New Business Software

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 1 July 2009

Q2 2009 Spam Trends

Posted on 08:05 by Unknown
Editor's Note: The spam data cited in this post is drawn from the network of Google email security and archiving services, powered by Postini, which provide email security to more than 50,000 organizations, including businesses of all sizes, government agencies, and educational institutions. To learn more about what the Gmail team is doing to keep spam out of your inboxes, check out this post.

Our "Spam Trend" update last quarter summarized the rise in both levels and types of spam, with new players and techniques entering the market. This quarter, proliferation continues, with an unpredictable pattern of drops and spikes as 2009 moves along. Overall, spam is measurably up: Q2'09 average spam levels are 53% higher than in Q1'09 and 6% higher than in Q2'08.

After last November's McColo ISP takedown, when spam volumes dropped by 70%, spammers worked overtime to fill the void. They succeeded: Within four months, spam levels rose back to pre-McColo levels. This upward trend continued through June 4, when another large ISP spam source, 3FN, was reported to have been dismantled. Spam volume immediately dropped 30% – not as extreme as McColo, but still significant. Although this created a sudden dip in spam levels, it also created an open invitation for opportunistic spammers to once again seize a market opportunity.

Over the coming months, we anticipate watching new players once again drive spam levels back up. Since June 4, spammers have already made up a significant amount of ground, climbing 14% from the initial drop.

Here's what the trend looked like, as tracked through Postini filters, over the past six months:


"Unpredictability" summarizes the overall trend as Q2'09 winds down and spammers test both new and "retro" techniques. For example, on June 18 we tracked a new attack that unleashed 50% of a typical day's spam volume in just two hours' time. This attack used a simple "newsletter" template – somewhat "old school" by today's spam standard – with malevolent links and images inserted into the content. Google's Postini filters detected more than 11,000 variants of this spam during those two hours. Because this spam enabled spoofing of the recipient domain (meaning the "from" field was falsified), distribution lists were especially hard-hit by this attack.


Resurgence of image spam

One of the other trends we're watching closely is the sudden popularity of "image spam" – a form of spam that rose to prominence in 2007, before most anti-spam filters learned how to block it. It's simple stuff: basic email with advertising content, usually containing a related image. They can also include malicious links or content – and either way, the large file size of an image spam can place a heavy load on an email network.

An image spam email might look something like this:



Evidence of the resurgence in image spam can be seen in the graph below, which shows that the actual size of spam messages, measured in bytes, is back on the rise:


There are a couple of possible explanations for the resurgence in image spam, despite the fact that most spam filters out there have adapted to the technique. One theory is that this wave is designed to test the defenses
of the different spam filters out there, so that spammers can do statistical analysis on what subject lines and content have the highest probability of success.

Another is that there may be some new players entering the spam game, following the McColo and 3FN takedowns, and these new players are opening with some well-tested techniques. Either way, we're watching this trend and will share insights as we gain them in the weeks and months ahead.

Spike in payload viruses

June was also an active month for viruses sent as email attachments, otherwise known as "payload viruses." Volumes rose to their highest level in almost two years as spammers returned to yet another tried-and-true technique to expand their botnets.

As you can see in the chart below, June's activity is almost as high as the two-month payload virus surge seen in Q3'07. Fortunately, Google's Postini zero-hour heuristics detected this uprise early and kept payload attacks in the cloud and away from users' email networks.


Everything old might be new again

In summary, Q2'09 saw continued unpredictability and the resurgence of old-style spam attacks. Are spammers finally running out of original ideas? And if so, like Hollywood, are we now starting to see spam "remakes," based on originals of a few years ago? And what are spammers looking to accomplish as they unleash these remakes? Only time will tell.

For more information on how Google email security services, powered by Postini, can help your organization provide better spam protection and take a load off your network by halting spam in the cloud, visit www.google.com/postini.

Posted by Amanda Kleha, Google message security and archiving team

Email ThisBlogThis!Share to XShare to Facebook
Posted in admin, enterprise, Google Apps, Google Email Security and Archiving, hints and tips, Postini, spam and security trends | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ​Modern browsers for modern applications
    ​The web has evolved in the last ten years, from simple text pages to rich, interactive applications including video and voice. Unfortunatel...
  • Help customers find their way with new Google Maps gadget
    Last week, I looked up directions to the hotel in Sacramento that I had booked for the Fourth of July weekend. As I had never been to that p...
  • Connecting Google Apps Education Edition with Blackboard
    Editor's note: George Kroner is a Developer Relations Engineer for Blackboard, a company that focuses on transforming and improving the ...
  • Students and others find what they're looking for with Google Search
    When you think about all that a university has to offer, you probably think of classes, curriculum, and alumni activities. But universities ...
  • 30,000 Valeo employees put Google Apps to work
    Tens of millions of people around the world have transitioned from software-based email and personal productivity tools to powerful web-base...
  • Spelling Suggestions and Thumbnail View in Google Docs
    Google Docs lets you create, store, and share work files with teammates and other colleagues. Today we're making it easier for you to s...
  • Google Apps update: Email migration, shared address book, and a cool video
    Posted by Ryan Pollock, Product Marketing As Vikaram noted on the Official Google Blog , today was a big day for Google Apps. We introduced ...
  • Google Apps on Campus: Getting Things Done in '08
    2008 was an action-packed year for Google Apps for Education . We grew by 300% since last year, released two new products: Google Sites and...
  • Collaborating with Google Apps and Socialwok
    Editor's Note: Ming Yong is co-founder of Socialwok, a a feed-based group collaboration application for enterprises that integrates with...
  • A new look for Google Docs spreadsheets
    When you next open a spreadsheet in Google Docs, you'll notice a number of updates to the spreadsheets interface. The simplified toolbar...

Categories

  • admin
  • Android
  • cloud computing
  • developers
  • earth and maps
  • education
  • enterprise
  • events
  • gmail
  • gonegoogle
  • Google Apps
  • Google Apps Blog
  • Google Calendar
  • google commerce search
  • google docs
  • Google Email Security and Archiving
  • Google Enterprise Search
  • Google I/O
  • Google Maps
  • google message security
  • Google Search Appliance
  • Google Site Search
  • google sites
  • Google spreadsheets
  • Google Video
  • Google Wave
  • government
  • guest post
  • hints and tips
  • innovation
  • IT
  • K-12
  • large business
  • mashups
  • medium business
  • migration
  • mobile
  • new features
  • non-profit
  • partners
  • Postini
  • productivity
  • small business
  • spam and security trends
  • success story
  • switch
  • university
  • viewpoint
  • webinar
  • webmaster

Blog Archive

  • ►  2010 (14)
    • ►  January (14)
  • ▼  2009 (178)
    • ►  December (11)
    • ►  November (12)
    • ►  October (15)
    • ►  September (19)
    • ►  August (18)
    • ▼  July (19)
      • Enhancements to Google Apps Directory Sync
      • Google Apps Connector for BlackBerry Enterprise Se...
      • Virtual Alabama: three years into visualizing our ...
      • Google Apps status updates now in your RSS feed
      • Pearson saves customers time and money with Google...
      • Los Angeles universities take to the clouds with G...
      • Welcoming Google Earth Enterprise users
      • Today's the day: signups open for free Google Mess...
      • Building blocks: connecting Google Apps for Educat...
      • Google Calendar Labs and our first Gmail Labs grad...
      • Switching to Google Apps from Lotus Notes just got...
      • Google Earth Enterprise gets historical, two-dimen...
      • Help customers find their way with new Google Maps...
      • Google Apps Standard Edition: still free
      • Paving the road to Apps adoption in large enterprises
      • Template galleries for Google Apps domains
      • Drag and drop, and organize your labels in Gmail
      • Improvements to Google Apps contacts
      • Q2 2009 Spam Trends
    • ►  June (13)
    • ►  May (15)
    • ►  April (15)
    • ►  March (14)
    • ►  February (13)
    • ►  January (14)
  • ►  2008 (78)
    • ►  December (9)
    • ►  November (16)
    • ►  October (8)
    • ►  September (8)
    • ►  August (3)
    • ►  July (4)
    • ►  June (4)
    • ►  May (5)
    • ►  April (5)
    • ►  March (7)
    • ►  February (5)
    • ►  January (4)
  • ►  2007 (79)
    • ►  December (6)
    • ►  November (7)
    • ►  October (6)
    • ►  September (8)
    • ►  August (4)
    • ►  July (9)
    • ►  June (6)
    • ►  May (10)
    • ►  April (7)
    • ►  March (7)
    • ►  February (1)
    • ►  January (8)
  • ►  2006 (76)
    • ►  December (4)
    • ►  November (6)
    • ►  October (13)
    • ►  September (10)
    • ►  August (6)
    • ►  July (9)
    • ►  June (6)
    • ►  May (7)
    • ►  April (3)
    • ►  March (3)
    • ►  February (7)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile