Anomaly Detection in Emails using Machine Learning and Header Information
Anomalies in emails such as phishing and spam present major security risks such as the loss of privacy, money, and brand reputation to both individuals and organizations. Previous studies on email anomaly detection relied on a single type of anomaly and the analysis of the email body and subject content. A drawback of this approach is that it takes into account the written language of the email content. To overcome this deficit, this study conducted feature extraction and selection on email header datasets and leveraged both multi and one-class anomaly detection approaches. Experimental analysis results obtained demonstrate that email header information only is enough to reliably detect spam and phishing emails. Supervised learning algorithms such as Random Forest, SVM, MLP, KNN, and their stacked ensembles were found to be very successful, achieving high accuracy scores of 97% for phishing and 99% for spam emails. One-class classification with One-Class SVM achieved accuracy scores of 87% and 89% with spam and phishing emails, respectively. Real-world email filtering applications will benefit from the use of only the header information in terms of resources utilization and efficiency.
Code (1)
Tasks
Anomaly DetectionBIG-bench Machine LearningOne-Class ClassificationMethods 이 논문이 사용한 방법론
Similar Papers 제목 키워드 기반
EMFET: E-mail Features Extraction Tool
EMFET is an open source and flexible tool that can be used to extract a large number of features from any email corpus with emails saved in EML format. The extracted features can be categorized into three main groups: he…
BIG-bench Machine LearningSpam detectionImplementing Active Learning in Cybersecurity: Detecting Anomalies in Redacted Emails
Research on email anomaly detection has typically relied on specially prepared datasets that may not adequately reflect the type of data that occurs in industry settings. In our research, at a major financial services co…
Active LearningAnomaly DetectionHolmes: An Efficient and Lightweight Semantic Based Anomalous Email Detector
Email threat is a serious issue for enterprise security, which consists of various malicious scenarios, such as phishing, fraud, blackmail and malvertisement. Traditional anti-spam gateway commonly requires to maintain a…
Anomaly DetectionNovelty DetectionSentenceSpam Detection Using BERT
Emails and SMSs are the most popular tools in today communications, and as the increase of emails and SMSs users are increase, the number of spams is also increases. Spam is any kind of unwanted, unsolicited digital comm…
Spam detectionFederated Semi-Supervised Classification of Multimedia Flows for 3D Networks
Automatic traffic classification is increasingly becoming important in traffic engineering, as the current trend of encrypting transport information (e.g., behind HTTP-encrypted tunnels) prevents intermediate nodes from …
Anomaly Detectionfeature selectionIntrusion DetectionManagement+1