New Business Software

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 26 January 2009

2008: The year in spam

Posted on 06:42 by Unknown
[Ed. Note: The spam data cited in this post is drawn from the Postini Message Security network, which processes and culls spam from more than 2 billion enterprise email connections per day, giving Google strong insight into the state of the spam industry overall. For a discussion of what Google is doing to keep spam out of your Gmail inboxes on the consumer side, check out this post.]

In November 2008 a large source of the world's spam, the McColo network, was taken offline. Prior to that, spam levels had been holding relatively constant. But when McColo went offline, we saw spam drop by 70% compared with previous levels. However, spammers are recovering with vigor.

While spam is still down overall, it's important to note its rate of growth. Spam levels are up by 156% since November 2008. As spammers recover, the increased rate of spam growth will likely have total spam volumes back to pre-McColo levels within a few months.



Although McColo received a lot of attention, the highest volume of spam in 2008 actually came on April 23, which was an all-time high spam level for Google Message Security data centers. That day, the average number of spam messages blocked per user was 194. This peak was driven by an unprecedented number of non-delivery receipt (NDR) attacks we saw in April. One customer who was the target of a specific NDR attack said that their users were receiving an average of 100 emails every minute.

As spammers fill the void left by McColo, it's reasonable to anticipate a decreasing rate of growth as spam reaches November 2008 levels. However, since the November levels weren't even the peak for the year, and since spammers appear to be quickly recovering, the question remains: Where will spam volume top out in 2009? Will it be near the November 2008 level? the April 2008 level? Or higher?



One way to approach that question might be to compare 2008 overall levels with previous years. Spam threats rose visibly in 2008, reflecting the overall trend of rising attacks. Even with the drop in November 2008, spam levels climbed 25% over 2007. Our statistics show that the average unprotected user would have received 45,000 spam messages in 2008 (up from 36,000 in 2007). All indicators suggest this trend will continue as virus, malware, and link-based attacks become both more frequent and more ingenious.



Looking ahead to the rest of 2009, we expect viruses sent via email and in blended attacks (email and web) to continue to be a serious threat. During the second half of 2008, virus volume increased six-fold from the first half of the year. These spam messages would often try to fool users by mimicking legitimate emails such as package tracking notifications or invoices that included virus attachments. Another popular technique in 2008 was emailing spoofed news alerts with URLs that would link to a website hosting the virus.

We can also expect that viruses and malware will continue to be a key tool and area of focus for spammers to upgrade their platforms. Even though virus attachment volumes have been low so far this year, we expect spammers to work hard to rebuild their networks to replace what was lost in the McColo shutdown.

Of course, the only thing we can really say with certainty about 2009 is that spam and viruses will continue to be unpredictable. And given that uncertainty, virus detection and blocking technologies become even more important. Last year we released advanced new anti-virus heuristics that specifically targeted zero-hour vulnerability (the period of time between when a new virus enters the wild and the release of the anti-virus signature file). When the zero-hour protection identifies a suspicious message, the message is scanned using the new anti-virus heuristics, and if confirmed as a virus, the message is quarantined.

The chart below is an example of our new heuristic virus detection and blocking at work. On October 1, 2008, our automated technology detected a viral message pattern (later identified as new strain of the Downloader-AAP!zip) in the wild and started quarantining messages with this virus. Five hours later we received the new virus signature file from one of our anti-virus partners and the signature-based blocks began to take effect.



As seen from the roller-coast ride of spam and viruses in 2008, spam has again demonstrated its resiliency. Despite eliminating a major source, spam keeps coming back. Spammers are re-investing with increasing speed to evolve their systems into decentralized, harder-to-detect ecosystems. If you'd like to know more about Google's anti-spam solution for businesses, visit us at www.google.com/a/security.

Posted by Amanda Kleha, Google Message Security Team
Email ThisBlogThis!Share to XShare to Facebook
Posted in spam and security trends | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ​Modern browsers for modern applications
    ​The web has evolved in the last ten years, from simple text pages to rich, interactive applications including video and voice. Unfortunatel...
  • Help customers find their way with new Google Maps gadget
    Last week, I looked up directions to the hotel in Sacramento that I had booked for the Fourth of July weekend. As I had never been to that p...
  • Connecting Google Apps Education Edition with Blackboard
    Editor's note: George Kroner is a Developer Relations Engineer for Blackboard, a company that focuses on transforming and improving the ...
  • Students and others find what they're looking for with Google Search
    When you think about all that a university has to offer, you probably think of classes, curriculum, and alumni activities. But universities ...
  • 30,000 Valeo employees put Google Apps to work
    Tens of millions of people around the world have transitioned from software-based email and personal productivity tools to powerful web-base...
  • Spelling Suggestions and Thumbnail View in Google Docs
    Google Docs lets you create, store, and share work files with teammates and other colleagues. Today we're making it easier for you to s...
  • Google Apps update: Email migration, shared address book, and a cool video
    Posted by Ryan Pollock, Product Marketing As Vikaram noted on the Official Google Blog , today was a big day for Google Apps. We introduced ...
  • Google Apps on Campus: Getting Things Done in '08
    2008 was an action-packed year for Google Apps for Education . We grew by 300% since last year, released two new products: Google Sites and...
  • Collaborating with Google Apps and Socialwok
    Editor's Note: Ming Yong is co-founder of Socialwok, a a feed-based group collaboration application for enterprises that integrates with...
  • A new look for Google Docs spreadsheets
    When you next open a spreadsheet in Google Docs, you'll notice a number of updates to the spreadsheets interface. The simplified toolbar...

Categories

  • admin
  • Android
  • cloud computing
  • developers
  • earth and maps
  • education
  • enterprise
  • events
  • gmail
  • gonegoogle
  • Google Apps
  • Google Apps Blog
  • Google Calendar
  • google commerce search
  • google docs
  • Google Email Security and Archiving
  • Google Enterprise Search
  • Google I/O
  • Google Maps
  • google message security
  • Google Search Appliance
  • Google Site Search
  • google sites
  • Google spreadsheets
  • Google Video
  • Google Wave
  • government
  • guest post
  • hints and tips
  • innovation
  • IT
  • K-12
  • large business
  • mashups
  • medium business
  • migration
  • mobile
  • new features
  • non-profit
  • partners
  • Postini
  • productivity
  • small business
  • spam and security trends
  • success story
  • switch
  • university
  • viewpoint
  • webinar
  • webmaster

Blog Archive

  • ►  2010 (14)
    • ►  January (14)
  • ▼  2009 (178)
    • ►  December (11)
    • ►  November (12)
    • ►  October (15)
    • ►  September (19)
    • ►  August (18)
    • ►  July (19)
    • ►  June (13)
    • ►  May (15)
    • ►  April (15)
    • ►  March (14)
    • ►  February (13)
    • ▼  January (14)
      • This morning's spam filter issue
      • "And Together We Form Voltron" (or "How to Connect...
      • Announcing offline access in Gmail Labs
      • "With Google, the sky is the limit"
      • 2008: The year in spam
      • SADA Systems, Inc. uses Google Sites to create its...
      • Designing the search you've been looking for
      • "Why I sleep better at night with Google Apps," by...
      • Students and others find what they're looking for ...
      • A new layer of data access security for Google Apps
      • Channeling the Cloud: Announcing the Google Apps ...
      • Serving businesses better with Google Apps
      • Putting the "App" in "H-App-y New Year"
      • Google Earth: now you CAN take it with you
  • ►  2008 (78)
    • ►  December (9)
    • ►  November (16)
    • ►  October (8)
    • ►  September (8)
    • ►  August (3)
    • ►  July (4)
    • ►  June (4)
    • ►  May (5)
    • ►  April (5)
    • ►  March (7)
    • ►  February (5)
    • ►  January (4)
  • ►  2007 (79)
    • ►  December (6)
    • ►  November (7)
    • ►  October (6)
    • ►  September (8)
    • ►  August (4)
    • ►  July (9)
    • ►  June (6)
    • ►  May (10)
    • ►  April (7)
    • ►  March (7)
    • ►  February (1)
    • ►  January (8)
  • ►  2006 (76)
    • ►  December (4)
    • ►  November (6)
    • ►  October (13)
    • ►  September (10)
    • ►  August (6)
    • ►  July (9)
    • ►  June (6)
    • ►  May (7)
    • ►  April (3)
    • ►  March (3)
    • ►  February (7)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile