Friday | 10 July, 2009
CSO
Spam Wars
Sandra Rossi 28/09/2006 12:39:26

Image Problems

spammers, a picture is better than 1000 words

Spam is again on the rise, led by a flood of junk images that spammers have crafted over the past few months to trick e-mail filters, according to security vendors. Called "image-based" spam, these junk images typically do not contain any text, making it harder for filters that look for known URLs or suspicious words to block them. Instead of a typed message, users will see only an embedded .gif or .jpeg image file urging them to buy pharmaceuticals or invest in penny stocks.

Antispam vendor Cloudmark says that half of the incoming spam is now image-based on the "honeypot" systems it puts out on the Internet to lure spammers. "About a year-and-a-half ago we started seeing a little bit of it, but it wasn't until the past six months that it became a serious issue for many antispam companies," says Adam O'Donnell, a senior research scientist with the company.

Image-based spam has jumped from about 1 percent of all spam messages in June 2005 to around 12 percent today, according to Craig Sprosts, senior product manager with IronPort Systems. Its growth is helping to fuel a global resurgence in spamming, he says.

The total number of spam messages sent daily is up 40 percent since April, Sprosts says. Much of this new spam is coming from a "relatively small group of spammers with control over very large zombie networks", of hijacked computers, he says.

Spammers now generate an estimated 55 billion messages per day, according to IronPort. A year ago that number was 30 billion e-mail messages per day. The combination of greater volume and better techniques has meant more complaints for network administrators.

Administrators at Avnet have started stripping certain embedded image files out of all messages, after seeing an uptick in image-based spam two months ago, says Rob Kudray, manager of messaging services with the computer distributor.

One other tactic that is helping keep inboxes full is the spammers' practice of constantly registering new domains. Of the 35 million domains registered in April, 32 million were never paid for and expired after five days, Sprosts says. He believes that many of those domains were used by spammers to send out their unsolicited e-mail during that five-day grace period.

This technique makes it very difficult to blacklist e-mail based on the URLs it contains. "Traditional blacklists and whitelist approaches just can't keep up with how fast they're registering new domains and changing the URLs in the e-mail," Sprosts says. Robert McMillan

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Sponsored Links