{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T23:36:48Z","timestamp":1783035408769,"version":"3.54.6"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,9,4]],"date-time":"2023-09-04T00:00:00Z","timestamp":1693785600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,9,4]],"date-time":"2023-09-04T00:00:00Z","timestamp":1693785600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","doi-asserted-by":"publisher","award":["No.2019163"],"award-info":[{"award-number":["No.2019163"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Strategic Priority Research Program of Chinese Academy of Sciences","award":["No. XDC02040100"],"award-info":[{"award-number":["No. XDC02040100"]}]},{"name":"Key Laboratory of Network Assessment Technology at Chinese Academy of Sciences and Beijing Key Laboratory of Network security and Protection Technology"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The illegal use of compromised email accounts by adversaries can have severe consequences for enterprises and society. Detecting compromised email accounts is more challenging than in the social network field, where email accounts have only a few interaction events (sending and receiving). To address the issue of insufficient features, we propose a novel approach to detecting compromised accounts by combining time zone differences and alternate logins to identify abnormal behavior. Based on this approach, we propose a compromised email account detection framework that relies on widely available and less sensitive login logs and does not require labels. Our framework characterizes login behaviors to identify logins that do not belong to the account owner and outputs a list of account-subnet pairs ranked by their likelihood of having abnormal login relationships. This approach reduces the number of account-subnet pairs that need to be investigated and provides a reference for investigation priority. Our evaluation demonstrates that our method can detect most email accounts that have been accessed by disclosed malicious IP addresses and outperforms similar research. Additionally, our framework has the capability to uncover undisclosed malicious IP addresses.<\/jats:p>","DOI":"10.1186\/s42400-023-00167-8","type":"journal-article","created":{"date-parts":[[2023,9,4]],"date-time":"2023-09-04T02:01:42Z","timestamp":1693792902000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Detecting compromised email accounts via login behavior characterization"],"prefix":"10.1186","volume":"6","author":[{"given":"Jianjun","family":"Zhao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Can","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yaqin","family":"Cao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuling","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiang","family":"Cui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qixu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,9,4]]},"reference":[{"key":"167_CR13","unstructured":"AlienVault (2022) Open Threat Exchange. https:\/\/otx.alienvault.com\/browse\/global\/pulses"},{"key":"167_CR1","unstructured":"CNN (2021) Fake FBI emails about a sophisticated attack are part of \u2018ongoing situation,\u2019 agency says. https:\/\/edition.cnn.com\/2021\/11\/13\/politics\/fbi-fake-emails-cyber-threat\/index.html"},{"key":"167_CR2","unstructured":"Corp AS (2022) H2 2022 email threat report. https:\/\/abnormalsecurity.com\/resources\/h2-2022-report-brand-impersonation-phishing"},{"key":"167_CR3","unstructured":"Egele M, Stringhini G, Kruegel C, Vigna G (2013) Compa: detecting compromised accounts on social networks. In: NDSS"},{"issue":"4","key":"167_CR4","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1109\/TDSC.2015.2479616","volume":"14","author":"M Egele","year":"2015","unstructured":"Egele M, Stringhini G, Kruegel C, Vigna G (2015) Towards detecting compromised accounts on social networks. IEEE Trans Dependable Secure Comput 14(4):447\u2013460","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"167_CR5","unstructured":"Hao S, Syed NA, Feamster N, Gray AG, Krasser S (2009) Detecting spammers with snare: spatio-temporal network-level automatic reputation engine. In: USENIX security symposium, vol 9"},{"key":"167_CR6","unstructured":"Ho G, Sharma A, Javed M, Paxson V, Wagner D (2017) Detecting credential spearphishing in enterprise settings. In: 26th USENIX security symposium (USENIX security 17), pp 469\u2013485"},{"key":"167_CR7","unstructured":"Ho G, Cidon A, Gavish L, Schweighauser M, Paxson V, Savage S, Voelker GM, Wagner D (2019) Detecting and characterizing lateral phishing at scale. In: 28th USENIX security symposium (USENIX security 19), pp 1273\u20131290"},{"key":"167_CR8","doi-asserted-by":"crossref","unstructured":"Hu X, Li B, Zhang Y, Zhou C, Ma H (2016) Detecting compromised email accounts from the perspective of graph topology. In: Proceedings of the 11th international conference on future internet technologies, pp 76\u201382","DOI":"10.1145\/2935663.2935672"},{"key":"167_CR9","unstructured":"ipgeolocation (2022) Free IP geolocation API and accurate IP geolocation database. https:\/\/ipgeolocation.io"},{"key":"167_CR10","doi-asserted-by":"crossref","unstructured":"Karimi H, VanDam C, Ye L, Tang J (2018) End-to-end compromised account detection. In: 2018 IEEE\/ACM international conference on advances in social networks analysis and mining (ASONAM). IEEE, pp 314\u2013321","DOI":"10.1109\/ASONAM.2018.8508296"},{"key":"167_CR11","doi-asserted-by":"crossref","unstructured":"Machlica L, Vanek J, Zajic Z (2011) Fast estimation of gaussian mixture model parameters on GPU using CUDA. In: 2011 12th international conference on parallel and distributed computing, applications and technologies. IEEE, pp 167\u2013172","DOI":"10.1109\/PDCAT.2011.40"},{"key":"167_CR12","unstructured":"MaxMind (2022) Geolocate an IP address using Web Services. https:\/\/dev.maxmind.com\/geoip\/geolocate-an-ip\/web-services?lang=en"},{"issue":"10","key":"167_CR14","doi-asserted-by":"publisher","first-page":"4965","DOI":"10.1007\/s11227-018-2336-3","volume":"74","author":"AY Nur","year":"2018","unstructured":"Nur AY, Tozal ME (2018) Identifying critical autonomous systems in the internet. J Supercomput 74(10):4965\u20134985","journal-title":"J Supercomput"},{"issue":"27","key":"167_CR15","doi-asserted-by":"publisher","first-page":"19349","DOI":"10.1007\/s11042-020-08721-z","volume":"79","author":"S Pv","year":"2020","unstructured":"Pv S, Bhanu S (2020) UbCadet: detection of compromised accounts in twitter based on user behavioural profiling. Multimed Tools Appl 79(27):19349\u201319385","journal-title":"Multimed Tools Appl"},{"key":"167_CR16","first-page":"659","volume":"741","author":"DA Reynolds","year":"2009","unstructured":"Reynolds DA (2009) Gaussian mixture models. Encycl Biom 741:659\u2013663","journal-title":"Encycl Biom"},{"issue":"1","key":"167_CR17","doi-asserted-by":"publisher","first-page":"176","DOI":"10.1109\/TIFS.2015.2482465","volume":"11","author":"X Ruan","year":"2015","unstructured":"Ruan X, Wu Z, Wang H, Jajodia S (2015) Profiling online social behaviors for compromised account detection. IEEE Trans Inf Forensics Secur 11(1):176\u2013187","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"4","key":"167_CR18","doi-asserted-by":"publisher","DOI":"10.1088\/2057-1976\/2\/4\/045002","volume":"2","author":"LEV Silva","year":"2016","unstructured":"Silva LEV, Senra Filho A, Fazan VPS, Felipe JC, Junior LM (2016) Two-dimensional sample entropy: assessing image texture through irregularity. Biomed Phys Eng Express 2(4):045002","journal-title":"Biomed Phys Eng Express"},{"key":"167_CR19","unstructured":"Stringhini G, Mourlanne P, Jacob G, Egele M, Kruegel C, Vigna G (2015) $$\\{$$EVILCOHORT$$\\}$$: detecting communities of malicious accounts on online services. In: 24th USENIX security symposium (USENIX security 15), pp 563\u2013578"},{"key":"167_CR20","unstructured":"UpGuard (2022) The 67 biggest data breaches. https:\/\/www.upguard.com\/blog\/biggest-data-breaches"},{"issue":"20","key":"167_CR21","doi-asserted-by":"publisher","first-page":"5346","DOI":"10.1002\/cpe.5346","volume":"31","author":"SP Velayudhan","year":"2019","unstructured":"Velayudhan SP, Somasundaram MSB (2019) Compromised account detection in online social networks: a survey. Concurr Comput Pract Exp 31(20):5346","journal-title":"Concurr Comput Pract Exp"},{"key":"167_CR22","unstructured":"Viswanath B, Bashir MA, Crovella M, Guha S, Gummadi KP, Krishnamurthy B, Mislove A (2014) Towards detecting anomalous user behavior in online social networks. In: 23rd USENIX security symposium (USENIX security 14), pp 223\u2013238"},{"key":"167_CR23","unstructured":"Wikipedia (2022a) Advanced persistent threat. https:\/\/en.wikipedia.org\/wiki\/Advanced_persistent_threat"},{"key":"167_CR24","unstructured":"Wikipedia (2022b) Hillary Clinton email controversy. https:\/\/en.wikipedia.org\/wiki\/Hillary_Clinton_email_controversy"},{"key":"167_CR25","unstructured":"Wikipedia (2022c) Kernel density estimation. https:\/\/en.wikipedia.org\/wiki\/Kernel_density_estimation"},{"key":"167_CR26","unstructured":"Wikipedia (2022d) Jensen\u2013Shannon divergence.  https:\/\/en.wikipedia.org\/wiki\/Jensen-Shannon_divergence"},{"issue":"1","key":"167_CR27","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1162\/neco.1996.8.1.129","volume":"8","author":"L Xu","year":"1996","unstructured":"Xu L, Jordan MI (1996) On convergence properties of the EM algorithm for gaussian mixtures. Neural Comput 8(1):129\u2013151","journal-title":"Neural Comput"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00167-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00167-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00167-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,4]],"date-time":"2023-09-04T02:02:20Z","timestamp":1693792940000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00167-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,4]]},"references-count":27,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["167"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00167-8","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,4]]},"assertion":[{"value":"6 April 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 June 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 September 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"36"}}