针对目前垃圾邮件制造者不断利用新技术和新方法,使垃圾邮件的内容和发送手段等都发生了明显的变化,对传统基于内容的反垃圾邮件技术提出了严峻挑战的问题,提出了一种主动式的垃圾邮件行为识别技术。通过分析当前垃圾邮件的通信行为和MTA通信原理,提出了追踪源头认证、信誉验证和质询验证行为识别技术,详细阐述了它们在MTA通信连接的不同阶段对垃圾邮件进行识别与拦截的方法,并给出了整个行为识别算法。最后设计了一个可扩展性良好的垃圾邮件过滤网关并进行了实验。实验结果表明,提出的识别技术真正实现了与内容无关、语言类型无关的邮件实时过滤,并具有良好的效率和准确率。
Aiming at many of spam makers applied constantly the new technology and approach both to make spare and send spam, witch were challenging the traditional technique of anti-spam based on e-mail content. This paper proposed a kind of active of spam behavior identify technology through analyzing the characteristic of communication behavior of the current spam and the communication principle of MTA. It comprised the technique of track source authentication, credibility authentication, and interrogatory authentication. This paper fully expounded their method of identifying and holding up spam in different phase of MTA 9ommunication conjunction, and presented the algorithm of behavior identify. At the end, designed a spam filter gateway that it had good extensibility, and had fulfilled the experiment. The result of experiment indicates that the technology of spam behavior identify has high-performance and high-accuracy, and it is really to realize real-time filter spam that it is irrelevant to the content and language type of spam.