 2.6 kernel for both i386 and x86_64 architectures and extensively evaluate its dynamic and static filtering performance on multiple machines with different hardware setups. We compare Swift to BPF (the BSD packet filter)-the de facto standard for packet filtering in modern operating systems-and hand-coded optimized C filters that are used for demonstrating possible performance gains. For dynamic filtering tasks, Swift is at least three orders of magnitude faster than BPF in terms of filter update latency. For static filtering tasks, Swift outperforms BPF up to three times in terms of packet processing speed and achieves much closer performance to the optimized C filters. We also show that Swift can harness the processing power of hardware SIMD instructions by virtue of its SIMD-capable instruction set. Zhenyu Wu 0003, Mengjun Xie, Haining Wang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2010 | Mimimorphism: a new approach to binary code obfuscationabstractBinary obfuscation plays an essential role in evading malware static analysis and detection. The widely used code obfuscation techniques, such as polymorphism and metamorphism, focus on evading syntax based detection. However, statistic test and semantic analysis techniques have been developed to thwart their evasion attempts. More recent binary obfuscation techniques are divided in their purposes of attacking either statistical or semantic approach, but not both. In this paper, we introduce mimimorphism, a novel binary obfuscation technique with the potential of evading both statistical and semantic detections. Mimimorphic malware uses instruction-syntax-aware high-order mimic functions to transform its binary into mimicry executables that exhibit high similarity to benign programs in terms of statistical properties and semantic characteristics. We implement a prototype of the mimimorphic engine on the Intel x86 platform, and evaluate its capability of evading statistical anomaly detection and semantic analysis detection techniques. Our experimental results demonstrate that the mimicry executables are indistinguishable from benign programs in terms of byte frequency distribution and entropy, as well as control flow fingerprint. Zhenyu Wu 0003, Steven Gianvecchio, Mengjun Xie, Haining Wang 0001 |
CCS | 3 |
| 2010 | A Collaboration-based Autonomous Reputation System for Email ServicesabstractThis paper presents CARE, an autonomous email reputation system based on inter-domain collaboration. Within the framework of CARE, each domain independently builds its reputation database based on both the local email history and the information exchanged with other collaborating domains. CARE examines the trustworthiness of the email histories obtained from collaborators by correlating them with the local email history. To validate the efficacy of CARE, we have analyzed real email logs, conducted a DNS-based estimation experiment, and performed a series of simulations. Our experimental results show that CARE can effectively improve the reliability and performance of email systems. Mengjun Xie, Haining Wang 0001 |
INFOCOM | 1 |
| 2010 | An automatic HTTP cookie management system
Chuan Yue, Mengjun Xie, Haining Wang 0001 |
Comput. Networks | 2 |
| 2009 | Battle of Botcraft: fighting bots in online games with human observational proofsabstractThe abuse of online games by automated programs, known as game bots, for gaining unfair advantages has plagued millions of participating players with escalating severity in recent years. The current methods for distinguishing bots and humans are based on human interactive proofs (HIPs), such as CAPTCHAs. However, HIP-based approaches have inherent drawbacks. In particular, they are too obtrusive to be tolerated by human players in a gaming context. In this paper, we propose a non-interactive approach based on human observational proofs (HOPs) for continuous game bot detection. HOPs differentiate bots from human players by passively monitoring input actions that are difficult for current bots to perform in a human-like manner. We collect a series of user-input traces in one of the most popular online games, World of Warcraft. Based on the traces, we characterize the game playing behaviors of bots and humans. Then, we develop a HOP-based game bot defense system that analyzes user-input actions with a cascade-correlation neural network to distinguish bots from humans. The HOP system is effective in capturing current game bots, which raises the bar against game exploits and forces a determined adversary to build more complicated game bots for detection evasion in the future. Steven Gianvecchio, Zhenyu Wu 0003, Mengjun Xie, Haining Wang 0001 |
CCS | 3 |
| 2008 | Swift: A Fast Dynamic Packet Filter
Zhenyu Wu 0003, Mengjun Xie, Haining Wang 0001 |
NSDI | 2 |
| 2008 | Measurement and Classification of Humans and Bots in Internet Chat
Steven Gianvecchio, Mengjun Xie, Zhengyu Wu, Haining Wang 0001 |
USENIX Security Symposium | 2 |
| 2008 | Thwarting E-mail Spam LaunderingabstractLaundering e-mail spam through open-proxies or compromised PCs is a widely-used trick to conceal real spam sources and reduce spamming cost in the underground e-mail spam industry. Spammers have plagued the Internet by exploiting a large number of spam proxies. The facility of breaking spam laundering and deterring spamming activities close to their sources, which would greatly benefit not only e-mail users but also victim ISPs, is in great demand but still missing. In this article, we reveal one salient characteristic of proxy-based spamming activities, namely packet symmetry, by analyzing protocol semantics and timing causality. Based on the packet symmetry exhibited in spam laundering, we propose a simple and effective technique, DBSpam, to online detect and break spam laundering activities inside a customer network. Monitoring the bidirectional traffic passing through a network gateway, DBSpam utilizes a simple statistical method, Sequential Probability Ratio Test, to detect the occurrence of spam laundering in a timely manner. To balance the goals of promptness and accuracy, we introduce a noise-reduction technique in DBSpam, after which the laundering path can be identified more accurately. Then DBSpam activates its spam suppressing mechanism to break the spam laundering. We implement a prototype of DBSpam based on libpcap , and validate its efficacy on spam detection and suppression through both theoretical analyses and trace-based experiments. Mengjun Xie, Heng Yin 0001, Haining Wang 0001 |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2007 | HoneyIM: Fast Detection and Suppression of Instant Messaging Malware in Enterprise-Like NetworksabstractInstant messaging (IM) has been one of most frequently used malware attack vectors due to its popularity. Distinct from other malware, it is straightforward for IM malware to find and hit the next victim by exploiting the current victim's contact list and playing social engineering tricks. Thus, the spread of IM malware is much harder to detect and suppress through conventional approaches. The previous solutions are ineffective to defend against IM malware in an enterprise-like network environment, mainly because of high false positive rate and the requirement of the IM server being inside the protected network. In this paper, we propose a novel IM malware detection and suppression mechanism, HoneyIM, which guarantees almost zero false positive on detecting and blocking IM malware in an enterprise-like network. The detection of HoneyIM is based on the concept of honeypot. HoneyIM uses decoy accounts to trap IM malware by leveraging malware spreading characteristics. Fed with accurate detection results, the suppression of HoneyIM can conduct a network-wide blocking. In addition, HoneyIM delivers attack information to network administrators in real-time so that system quarantine and recovery can be quickly performed. The core design of HoneyIM is generic, and can be applied to the scenarios that either enterprise IM services or public IM services are used in the protected network. Based on open-source IM client Pidgin and client honeypot Capture, we build a prototype of HoneyIM and validate its efficacy through both simulations and real experiments. Our results show that HoneyIM provides effective protection against IM malware in enterprise-like networks. Mengjun Xie, Zhenyu Wu 0003, Haining Wang 0001 |
ACSAC | 1 |
| 2007 | Automatic Cookie Usage Setting with CookiePickerabstractHTTP cookies have been widely used for maintaining session states, personalizing, authenticating, and tracking user behaviors. Despite their importance and usefulness, cookies have raised public concerns on Internet privacy because they can be exploited by Web sites to track and build user profiles. In addition, stolen cookies may also incur security problems. However, current web browsers lack secure and convenientmechanisms for cookie management. A cookie management scheme, which is easy-to-use and has minimal privacy risk, is in great demand; but designing such a scheme is a challenge. In this paper, we introduce CookiePicker, a system that can automatically validate the usefulness of cookies from a Web site and set the cookie usage permission on behalf of users. CookiePicker helps users achieve the maximum benefit brought by cookies, while minimizing the possible privacy and security risks. We implement CookiePicker as an extension to Firefox Web browser, and obtain promising results in the experiments. Chuan Yue, Mengjun Xie, Haining Wang 0001 |
DSN | 2 |
| 2006 | An effective defense against email spam launderingabstractLaundering email spam through open-proxies or compromised PCs is a widely-used trick to conceal real spam sources and reduce spamming cost in underground email spam industry. Spammers have been plaguing the Internet by exploiting a large number of spam proxies. The facility of breaking spam laundering and deterring spamming activities close to their sources, which would greatly benefit not only email users but also victim ISPs, is in great demand but still missing. In this paper, we reveal one salient characteristic of proxy-based spamming activities, namely packet symmetry, by analyzing protocol semantics and timing causality. Based on the packet symmetry exhibited in spam laundering, we propose a simple and effective technique, DBSpam, to on-line detect and break spam laundering activities inside a customer network. Monitoring the bi-directional traffic passing through a network gateway, DBSpam utilizes a simple statistical method, Sequential Probability Ratio Test, to detect the occurrence of spam laundering in a timely manner. To balance the goals of promptness and accuracy, we introduce a noise-reduction technique in DBSpam, after which the laundering path can be identified more accurately. Then, DBSpam activates its spam suppressing mechanism to break the spam laundering. We implement a prototype of DBSpam based on libpcap, and validate its efficacy through both theoretical analyses and trace-based experiments. Mengjun Xie, Heng Yin 0001, Haining Wang 0001 |
CCS | 1 |