Measurement and evaluation of a real world deployment of a challenge-response spam filter

Isacenkova, Jelena; Balzarotti, Davide
IMC 2011, 11th ACM SIGCOMM Internet Measurement Conference, November 2-4, 2011, Berlin, Germany

Despite the number of existing solutions, spam still accounts for a large percentage of the email traffic on the Internet. Both the effectiveness and the impact of many common anti-spam techniques have already been largely studied and evaluated against multiple datasets. However, some of the less known solutions still lack a proper experimental validation. For example, Challenge-Response (CR) systems have been largely discussed, and often criticized, because they shift the effort to protect the user's mailbox from the recipient to the sender of the messages. In addition, these systems are believed to produce a lot of backscattered emails that further deteriorate the global Internet situation.

In this paper we present the first comprehensive measurement study of a real anti-spam system based on a challenge-response technique. In our work we analyze a large amount of data, collected for a period of six months from over forty companies protected by a commercial challenge-response product. We designed our experiments from three different point of views: the end user, the system administrator, and the entire Internet community. Our results cover many different aspects such as the amount of challenges sent, the delay on the message delivery, and the likelihood of getting the challenge server blacklisted.

Our aim is neither to attack nor to defend CR-based solutions. Instead, we hope that our findings will shed some light on some of the myths about these kind of systems, and will help both users and companies to take an informed decision on the topic.

 


DOI
HAL
Type:
Conférence
City:
Berlin
Date:
2011-11-02
Department:
Sécurité numérique
Eurecom Ref:
3500
Copyright:
© ACM, 2011. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in IMC 2011, 11th ACM SIGCOMM Internet Measurement Conference, November 2-4, 2011, Berlin, Germany
http://dx.doi.org/10.1145/2068816.2068855

PERMALINK : https://www.eurecom.fr/publication/3500