Slashdot Mirror


Spam Hits 95% of All Email

An anonymous reader writes "Commtouch released its Email Threats Trend Report based on the automated analysis of billions of email messages weekly. The report examines the appearance of new kinds of attachment spamsuch as PDF spam and Excel spam together with the decline of image spam, as well as the growing threat of innocent appearing spam containing links to malicious web sites. Image spam declined to a level of less than 5% of all spam, down from 30% in the first quarter of 2007; also, image pump-and-dump spam has all but disappeared, with pornographic images taking its place."

41 of 270 comments (clear)

  1. Summary only link by Lord+Grey · · Score: 5, Informative

    The link referenced in the posting goes to a summary page that is a little light on details. At the bottom of that page is a link to the PDF-formatted report. There's a lot more information there, including some screenshots of example SPAM and malware sites, trends in attack vectors, zombie systems, etc.. Interesting stuff.

    --
    // Beyond Here Lie Dragons
    1. Re:Summary only link by speaker+of+the+truth · · Score: 2, Interesting

      Considering this is the land of the goatse posts and I've never heard of commtech before, how do I know this isn't a virus PDF?

      --
      Using openSUSE instead of Windows since 9th of October, 2007 and liking it.
    2. Re:Summary only link by cayenne8 · · Score: 2, Funny
      From the article:"... image pump-and-dump spam has all but disappeared, with pornographic images taking its place."

      I dunno....I thought "pump-and-dump" was another word for "pornographic images"....

      :-)

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  2. My spam is still lame :-P by danaris · · Score: 5, Funny

    ...also, image pump-and-dump spam has all but disappeared, with pornographic images taking its place.

    Huh? Where? Man, all I ever get are stupid Viagra spam and "O3M S0FTWARE!" (and variants thereupon).

    Humpfh. Everyone gets pr0n spam but me.

    Dan Aris

    --
    Fun. Free. Online. RPG. BattleMaster.
    1. Re:My spam is still lame :-P by varmittang · · Score: 4, Funny

      Tell me, is it bad when if you recognize someone from high school in one of those.

      --
      -----BEGIN PGP SIGNATURE-----
      12345
      -----END PGP SIGNATURE-----
    2. Re:My spam is still lame :-P by Chrisq · · Score: 4, Funny

      Especially when its your phys ed. teacher.

    3. Re:My spam is still lame :-P by blindcoder · · Score: 5, Funny

      Do you recognise the girl? Then call her!
      Do you recognise the canine? Then yes, that's bad.

      --
      See my blog for my free opinions.
  3. SPAM @ 95%?! by thatskinnyguy · · Score: 4, Informative

    Thank God for Gmail and its excellent spam filtering! I don't think I've had any spam hit my inbox in 2 years. :-)

    --
    The game.
    1. Re:SPAM @ 95%?! by blindcoder · · Score: 4, Funny

      That's because they read every mail before it hits your inbox.

      --
      See my blog for my free opinions.
    2. Re:SPAM @ 95%?! by Nimey · · Score: 2, Interesting

      Gmail's spam filters have definitely improved. When I first got my account (in '03?) I foolishly posted something to Usenet via DejaGoogle (required my @gmail.com account) and the spam just started rolling in. I still get lots of spam, but almost all of it is properly routed to the spam folder, and thanks to the CustomizeGoogle extension, I don't even see the spam count.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    3. Re:SPAM @ 95%?! by Opportunist · · Score: 3, Funny

      I do NOT want to know what words you teach your 3 year old.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:SPAM @ 95%?! by jfengel · · Score: 3, Insightful

      They're good, but they're not that good for me. I get several spams a day in my inbox (and thousands a day filtered out).

      Bizarrely, they should be easy to identify. Most of them are in Russian. Whatever bayesian network they're doing should have figured out by now that I don't read Russian.

      The other one is the same template, over and over, all beginning with the same phrase. I have no idea why that one keeps getting through.

      I'm sure not complaining; they're clearly filtering out a huge amount of sheer misery.

  4. call me a cynic, but by petes_PoV · · Score: 4, Insightful
    ... here's a report from a company that specialises in anti-virus and other security products.

    While I'm not denying spam etc. is an annoyance and does cause a lot of people some problems, do we really want to accept at face value some words from an organisation that could well have a vested interest in making the problem appear more threatening than it really is?

    Personally I'd prefer to teach people how to avoid spam/virus infection - in the same way we teach people how to avoid clinical infection, than to go around wailing about how bad the problem is.

    --
    politicians are like babies' nappies: they should both be changed regularly and for the same reasons
    1. Re:call me a cynic, but by gammygator · · Score: 5, Insightful

      FWIW, about 90% of our e-mail has been spam... and we've seen a solid 50% increase in traffic over the past quarter. The numbers aren't that out of whack. quote: Personally I'd prefer to teach people how to avoid spam/virus infection... Good luck with that. Particularly with the avoiding spam part. If you come up with a foolproof method that actually involves using e-mail... I'm sure you'll be a lot richer than I am.

      --

      No Nyarlathotep, No Chaos
      Know Nyarlathotep, Know Chaos
    2. Re:call me a cynic, but by Snocone · · Score: 3, Interesting

      Can you imagine any other form of communication that was 95% inefficient?

      Flirting.

      Let us pick some text randomly off a googled link and exercise our imagination.

      "First for Emailing - UK's only Emailing Academy

      We are offering you two free e-courses value $45 each. One is our new success emailing communication programme and the other is our popular lifestyle coaching programme

      SUCCESS EMAILING Communication Tips - series of 4 communication tips modules. Designed to get you connecting and interacting more easily and effectively plus monthly success emailing newsletter with tips, quotes and news..."


      When there is a large industry which advertises itself in terms like that instead of the original then perhaps there would be a point to be made that email communications are unusually inefficient. In the meantime, well, sure looks to me like anyone who has ever interacted with the opposite sex should have no problem imagining a form of communication in which 5% efficiency would be a striking -- well nigh unbelievable actually -- increase, and somehow that communication medium has not died out in several millions of years.

      *looks around* Ah .... neee-ver mind.

    3. Re:call me a cynic, but by l0b0 · · Score: 3, Informative

      The statistics for CERN yesterday: 90% rejected, 7% (manually) moved to spam folder, 3% good mails. And that's not even including those that are just deleted without being moved to the spam folder. Scary tendency.

    4. Re:call me a cynic, but by Snocone · · Score: 2, Funny

      Are you saying flirting is 95% ineffective? You have got to be kidding.

      Well, let's assume I am, shall we?

      In that case, explain the existence of the site I faux-quoted and its ilk.

      Methinks that if I was indeed kidding, there would not exist the market which this class of business caters to. (Or, for that matter, the porn/prostitution/yadayadayada classes of business.) However, since they do exist, we can deduce that the market that they are addressing does indeed exist, and it would appear to further be a reasonable assumption that if people could undercut 95% inefficiency on a consistent basis, then that market would not exist. But it does. So, I am not kidding. QED.

  5. doubtful by jsldub · · Score: 2, Interesting

    I highly doubt that, "All Email"?

    Did they track private networks? Encrypted Email?

  6. Re:white lists are the way to go by tepples · · Score: 4, Insightful

    And really - if I want to hear from you then you'll be on that list. If you aren't on that list then I don't want you cluttering up my inbox in the first place. Let me guess: You don't run a business.
  7. Mine is full of spam... by psychicsword · · Score: 3, Funny

    All I ever get is spam.

    Most of the subjects are as follows:(filtered for privacy)
    Courses next term
    [Course name here] Grades
    IMPORTANT: Calculus Final Exam Time
    Hello from [Relative name here]
    [Subscribe newsletter here]
    Funny pictures

    Why wont it stop?

  8. That's not an unrealistic number by SaDan · · Score: 5, Interesting

    I work at an ISP and we do SPAM detection and elimination at our border routers. We scan both incoming and outgoing email, and will auto blacklist our own internal IPs if we detect SPAM.

    The highest two-week percentage of rejected incoming email that I've seen broke 97% a few months ago. It's normally between 90% and 95%.

    It's loads of fun dealing with this crap.

    1. Re:That's not an unrealistic number by SaDan · · Score: 3, Informative

      FortiNet FortiGate 1000A hardware firewalls, which block 99% of the SPAM we receive (a couple slip through for various reasons), and we run Zimbra with AV/AS scanning enabled.

      The FortiGates are configured to just drop the SPAM, so 100% of SPAM detected by the firewalls never get past the firewalls.

    2. Re:That's not an unrealistic number by SaDan · · Score: 2, Informative

      Anything we reject will bounce with a 500 category error and an explanation (blacklisted IP, checksum matching, known spamming address, known spamming URL). We have had calls, but they've been from people who were blacklisted because they had machines infected with trojans or were part of a bot-net sending out tons of SPAM.

      People are upset until we ship them a copy of the logs pertaining to their account or IP address. Once they have the proof, they tend to argue less, or even ask for assistance (which we provide in most cases).

  9. Comment removed by account_deleted · · Score: 2, Interesting

    Comment removed based on user account deletion

  10. Not new. by Anonymous Coward · · Score: 2, Informative

    Wasn't "95% of email is spam" reported by the BBC back in 2006?

    And Security Focus has a great article that shows how all of these numbers are totally made up.

  11. penalize the seller not the messenger by Anonymous Coward · · Score: 2, Insightful

    If the financial incentive is removed the problem should go away. The spammer is not the root cause, the entity hiring the spammer and benefiting from the people responding to the advertisement appears to be the root cause and is easier to identify.

    The entity initiating the process is identifiable ( the contact information must be accurate in order to effect the sale ) unlike the spammer that can utilize many techniques to avoid identification.

  12. OK, another data point by CustomDesigned · · Score: 4, Interesting

    Checking my mail stats, since 4 am this morning, I've received 51985 emails, 51909 of which were filtered as spam. That's 99%. Checking the bandwidth monitor, the spam has consumed a steady 100Kbit/s since 4 am, despite being mostly blocked in SMTP envelope via SPF and reputation (SPF blocks forgeries, reputation blocks spammers with the balls to use their own domain).

  13. Any different? by Gorkamecha · · Score: 3, Insightful

    Is this any different then the stats of the dead tree style of spam that appears in my mailbox every day?
    And we have seen the huge (cough) progress made in removing that snail mail spam from the system.

    Honestly, there seems to have been more progress in weeding out the digital spam then the paper sort.
    Even vague sort of laws and protections and such.

  14. Re:white lists are the way to go by cliffski · · Score: 2, Insightful

    and what goes on the business card, the press release and other similar locations? or you think you can run a business that has no email address and ignores emails sent blindly to sales@ info@ and webmaster@ not to mention support@ ?

    --
    DRM-free indie games for the PC and Mac: Positech Games
  15. So where's the invisible hand? by suv4x4 · · Score: 2, Interesting

    Since most slashdotters are libertarians for some reason (and I could argue even I am to some degree) my question is: where's the technological efficient solution to this.

    We've seen some "free market" solutions which basically required that you pay a fee to every mail provider so they don't trash your email. And this didn't particularly help spam either.

    I come to the conclusion that spam as an issue is one of two things, or both of those things:

    1) Not that big of a problem (hard to believe if you are a mail provider / ISP yourself)

    2) Impossible to solve by means of free market solutions, and requires cooperation and standardization of new technology.

    Point 2 is hard to happen since every little startup that comes with a mini solution, trumpet it on their own and hence they are only a nuissance to deal with in the big picture (due to lack of a single standard, it's impossible to have clients which make the process of whitelisting easier and even half automatic).

    Here are couple of solution which would get us half-there, but are only quarter-implemented right now:

    1) Whitelist SMTP servers by talking back to the supposed mail of origin and comparing IP-s. The SMTP may return list of IP-s this host responds from. This is then cached and used for further authentication on this domain. It *may* lead to DoS if many hosts do a first-time check simultaneously, but it's unlikely (and less problematic, given we're eliminating 95% of bad emails this way).

    2) Test-for-human-intelligence in your first email to a new email. Such as, I don't know, some sort of CAPTCHA you fill-in? Once this is done, communication can proceed without further tests between those two emails. The receiver still has the option to block you, lest you employ a mechanical turk.

    Those solutions are boring, they're incomplete in a way, they introduce hassle, but if we *all* agree on those, they can be made less of a hassle, and still not lose their efficacy.

    That would require the likes of AOL, Hotmail, Gmail and so on free mail providers to cooperate with the likes of Microsoft, Apple, Linux devs and so on, to implement this on both the clients and servers.

    Right now, I could see Hotmail cooperating with Microsoft (.. wink, wink.. :P ), but that's where it ends.

  16. Why we can't stop spam with our current techniques by damn_registrars · · Score: 5, Interesting

    We can't stop it because we aren't addressing the real problem. Spam is an economic problem. People send out spam because they make money off of it. And they will therefore continue to send out spam as long as they make money off of it.

    If you want to stop spam, you have to remove the economic incentive. To do that, you need to cut off the co-conspirators that are allowing the spamvertised domains to be established and hosted. If you can either prevent them from getting a cut off the action, or punish them severely for taking their cut, then you can stop spam.

    Until then, if all we do is try to filter spam out, we'll just continue to see the costs of inaction. Beyond that, we're ignoring the fact that filtering has real costs, as well. Filtering doesn't prevent the spam from traversing the internet, and furthermore it requires human time to update as the spammers change their tactics.

    --
    Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
  17. Email is dead, long live Email by kthejoker · · Score: 5, Interesting

    As email asymptotically reachs 100% spam, we will have essentially created a mechanism whose sole goal is to deliver us undesired ads and scams. Talking about spam detectors and blockers and blacklists is irrelevant. Why devote all of this energy to ensure that maybe 5, 10, or 20 people can contact you or your business a day? Or even 20,000, which only highlights the issue that separating spam from valid emails is just bad juju. Simply put, there is no solution to asynchronous communication that is not too tedious or too restrictive. We'd be a lot better off if we blew up all the email servers, and put all of the energy and cost savings into developing encrypted telepathy. You think I'm kidding.

    1. Re:Email is dead, long live Email by mrjb · · Score: 2, Funny

      and put all of the energy and cost savings into developing encrypted telepathy
      It will never work. Considering the trash in my brain, I must conclude that it has already been done, and it has already been compromised.

      --
      Visit http://ringbreak.dnd.utwente.nl/~mrjb/growingbettersoftware to download your free copy of the book
  18. Re:white lists are the way to go by DrgnDancer · · Score: 2, Insightful

    Must be nice not need to hear from customers. Or legit vendors. Or old friends who changed their e-mail addresses. I'm jealous.

    I can't even the use apparently moderately effective "blacklist Chinese and Russian IPs" technique. We correspond all over the world.

    --
    I don't need a million points of light, just two points of multi-mode fiber and a 10 Gig-E router.
  19. Only a few more percentage points to go... by s_p_oneil · · Score: 2, Interesting

    ...before it reaches the level of spam I get in the mailbox in front of my house. I swear, if we want to save the trees, we need to start by arresting the people putting all those unwanted 20-100 page sales catalogs in everyone's mailbox every day.

  20. Comment removed by account_deleted · · Score: 2, Insightful

    Comment removed based on user account deletion

  21. Re:Can we go to my scheme yet? by Belacgod · · Score: 2, Insightful

    As what happened with e-solutions, the Russian mobsters in charge of spam will simply hire better hitmen and eliminate the ones you send, until no one will take the contracts you offer anymore.

  22. Greylisting to the rescue! by Trifthen · · Score: 4, Informative

    Seriously.

    I hate to bring up anecdotal evidence, but, while I still get spam, my flood has gone down to a relative trickle simply by plugging postgrey into postfix. I could probably reduce it to zero with a bayesian filter, but I won't bother. Scanning through my logs, my server rejects literally thousands of spams every day, and I'm just one guy with two email addresses and a handful of aliases.

    So, it would come as no surprise to me that spam volume is that high, I just never see it. I almost want to turn off my filter for a day just to see what would happen.

    Well, maybe not. :)

    --
    Read: Rabbit Rue - Free serial nove
  23. Re:Greylisting to the rescue! (or not) by Anti-Trend · · Score: 3, Interesting

    I knew somebody would bring up greylisting. :) During the business day[1], I work for a company that produces several widely-used anti-spam appliances and a service-based filter as well. We see about 2,000 networks a week, and get a pretty good feel for spam trends and countermeasure effectiveness. I can say with all honesty that in my experiences, greylisting hurts more than it helps for most organizations.
     
    Basically, greylisting is putting an email transaction on hold to see if the sender will retry. The idea is that if the sender is illigitimate, they won't bother resending. However, spammers have been onto this method for as long as it's existed, much moreso lately. All they have to do is take greylisted hosts and move them to the end of their script for later processing. The second time around, the spam gets through anyway. Even with its meager benefits, most organizations want email to come through as quickly as possible, and greylisting delays email by its very nature. It's also much less effective than existing technology that won't hinder most legitimate mail like DNSBL and/or SPF, spamwords+OCR (for image spam), and blocking on unknown recipients.
     
      To summate, if greylisting makes you happy, then don't let me dissuade you from using it. it does indeed stop some spam. But please don't give the false impression that it's a magic bullet; most of the complaints we receive are from clients who've enabled greylisting and can't figure out why their mail is delayed.

    [1] I am also a consultant to another firm who hosts manged email with spam filtering. Due to the complaints above, we have also disabled greylisting there. It was only effective at stopping about 5% of spam reliably, but a delay is put on all mail that isn't otherwise whitelisted. There are plenty of other methods which are both more effective and don't slow down the mailflow or tie up much resources on the MTA.

    --
    Working in a DevOps shop is like playing in a band made up entirely of keytarists.
  24. Re:Greylisting to the rescue! (or not) by Trifthen · · Score: 2, Insightful
    I think you miss the true point of greylisting. See, the delay is only half of the whole equation. Sure, the host may try again, but I'm also subscribed to a few relatively non-strict DNSBL lists. Now, imagine the combination:
    1. Spammer sends a spam.
    2. Spam gets delayed by 5 minutes.
    3. Lazy Spammer neglects to resend. EOM.
    4. Spammer gets put into a DNSBL sometime during the day.
    5. Creative Spammer resends several hours later.
    6. Rejected as bad host, due to DNSBL.
    Also, postgrey, like most greylist plugins, will automatically whitelist an IP that has had several successful deliveries over the course of a few days. It regularly purges this list every 30 days, so if a spammer accidentally gets whitelisted, that doesn't last long. And like I said, DNSBL is checked *before* the greylist is invoked. So, 95+% of spam sent to me every day, never makes it past my SMTP server. And if I bothered to bolt a bayesian filter on top, I'd probably get a handful of spam per year, but I can handle deleting the half dozen that make it through every week. It may not work for everyone, but Email Purgatory seems damn good to me.
    --
    Read: Rabbit Rue - Free serial nove
  25. Re:Why we can't stop spam with our current techniq by SL+Baur · · Score: 2, Insightful

    We can't stop it because we aren't addressing the real problem. Spam is an economic problem. People send out spam because they make money off of it. And they will therefore continue to send out spam as long as they make money off of it.

    If you want to stop spam, you have to remove the economic incentive. To do that, you need to cut off the co-conspirators You're right, but for the wrong (IMO) reason. Spam has economic incentive because all the costs of email are borne by the recipient. Botnets have made it even cheaper. You must remove that if you want to really fix the problem.

    If you do not remove the economic incentive, nothing will work because it will just be an arms race and the "good guys" will necessarily always be on the defensive side.