• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

A Protection Method against Denial of Service Attack Caused by Sender Spoofed Spam Mails

Research Project

Project/Area Number 15500039
Research Category

Grant-in-Aid for Scientific Research (C)

Allocation TypeSingle-year Grants
Section一般
Research Field Computer system/Network
Research InstitutionOKAYAMA UNIVERSITY

Principal Investigator

YAMAI Nariyoshi  OKAYAMA UNIVERSITY, Information Technology Center, Associate Professor, 総合情報基盤センター, 助教授 (90210319)

Co-Investigator(Kenkyū-buntansha) NAKAMURA Motonori  Kyoto University, ACCMS, Associate Professor, 学術情報メディアセンター, 助教授 (30268156)
MIYASHITA Takuya  OKAYAMA UNIVERSITY, Information Technology Center, Research Associate, 総合情報基盤センター, 助手 (70304300)
OKAYAMA Kiyohiko  OKAYAMA UNIVERSITY, Faculty of Engineering, Research Associate, 工学部, 助手 (20252588)
Project Period (FY) 2003 – 2004
Project Status Completed (Fiscal Year 2004)
Budget Amount *help
¥3,600,000 (Direct Cost: ¥3,600,000)
Fiscal Year 2004: ¥1,000,000 (Direct Cost: ¥1,000,000)
Fiscal Year 2003: ¥2,600,000 (Direct Cost: ¥2,600,000)
KeywordsE-mail / spam mail / Denial of Service attack / mail server / DNS / load sharing / spamメール / SPAMメール / ネームサーバ
Research Abstract

This research project aims to develop a protection method against Denial Service (DoS) attack to victim mail servers, by means of massive error mails generated by sender spoofed spam mails. We have developed the following functions.
1.Early detection of DoS attacks
We have verified two early detection methods of DoS attack, namely monitoring DNS query frequency and counting the number of error mails received. According to the attack log of a mail server of Okayama University in August 2004, we have confirmed that both methods are effective for early detection.
2.Load sharing of error mail handling among mail servers
We have developed a processing method to separate error mails from normal mails, depending on existence of MX record cache. According to the attack log in August 2004, we have confirmed that this method is effective for load sharing. We also have developed a priority control method of mail delivery from specified mail servers, by giving a different MX record to each DNS query.
3.Speeding up of error mail processing
We have developed a speeding up method of error mail processing, not by discarding after receiving, but by rejecting all mails with null sender address during DoS attack.
4.Processing of complaint mails
We have developed a method to distinguish complaint mails using a distributed spam database. In this method normal mails including the attacking spam mail are processed as complaint mails.
5.Identification of spam sender
We have developed a sender identification system which finds out the IP address of the spam sender and, if the sender exists on the inside network, pinpoints the location of spam sender to an accuracy of room level. We also developed an operation method of e-mail systems based on "POP before SMTP", applicable even to large scale organizations that introduce a mail gateway.

Report

(3 results)
  • 2004 Annual Research Report   Final Research Report Summary
  • 2003 Annual Research Report
  • Research Products

    (29 results)

All 2006 2005 2004 2003 Other

All Journal Article (25 results) Publications (4 results)

  • [Journal Article] Priority Control in Receiving E-mails by Giving a Separate Response to Each DNS Query2006

    • Author(s)
      Shin Maruyama
    • Journal Title

      Proceedings of The 2005 Symposium on Applications and the Internet(SAINT2006)

      Pages: 90-93

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 発信者詐欺spamメールに起因するバウンスメール集中への対策方法2006

    • Author(s)
      山井成良
    • Journal Title

      情報処理学会論文誌 47(印刷中)

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 動的に応答を変えるDNSを利用した電子メール受信の優先制御2006

    • Author(s)
      丸山伸
    • Journal Title

      情報処理学会論文誌 47(印刷中)

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] Priority Control in Receiving E-mails by Giving a Separate Response to Each DNS Query2006

    • Author(s)
      Shin MARUYAMA
    • Journal Title

      Proceedings of the 2006 Symposium on Applications and the Internet (SAINT2006)

      Pages: 90-93

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Protection Method against Massive Bounce Mails Caused by Sender Spoofed Spam Mails2006

    • Author(s)
      Nariyoshi YAMAI
    • Journal Title

      IPSJ Journal Vol.47,No.4(to appear)

    • NAID

      110004734698

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] Priority Control in Receiving E-mails by Giving a Separate Response to Each DNS Query2006

    • Author(s)
      Shin MARUYAMA
    • Journal Title

      IPSJ Journal Vol.47,No.4(to appear)

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Protection Method against Massive Error Mails Caused by Sender Spoofed Spam Mails2005

    • Author(s)
      Nariyoshi Yamai
    • Journal Title

      Proceedings of The 2005 Symposium on Applications and the Internet(SAINT2005)

      Pages: 384-390

    • NAID

      120006658706

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 大規模組織におけるPOP before SMTPに基づく管理の容易な電子メールシステム運用方法2005

    • Author(s)
      山井成良
    • Journal Title

      情報処理学会論文誌 46

      Pages: 1041-1050

    • NAID

      110002768607

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 宛先不明メールを利用した分散協調型spamフィルタの認識率向上2005

    • Author(s)
      漣一平
    • Journal Title

      情報処理学会 分散システム/インターネット運用技術研究会研究報告 2004-DSM-37

      Pages: 79-84

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Protection Method against Massive Error Mails Caused by Sender Spoofed Spam Mails2005

    • Author(s)
      Nariyoshi YAMAI
    • Journal Title

      Proceedings of the 2005 Symposium on Applications and the Internet (SAINT2005)

      Pages: 384-390

    • NAID

      120006658706

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] An Operation Method of E-mail Systems for Large Scale Organizations Based on "POP before SMTP" with Minimal Administration2005

    • Author(s)
      Nariyoshi YAMAI
    • Journal Title

      IPSJ Journal Vol.46,No.4

      Pages: 1041-1050

    • NAID

      110002768607

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] An Accuracy Improvement Method of Distributed Cooperative Spam Filter Using Invalid Recipient Mail2005

    • Author(s)
      Ippei SAZANAMI
    • Journal Title

      IPSJ SIG Technical Report 2005-DSM-37

      Pages: 79-84

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Protection Method against Massive Error Mails Caused by Sender Spoofed Spam Mails2005

    • Author(s)
      Nariyoshi Yamai
    • Journal Title

      Proceedings of The 2005 Symposium on Applications and the Internet (SAINT2005)

      Pages: 384-390

    • NAID

      120006658706

    • Related Report
      2004 Annual Research Report
  • [Journal Article] 利用者間協調に基づくspamメール発信源の特定2005

    • Author(s)
      大石祥雄
    • Journal Title

      岡山理科大学工学部電子工学科特別研究報告

    • Related Report
      2004 Annual Research Report
  • [Journal Article] 遅延評価による分散協調型spamフィルタの検出率向上2004

    • Author(s)
      漣一平
    • Journal Title

      情報処理学会 コンピュータセキュリティ研究会研究報告 2003-CSEC-24

      Pages: 139-144

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 動的に応答が変化するネームサーバー技術のメール配送エージェントへの応用2004

    • Author(s)
      丸山伸
    • Journal Title

      情報処理学会 分散システム/インターネット運用技術研究会研究報告 2004-DSM-32

      Pages: 79-84

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 発信者詐欺spamメールに起因するエラーメール集中への対応手法2004

    • Author(s)
      山井成良
    • Journal Title

      情報科学技術フォーラム情報技術レターズ 3

      Pages: 313-316

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 差出人詐欺型ウィルスメールの発信源自動追跡2004

    • Author(s)
      大隈淑弘
    • Journal Title

      情報処理学会 分散システム/インターネット運用技術研究会研究報告 2004-DSM-35

      Pages: 53-58

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Dynamic Modification on DNS Response and its Application on Mail Transfer Agent2004

    • Author(s)
      Shin MARUYAMA
    • Journal Title

      IPSJ SIG Technical Report 2004-DSM-32

      Pages: 79-84

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Protection Method against Massive Error Mails Caused by Sender Spoofed Spam Mails2004

    • Author(s)
      Nariyoshi YAMAI
    • Journal Title

      Information Technology Letters Vol.3

      Pages: 313-316

    • NAID

      120006658706

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] Automatic Sender Tracing of Virus E-mails with Spoofed Sender Addresses2004

    • Author(s)
      Yoshihiro OOSUMI
    • Journal Title

      IPSJ SIG Technical Report 2004-DSM-25

      Pages: 53-58

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] 発信者詐称spamメールに起因するエラーメール集中への対策手法2004

    • Author(s)
      山井成良
    • Journal Title

      情報科学技術フォーラム情報技術レターズ 3

      Pages: 313-316

    • Related Report
      2004 Annual Research Report
  • [Journal Article] POP beforeに基づく大規模組織に適した電子メール不正中継対策2003

    • Author(s)
      繁田展史
    • Journal Title

      情報処理学会 マルチメディア,分散,協調とモバイル(DICOMO 2003)シンポジウム論文集

      Pages: 813-816

    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] A Third-party Relay Countermeasures of E-mail based on POP before SMTP for Large-scale Organizations2003

    • Author(s)
      Nobufumi SHIGETA
    • Journal Title

      IPSJ Symposium Series Vol.2003,No.9

      Pages: 813-816

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Journal Article] An Accuracy Improvement Method of Distributed Cooperative Spam Filter Using Delayed Evaluation Technique2003

    • Author(s)
      Ippei SAZANAMI
    • Journal Title

      IPSJ SIG Technical Report 2003-CSEC-24

      Pages: 139-144

    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2004 Final Research Report Summary
  • [Publications] 繁田展史: "発信者詐称spamメールに起因するエラーメール集中への対策"岡山大学大学院自然科学研究科博士前期課程修士学位論文. (2004)

    • Related Report
      2003 Annual Research Report
  • [Publications] 漣 一平: "遅延評価による分散協調型spamフィルタの検出率向上"岡山大学工学部通信ネットワーク工学科特別研究報告書. (2004)

    • Related Report
      2003 Annual Research Report
  • [Publications] 漣 一平: "遅延評価による分散協調型spamフィルタの検出率向上"情報処理学会研究報告. 2003-DPS・117. 139-144 (2004)

    • Related Report
      2003 Annual Research Report
  • [Publications] 丸山 伸: "動的に応答が変化するネームサーバー技術のメール配送エージェントへの応用"情報処理学会研究報告. 2003-DSM・32(発表予定). (2004)

    • Related Report
      2003 Annual Research Report

URL: 

Published: 2003-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi