Paper published in Journal of Digital Forensics (JDFSL)

Hot Zone Identification: Analyzing Effects of Data Sampling on Spam Clustering
Authors: Rasib Khan, Mainul Mizan, Ragib Hasan, and Alan Sprague,
Journal of Digital Forensics, Security and Law (JDFSL), 9(1): 67-82, 2014

This paper was selected as one of the best papers from ADFSL Conference on Digital Forensics, Security and Law for publication in Journal of Digital Forensics (JDFSL).

Abstract: Email is the most common and comparatively the most efficient means of exchanging information in today’s world. However, given the widespread use of emails in all sectors, they have been the target of spammers since the beginning. Filtering spam emails has now led to critical actions such as forensic activities based on mining spam email. The data mine for spam emails at the University of Alabama at Birmingham is considered to be one of the most prominent resources for mining and identifying spam sources. It is a widely researched repository used by researchers from different global organizations. The usual process of mining the spam data involves going through every email in the data mine and clustering them based on their different attributes. However, given the size of the data mine, it takes an exceptionally long time to execute the clustering mechanism each time. In this paper, we have illustrated sampling as an efficient tool for data reduction, while preserving the information within the clusters, which would thus allow the spam forensic experts to quickly and effectively identify the ‘hot zone’ from the spam campaigns. We have provided detailed comparative analysis of the quality of the clusters after sampling, the overall distribution of clusters on the spam data, and timing measurements for our sampling approach. Additionally, we present different strategies which allowed us to optimize the sampling process using data-preprocessing and using the database engine’s computational resources, and thus improving the performance of the clustering process.