New Business Software

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 31 March 2009

Spam data and trends: Q1 2009

Posted on 07:00 by Unknown
Editor's Note: The spam data cited in this post is drawn from the Google enterprise security and archiving security network (Postini), which delivers an added layer of security for standalone mail servers and Google Apps Premier Edition customers. For a discussion of the anti-spam measures included in Gmail, please see this post from the Gmail blog.

In providing email security to more than 50,000 businesses and 15 million business users, Google security and archiving services, powered by Postini, process and cull spam from more than three billion enterprise email connections every day. This gives us strong insights into the state of the spam industry, some of which we share in regular posts to this blog.

R
ead on for a quick overview of spam trends and events in the first quarter of 2009.

What we saw in the Postini data centers

The most significant spam-related event in the first quarter of 2009 occurred when spam volume returned to pre-McColo takedown levels. By the second half of March, seven-day average spam volume was at the same volume we saw prior to the blocking of the McColo ISP in November 2008.


Spammers have clearly rallied following the McColo takedown, and overall spam volume growth during Q1 2009 was the strongest it's been since early 2008, increasing an average of 1.2% per day. To put that number into context, the growth rate of spam volume in Q1 2008 was approximately 1% per day – which, at the time, was a record high.

Of course, like every year before it, 2008 set a new record for overall spam volume. But in 2008 spam growth flattened over the summer and early fall, and then fell off a cliff after the McColo takedown (daily growth declined to .8%, .3%, and then .01% in the last three quarters of the year). This pattern raises some interesting questions regarding what we can expect in the rest of 2009: Will spam growth once again flatten or decline after a strong first quarter? Or have spammers – as part of their recovery from the McColo takedown – rebuilt botnets to be capable of sustaining or even accelerating this early growth spurt?

It's difficult to ascertain exactly how spammers have rebuilt in the wake of McColo, but data suggests they're adopting new strategies to avoid a McColo-type takedown from occurring again. Specifically, the recent upward trajectory of spam could indicate that spammers are building botnets that are more robust but send less volume – or at least that they haven't enabled their botnets to run at full capacity because they're wary of exposing a new ISP as a target.

New types of spam

The most significant development in spam vectors this quarter was the appearance of location-based spam. In this type of attack, users click on a link in a spam message and are directed to a page that contains a fraudulent news headline describing a crisis or disaster in a major city nearby. The attack customizes the location for each user by determining the geolocation of the user's source IP and then identifying the nearest major city. The addition of location creates a heightened level of interest, and the user is tempted to click on the embedded video – which in turn downloads a virus to his or her machine.

Meanwhile, the economy, financial markets, job cuts, and resume help continue to be the most prominent topics spammers are employing as lures for more traditional attacks. We also saw increased spam activity around the U.S. presidential inauguration and St. Patrick's Day, in keeping with the recent propensity spammers have demonstrated for reading the news and keeping their eyes on the holiday calendar in targeting their attacks.

Virus roundup

In early 2008, a trend emerged in which we saw spam messages with attached viruses (otherwise known as "payload viruses") spiking every Sunday, possibly targeting a maintenance window to catch corporate defenses when they were undergoing scheduled updates.


This year we've seen the payload viruses spread out across every day of the week, with no immediately obvious pattern in their distribution. It's difficult to say for certain what prompted the change, but one possible explanation is that spammers switched tactics because they weren't seeing the success they'd hoped for from the focused attacks.


Of course, p
ayload viruses have also seen a recent spike overall -- in the month of March we saw a 9x increase from February. This pales in comparison to the highs we saw last summer, but it may indicate a developing trend that's worth keeping a close eye on.

Viruses delivered as a blended threat (when a spam message directs a user to a malicious website, which then results in a virus being downloaded to the user's computer) continue to be popular with spammers. E-cards are one of the best examples of this vector, and Valentine's Day saw a flurry of activity using e-cards to direct users to malicious websites.

Conclusions

Spammers continue to prove their resilience -- whether it's bouncing back from the biggest takedown on record or finding new ways to exploit the ways we communicate for malicious purposes, they're clearly here to stay. And Google believes firmly in the power of the cloud to protect your enterprise from them: Outsourcing message security to Google enables you to leverage our technical expertise and massive infrastructure to keep spammers from your door. See how much spam is costing your business, learn how much you could be saving with Google Message Security, or contact us for more information.

Posted by Amanda Kleha, Google security and archiving team
Email ThisBlogThis!Share to XShare to Facebook
Posted in admin, Google Email Security and Archiving, IT, Postini, spam and security trends | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ​Modern browsers for modern applications
    ​The web has evolved in the last ten years, from simple text pages to rich, interactive applications including video and voice. Unfortunatel...
  • Help customers find their way with new Google Maps gadget
    Last week, I looked up directions to the hotel in Sacramento that I had booked for the Fourth of July weekend. As I had never been to that p...
  • Connecting Google Apps Education Edition with Blackboard
    Editor's note: George Kroner is a Developer Relations Engineer for Blackboard, a company that focuses on transforming and improving the ...
  • Students and others find what they're looking for with Google Search
    When you think about all that a university has to offer, you probably think of classes, curriculum, and alumni activities. But universities ...
  • 30,000 Valeo employees put Google Apps to work
    Tens of millions of people around the world have transitioned from software-based email and personal productivity tools to powerful web-base...
  • Spelling Suggestions and Thumbnail View in Google Docs
    Google Docs lets you create, store, and share work files with teammates and other colleagues. Today we're making it easier for you to s...
  • Google Apps update: Email migration, shared address book, and a cool video
    Posted by Ryan Pollock, Product Marketing As Vikaram noted on the Official Google Blog , today was a big day for Google Apps. We introduced ...
  • Google Apps on Campus: Getting Things Done in '08
    2008 was an action-packed year for Google Apps for Education . We grew by 300% since last year, released two new products: Google Sites and...
  • Collaborating with Google Apps and Socialwok
    Editor's Note: Ming Yong is co-founder of Socialwok, a a feed-based group collaboration application for enterprises that integrates with...
  • A new look for Google Docs spreadsheets
    When you next open a spreadsheet in Google Docs, you'll notice a number of updates to the spreadsheets interface. The simplified toolbar...

Categories

  • admin
  • Android
  • cloud computing
  • developers
  • earth and maps
  • education
  • enterprise
  • events
  • gmail
  • gonegoogle
  • Google Apps
  • Google Apps Blog
  • Google Calendar
  • google commerce search
  • google docs
  • Google Email Security and Archiving
  • Google Enterprise Search
  • Google I/O
  • Google Maps
  • google message security
  • Google Search Appliance
  • Google Site Search
  • google sites
  • Google spreadsheets
  • Google Video
  • Google Wave
  • government
  • guest post
  • hints and tips
  • innovation
  • IT
  • K-12
  • large business
  • mashups
  • medium business
  • migration
  • mobile
  • new features
  • non-profit
  • partners
  • Postini
  • productivity
  • small business
  • spam and security trends
  • success story
  • switch
  • university
  • viewpoint
  • webinar
  • webmaster

Blog Archive

  • ►  2010 (14)
    • ►  January (14)
  • ▼  2009 (178)
    • ►  December (11)
    • ►  November (12)
    • ►  October (15)
    • ►  September (19)
    • ►  August (18)
    • ►  July (19)
    • ►  June (13)
    • ►  May (15)
    • ►  April (15)
    • ▼  March (14)
      • Theme scheme in Google Apps
      • Spam data and trends: Q1 2009
      • Drawing on the job
      • Google Services for Websites expands to include Go...
      • Schools in India get the "App"titude
      • Charts, charts, charts!
      • San Francisco Bay Area: Invitation to Google At Wo...
      • Go go gadgets...in Google Sites
      • Unlocking information, streamlining IT
      • 10 Gigs of Virtual Class (or Virtual Talent Show) ...
      • @everyone: We're on twitter
      • Google Video for business: now featuring larger vi...
      • Everything you always wanted to know about keeping...
      • Oscar Night for Enterprise Search
    • ►  February (13)
    • ►  January (14)
  • ►  2008 (78)
    • ►  December (9)
    • ►  November (16)
    • ►  October (8)
    • ►  September (8)
    • ►  August (3)
    • ►  July (4)
    • ►  June (4)
    • ►  May (5)
    • ►  April (5)
    • ►  March (7)
    • ►  February (5)
    • ►  January (4)
  • ►  2007 (79)
    • ►  December (6)
    • ►  November (7)
    • ►  October (6)
    • ►  September (8)
    • ►  August (4)
    • ►  July (9)
    • ►  June (6)
    • ►  May (10)
    • ►  April (7)
    • ►  March (7)
    • ►  February (1)
    • ►  January (8)
  • ►  2006 (76)
    • ►  December (4)
    • ►  November (6)
    • ►  October (13)
    • ►  September (10)
    • ►  August (6)
    • ►  July (9)
    • ►  June (6)
    • ►  May (7)
    • ►  April (3)
    • ►  March (3)
    • ►  February (7)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile