{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T18:01:22Z","timestamp":1754157682309,"version":"3.41.2"},"reference-count":31,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2012,10,5]],"date-time":"2012-10-05T00:00:00Z","timestamp":1349395200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,10,5]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>IP reputation systems, which filter e\u2010mail based on the sender's IP address, are located at the perimeter \u2013 before the messages reach the mail server's anti\u2010spam filters. To increase IP reputation system efficacy and overcome the shortcomings of individual IP\u2010based filtering, recent studies have suggested exploiting the properties of IP clusters, such as those of Autonomous Systems (AS). Cluster\u2010based techniques can enhance accuracy and reduce false negative rates. However, clusters generally contain enormous amounts of IP addresses, which hinder cluster\u2010based systems from reaching their full spam filtering potential. The purpose of this paper is exploitation of social network metrics to obtain a more granular, i.e. sub\u2010divided, view of cluster\u2010based reputation, and thus enhance spam filtering accuracy.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>The authors examined the performance of various social network metrics, including nodal degree, betweenness centrality, closeness centrality and valued graphs, to find an optimal element that enhances IP reputation prediction in AS clusters.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>It was found that all measures contributed to prediction, yet the best predictor of spam reputation was the out\u2010degree metric, which showed a strong positive correlation with spam reputation prediction. This implies that more granular information can increase the accuracy of IP reputation prediction in AS clusters.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>Used in conjunction with other technologies, the granular cluster\u2010based reputation system can be a valuable addition to commercial and open\u2010source spam filtering systems, or to standalone DNS\u2010based blacklists.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>The authors' approach can promote mitigation of larger spam volumes at the perimeter, save bandwidth, and conserve valuable system resources.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685221211267657","type":"journal-article","created":{"date-parts":[[2013,3,25]],"date-time":"2013-03-25T11:48:24Z","timestamp":1364212104000},"page":"281-295","source":"Crossref","is-referenced-by-count":5,"title":["Social network analysis for cluster\u2010based IP spam reputation"],"prefix":"10.1108","volume":"20","author":[{"given":"Zac","family":"Sadan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David G.","family":"Schwartz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022021220274880900_b25","unstructured":"BarracudaCentral (2011), available at: www.barracudacentral.org (accessed 5 August)."},{"key":"key2022021220274880900_b1","unstructured":"Batagelj, V. and Mrvar, A. (1998), \u201cPajek \u2013 a program for large network analysis\u201d, Connections, Vol. 21, pp. 47\u201057."},{"key":"key2022021220274880900_b2","doi-asserted-by":"crossref","unstructured":"Boykin, P.O. and Roychowdhury, V.P. (2005), \u201cLeveraging social networks to fight spam\u201d, IEEE Computer, Vol. 38 No. 4, pp. 61\u20108.","DOI":"10.1109\/MC.2005.132"},{"key":"key2022021220274880900_b3","unstructured":"Carrara, E. and Hogben, G. (2007), \u201cReputation\u2010based systems: a security analysis\u201d, European Network and Information Security Agency Position Paper No. 2."},{"key":"key2022021220274880900_b4","doi-asserted-by":"crossref","unstructured":"Castillo, C., Donato, D., Gionis, A., Murdock, V. and Silvestri, F. (2007), \u201cKnow your neighbors: web spam detection using the web topology\u201d, Proceedings of the 30th Annual International ACM SIGIR Conference on Research and Development in Information Retrieval, Amsterdam, The Netherlands, pp. 423\u201030.","DOI":"10.1145\/1277741.1277814"},{"key":"key2022021220274880900_b5","doi-asserted-by":"crossref","unstructured":"Chirita, P.A., Diederich, J. and Nejdl, W. (2005), \u201cMailRank: using ranking for spam detection\u201d, Proceedings of the 14th ACM International Conference on Information and Knowledge Management, Bremen, Germany, pp. 373\u201080.","DOI":"10.1145\/1099554.1099671"},{"key":"key2022021220274880900_b6","doi-asserted-by":"crossref","unstructured":"Cormack, G.V. and Lynam, T.R. (2007), \u201cOnline supervised spam filter evaluation\u201d, ACM Transactions on Information Systems (TOIS), Vol. 25 No. 3, pp. 11\u2010es.","DOI":"10.1145\/1247715.1247717"},{"key":"key2022021220274880900_b7","doi-asserted-by":"crossref","unstructured":"Ebel, H., Mielsch, L.I. and Bornholdt, S. (2002), \u201cScale\u2010free topology of e\u2010mail networks\u201d, Phys. Rev. E, Vol. 66 No. 3, pp. 1\u20104.","DOI":"10.1103\/PhysRevE.66.035103"},{"key":"key2022021220274880900_b30","unstructured":"Federal Rules of Civil Procedure (2011), available at: www.uscourts.gov\/uscourts\/RulesAndPolicies\/rules\/2010%20Rules\/Civil%20Procedure.pdf (accessed 20 August)."},{"key":"key2022021220274880900_b8","doi-asserted-by":"crossref","unstructured":"Freeman, L. (1979), \u201cCentrality in social networks: I. Conceptual clarification\u201d, Social Networks, Vol. 1, pp. 215\u201039.","DOI":"10.1016\/0378-8733(78)90021-7"},{"key":"key2022021220274880900_b31","unstructured":"FSA Policy Statement (2011), available at: www.fsa.gov.uk\/pubs\/policy\/ps08_01.pdf (accessed 20 August)."},{"key":"key2022021220274880900_b9","unstructured":"Garriss, S., Kaminsky, M., Freedman, M.J., Karp, B., Mazieres, D. and Yu, H. (2006), \u201cRE: reliable email\u201d, Proceedings of the 3rd Symposium on Networked Systems Design and Implementation, San Jose, CA."},{"key":"key2022021220274880900_b10","doi-asserted-by":"crossref","unstructured":"Gloor, P.A. (2007), \u201cCoolhunting for trends on the web\u201d, Proc. IEEE International Symposium on Collaborative Technologies and Systems, Orlando, FL, pp. 1\u20108.","DOI":"10.1109\/CTS.2007.4621731"},{"key":"key2022021220274880900_b11","unstructured":"Golbeck, J. and Hendler, J. (2004), \u201cReputation network analysis for email filtering\u201d, Proceedings of the First Conference on Email and Anti\u2010Spam, Mountain View, CA, pp. 54\u20108."},{"key":"key2022021220274880900_b12","unstructured":"Hao, S., Syed, N.A., Feamster, N., Gray, A.G. and Krasser, S. (2009), \u201cDetecting spammers with SNARE: spatio\u2010temporal network\u2010level automatic reputation engine\u201d, SSYM'09 Proceedings of the 18th Conference on USENIX Security Symposium, Montreal, Canada, pp. 101\u201018."},{"key":"key2022021220274880900_b13","doi-asserted-by":"crossref","unstructured":"Krishnamurthy, B. and Wang, J. (2000), \u201cOn network\u2010aware clustering of web clients\u201d, ACM SIGCOMM Computer Communication Review, Vol. 30 No. 4, pp. 97\u2010110.","DOI":"10.1145\/347057.347412"},{"key":"key2022021220274880900_b14","unstructured":"Qian, Z., Mao, Z.M., Xie, Y. and Yu, F. (2010), \u201cOn network\u2010level clusters for spam detection\u201d, Proceedings of the 17th USENIX Annual Network and Distributed System Security Symposium, San Diego, CA."},{"key":"key2022021220274880900_b15","doi-asserted-by":"crossref","unstructured":"Ramachandran, A. and Feamster, N. (2006), \u201cUnderstanding the network\u2010level behavior of spammers\u201d, ACM SIGCOMM Computer Communication Review, Vol. 36 No. 4.","DOI":"10.1145\/1151659.1159947"},{"key":"key2022021220274880900_b16","doi-asserted-by":"crossref","unstructured":"Resnick, P., Zeckhauser, R., Friedman, E. and Kuwabara, K. (2000), \u201cReputation systems\u201d, Communications of the ACM, Vol. 43 No. 12, pp. 45\u20108.","DOI":"10.1145\/355112.355122"},{"key":"key2022021220274880900_b17","unstructured":"Roberts, F. (1976), Graph Theory and Its Applications to Problems of Society, Society for Industrial and Applied Mathematics, Philadelphia, PA."},{"key":"key2022021220274880900_b18","doi-asserted-by":"crossref","unstructured":"Sadan, Z. and Schwartz, D. (2010), \u201cWhiteScript: using social network analysis parameters to balance between browser usability and malware exposure\u201d, Computers & Security, Vol. 30 No. 1, pp. 4\u201012.","DOI":"10.1016\/j.cose.2010.10.001"},{"key":"key2022021220274880900_b26","unstructured":"SenderBase (2011), available at: www.senderbase.org (accessed 20 August)."},{"key":"key2022021220274880900_b28","unstructured":"Spamcop (2011), available at: www.spamcop.net\/ (accessed 12 August)."},{"key":"key2022021220274880900_b29","unstructured":"Spamhaus (2011), available at: www.spamhaus.org\/ (accessed 12 August)."},{"key":"key2022021220274880900_b24","unstructured":"Symantec Report (2011), available at: www.symanteccloud.com\/mlireport\/MLI_2011_03_March_Final\u2010EN.pdf (accessed 5 August)."},{"key":"key2022021220274880900_b27","unstructured":"TrustedSource (2011), available at: www.trustedsource.org (accessed 5 August)."},{"key":"key2022021220274880900_b19","unstructured":"Venkataraman, S., Sen, S., Spatscheckf, O., Haffnerf, P. and Song, D. (2007), \u201cExploiting network structure for proactive spam mitigation\u201d, Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, pp. 149\u201066."},{"key":"key2022021220274880900_b20","doi-asserted-by":"crossref","unstructured":"Wasserman, S. and Faust, K. (1994), Social Networks Analysis: Methods and Applications, Cambridge University Press, Cambridge.","DOI":"10.1017\/CBO9780511815478"},{"key":"key2022021220274880900_b21","unstructured":"Wasserman, S. and Faust, K. (2007), Social Networks Analysis: Methods and Applications, Cambridge University Press, Cambridge."},{"key":"key2022021220274880900_b22","doi-asserted-by":"crossref","unstructured":"Watts, D.J. and Strogatz, S.H. (1998), \u201cCollective dynamics of \u2018small\u2010world\u2019 networks\u201d, Nature, Vol. 393, pp. 440\u20102.","DOI":"10.1038\/30918"},{"key":"key2022021220274880900_b23","doi-asserted-by":"crossref","unstructured":"Zeheleva, E., Kolcz, A. and Getoor, L. (2008), \u201cTrusting spam reporters: a reporter\u2010base reputation system for email filtering\u201d, ACM Transactions on Information Systems, Vol. 27 No. 1.","DOI":"10.1145\/1416950.1416953"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685221211267657","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221211267657\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221211267657\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:25Z","timestamp":1753402165000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/20\/4\/281-295\/174709"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,10,5]]},"references-count":31,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2012,10,5]]}},"alternative-id":["10.1108\/09685221211267657"],"URL":"https:\/\/doi.org\/10.1108\/09685221211267657","relation":{},"ISSN":["0968-5227"],"issn-type":[{"type":"print","value":"0968-5227"}],"subject":[],"published":{"date-parts":[[2012,10,5]]}}}