摘要 |
A method for classifying abnormal emails is provided to realize a security technique in an email server by classifying the abnormal emails effectively based on a logical inference rule without any spam filtering process and operate the mail server safely by processing classification before a spam filtering server. A received email packet is decoded into a readable form and is classified into each header information by analyzing a packet header(S200). It is checked whether each classified header information is normal or abnormal, and a predetermined value is assigned to each header information depending on a determination result(S400). An abnormal email is classified based on a logical inference rule by using the predetermined value assigned to each header information(S500). The header information comprises mail header information, sender information, receiver information, and attached execution file information. The logical inference rule classifies the email into an abnormal email when the sender information is normal, the receiver and mail header information is abnormal, and an attached execution file is found. |