2003
DOI: 10.1007/3-540-44853-5_6
|View full text |Cite
|
Sign up to set email alerts
|

Behavior Profiling of Email

Abstract: This paper describes the forensic and intelligence analysis capabilities of the Email Mining Toolkit (EMT) under development at the Columbia Intrusion Detection (IDS) Lab. EMT provides the means of loading, parsing and analyzing email logs, including content, in a wide range of formats. Many tools and techniques have been available from the fields of Information Retrieval (IR) and Natural Language Processing (NLP) for analyzing documents of various sorts, including emails. EMT, however, extends these kinds of … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
29
0
1

Year Published

2004
2004
2020
2020

Publication Types

Select...
4
3
2

Relationship

0
9

Authors

Journals

citations
Cited by 40 publications
(30 citation statements)
references
References 4 publications
0
29
0
1
Order By: Relevance
“…Stolfo et al presented Email Mining Toolkit (EMT) [29,30]. This tool mines email logs to find cliques of users who frequently contact each other.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…Stolfo et al presented Email Mining Toolkit (EMT) [29,30]. This tool mines email logs to find cliques of users who frequently contact each other.…”
Section: Related Workmentioning
confidence: 99%
“…Techniques that leverage the similarities in the email templates or fingerprint the email lists to which bots send emails [24,32,43] work well in detecting spam and bot-infected machines, but fall short in detecting one-of-a-kind targeted email attacks, in which an attacker crafts an email tailored to the victim, and sends it only once. Even systems that look for changes of behavior in email accounts leverage the fact that accounts compromised by the same cybercriminals will show a similar behavior [10,29,30].…”
Section: Introductionmentioning
confidence: 99%
“…The studies in [28], [29] focus on communication patterns or profiles of applications instead of broader network traffic. Concurrent with our work, [30], [31] are most similar in spirit, and in a sense are complementary, to ours.…”
Section: Related Workmentioning
confidence: 99%
“…The Email Mining Toolkit (EMT) [13] provides interaction metrics while [4] aims at extracting the underlying activity structure. However all of these lack the notion of applied resources (e.g.…”
Section: Related Workmentioning
confidence: 99%