Detecting SPAM From Inside your Network
by Ron Gula on May 17, 2007
We all receive and are annoyed by the amount of "SPAM" email in our in-box. One way to fight SPAM is to monitor large networks for evidence of compromised hosts that are being used to email out unwanted content. This blog entry shows how passive network analysis and log analysis can be used to look for specific types of events that can indicate SPAM originating from inside your network.
Watch for Changes in the number of Email "Clients"