An Empirical Study of Clustering Behavior of Spammers and Group-based Anti-Spam Strategies

We conducted an empirical study of the clustering behavior of spammers and explored the group-based anti-spam strategies. We propose to block spammers as groups instead of dealing with each spam individually. We empirically observe that, with a certain grouping criteria such as having the same URL in the spam mail, the relationship among the spammers has demonstrated highly clustering structures. By examining the spam mails gathered in a seven-day period, we found that if a spammer is associated with multiple groups, it has a higher probability of sending more spam mails in the near future. We also observed that the spam mails from the same group of spammers often arrive in burst and a very small fraction of the active spammers actually accounted for a large portion of the total spam mails.