Time Email Received Helps to Identify Spam - More Spam Received at Night   - 1,238 Views,

Summary: Craig Hughes, who originally worked with the Spam Assassin team, and then went on to found GumStix, has discovered something interesting: much more spam is received during the nighttime hours than during the day. It's a dramatic enough difference that Hughes says that he is convinced that 'time of day received' is a useful test to help determine whether something is spam.

Previous Article « Using Free Starbucks Wifi Hoses Your RSS Feeds - Replaces Them with AT&T URLs
Read Next Article » Vundo Virus Raises Its Ugly Head Infecting Countless PCs

  Follow Anne on Twitter     Friend Anne on Facebook

Craig Hughes, who originally worked with the Spam Assassin team, and then went on to found GumStix, has discovered something interesting: much more spam is received during the nighttime hours than during the day. It’s a dramatic enough difference that Hughes says that he is convinced that ‘time of day received’ is a useful test to help determine whether something is spam.

Now, again, this applies to email received during U.S. nighttime hours - which doesn’t mean that it wasn’t sent during the day from somewhere else. For example, it may be the morning in Korea when some spammer there hits “send”, but in the U.S. where it’s received, it’s the middle of the night.

Hughes writes, of using “time received” as a test for whether something is more likely or not to be spam, that he is now “fully convinced that this must be a useful test.”

The way that he arrived at this conclusion was by plotting all of the email that he received over a year. He noted that there were regular spikes in traffic during weekdays, as one might expect for legitimate email. But, he discovered, there were no swings or spikes in the amount of bad email (spam, phishing, viruses, etc. - what Hughes calls “malmail”). Which meant that the ratio of good:bad email changed with the time and day of the week. At night, and on weekends, there was a higher malmail:good mail ratio.

Says Hughes, “Therefore, the ratio of malmail to real mail clearly is affected by time of day/day of week. If mail arrives outside of ‘normal email’ hours, it surely is much more likely to be malmail; a rule which learns which days/hours are good vs bad and scores mail accordingly surely would be useful for identifying and filtering out malmail.”

This makes a lot of sense, and we look forward to spam filters, like Spam Assassin, incorporating a “time of day” received rule into their rule set, as Hughes suggests.

You can read Hughes full analysis, and view his charts, here.

Time Email Received Helps to Identify Spam - More Spam Received at Night

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Using Free Starbucks Wifi Hoses Your RSS Feeds - Replaces Them with AT&T URLs
Read Next Article » Vundo Virus Raises Its Ugly Head Infecting Countless PCs

Read more:

»  If it Says You’ve Received a Greeting eCard from a Friend, Class Mate, or Partner - Well, You Haven’t. And Don’t Open It!

»  A Gaggle of Google Giggles (Gmail)

»  This List Tells You Who Is Advertising in Spam

»  If You Use Challenge/Response It May Be Your Email Delivery Which is Challenged

For additional similar stories check out our archives on Spam

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 1/9/2009
The Internet Patrol
Patrolling the Internet for You!