New Business Software

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 1 October 2009

Q3'09 Spam & Virus Trends from Postini

Posted on 12:00 by Unknown
Editor's note: The spam data cited in this post is drawn from the network of Google email security and archiving services, powered by Postini, which processes more than 3 billion email connections per day in the course of providing email security to more than 50,000 businesses and 15 million business users.

Back in 2007, we saw the first variants of a big virus attack later labeled the "Storm" virus. During that summer, Storm attacked with force, pushing payload spam activity to then-unprecedented levels and sustaining them for several months. The security community eventually caught up, and payload spam activity fell to nominal levels and held there. That is, until this year: Q2'09 saw a significant surge in payload spam activity, and now Q3'09 levels have made the 2007 Storm virus attack look small in comparison. Postini data centers have blocked more than 100 million viruses every day during what has so far been the height of the attack.


The majority (55%) of these viruses are messages like the one you see below, a fake notice of underreported income from the IRS (which the IRS distributed an alert on earlier this week). Another large contingent (33%) have come in the form of fake package tracking attachments, which were already on the rise in Q2. You might think a spoofed IRS notice or package tracking email is obviously spam, and wonder who would fall for it and actually click on the attachment.

However, at these volumes, it takes only a tiny fraction of the recipients being fooled for the spammers to add hundreds of computers to their botnets every day.


ISP takedowns continue, overall spam levels steady

Last quarter we saw a temporary 30% drop in overall spam levels following the 3FN ISP takedown, and the ISP takedown trend continues into Q3 with a new culprit called Real Host, a large Latvia-based ISP that was disconnected by upstream providers on August 1. This takedown didn't have the same drastic effects of McColo (last November), but it was comparable to 3FN. Ultimately, the effects of the Real Host takedown lasted only two days, with an initial 30% drop in spam followed by a quick resurgence.

Overall, spam levels remained steady this quarter, with little growth or decline since the Real Host incident. In Q3, spam as a percentage of total message volume is hovering around 90%, down from the Q2 average of around 95%. Q3'09 average spam levels were down 8% from Q2'09 and on par with levels in Q3'08. Spam levels also saw smaller ups and downs than in previous quarters.


Older spam techniques driving message size up

Last quarter we reported on the trend toward larger message sizes, measured in bytes. The trend has continued into this quarter, making 2009 a year of resurgence in old techniques such as image spam and payload viruses. When considering the spam bytes processed per user, growth has been steep in 2009, with Q3'09 rates up 123% from Q3'08.

Organizations that process spam inside their network should pay attention to this trend. The larger sizes create a bandwidth burden that can impact speed across your network. As the chart shows, Q2'09 delivered the record high to date for spam size – and subsequently for bandwidth drag for teams that manage spam in-house, potentially forcing those organizations to upgrade their capacity limits.


Best practices to optimize your enterprise spam filter

A common piece of feedback we get from our customers is that many of the messages in their spam folder or quarantine seem to come from "them" – from what appear to be valid email addresses from their own domain. These email addresses are actually spoofed (a common technique to mask the real origins of a message), and spammers employ this technique to take advantage of a mistake organizations sometimes make in configuring their spam filters: adding their own domain to their approved sender list.

While this might seem like a good idea at first glance – we want to make sure we don't block email from our colleagues, right? – in practice all it does is open your organization up to spoofed email. With that in mind, we strongly recommend that organizations not add their own domains to their approved sender lists. (Don't worry – legitimate mail from within your domain is correctly identified by filters and generally gets through just fine.)

For more information on how Google email security services, powered by Postini, can help your organization provide better spam protection and take a load off your network by halting spam in the cloud, visit www.google.com/postini.

Posted by Adam Swidler, Google Postini Services team
Email ThisBlogThis!Share to XShare to Facebook
Posted in Google Email Security and Archiving, Postini, spam and security trends | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • ​Modern browsers for modern applications
    ​The web has evolved in the last ten years, from simple text pages to rich, interactive applications including video and voice. Unfortunatel...
  • Help customers find their way with new Google Maps gadget
    Last week, I looked up directions to the hotel in Sacramento that I had booked for the Fourth of July weekend. As I had never been to that p...
  • Connecting Google Apps Education Edition with Blackboard
    Editor's note: George Kroner is a Developer Relations Engineer for Blackboard, a company that focuses on transforming and improving the ...
  • Students and others find what they're looking for with Google Search
    When you think about all that a university has to offer, you probably think of classes, curriculum, and alumni activities. But universities ...
  • 30,000 Valeo employees put Google Apps to work
    Tens of millions of people around the world have transitioned from software-based email and personal productivity tools to powerful web-base...
  • Spelling Suggestions and Thumbnail View in Google Docs
    Google Docs lets you create, store, and share work files with teammates and other colleagues. Today we're making it easier for you to s...
  • Google Apps update: Email migration, shared address book, and a cool video
    Posted by Ryan Pollock, Product Marketing As Vikaram noted on the Official Google Blog , today was a big day for Google Apps. We introduced ...
  • Google Apps on Campus: Getting Things Done in '08
    2008 was an action-packed year for Google Apps for Education . We grew by 300% since last year, released two new products: Google Sites and...
  • Collaborating with Google Apps and Socialwok
    Editor's Note: Ming Yong is co-founder of Socialwok, a a feed-based group collaboration application for enterprises that integrates with...
  • A new look for Google Docs spreadsheets
    When you next open a spreadsheet in Google Docs, you'll notice a number of updates to the spreadsheets interface. The simplified toolbar...

Categories

  • admin
  • Android
  • cloud computing
  • developers
  • earth and maps
  • education
  • enterprise
  • events
  • gmail
  • gonegoogle
  • Google Apps
  • Google Apps Blog
  • Google Calendar
  • google commerce search
  • google docs
  • Google Email Security and Archiving
  • Google Enterprise Search
  • Google I/O
  • Google Maps
  • google message security
  • Google Search Appliance
  • Google Site Search
  • google sites
  • Google spreadsheets
  • Google Video
  • Google Wave
  • government
  • guest post
  • hints and tips
  • innovation
  • IT
  • K-12
  • large business
  • mashups
  • medium business
  • migration
  • mobile
  • new features
  • non-profit
  • partners
  • Postini
  • productivity
  • small business
  • spam and security trends
  • success story
  • switch
  • university
  • viewpoint
  • webinar
  • webmaster

Blog Archive

  • ►  2010 (14)
    • ►  January (14)
  • ▼  2009 (178)
    • ►  December (11)
    • ►  November (12)
    • ▼  October (15)
      • How non-profit organizations go Google
      • A full complement of tools for a quarter the cost
      • New: refinement options for metadata in Google Sit...
      • Singing a new tune: Google Search Appliance now in...
      • Guest post: Australia's Mortgage Choice goes Google
      • Over 2 million companies have #goneGoogle around t...
      • Geek Out on the technical details of a Google Apps...
      • Faculty and staff are going Google, too
      • Easily share collections of files with Google Docs...
      • UK Universities going Google
      • Research finds that IT departments are thinking in...
      • Changes to Google Maps in the US
      • Get your money's worth with cloud-based messaging
      • AMR Research and Mercer discuss the ROI of Content...
      • Q3'09 Spam & Virus Trends from Postini
    • ►  September (19)
    • ►  August (18)
    • ►  July (19)
    • ►  June (13)
    • ►  May (15)
    • ►  April (15)
    • ►  March (14)
    • ►  February (13)
    • ►  January (14)
  • ►  2008 (78)
    • ►  December (9)
    • ►  November (16)
    • ►  October (8)
    • ►  September (8)
    • ►  August (3)
    • ►  July (4)
    • ►  June (4)
    • ►  May (5)
    • ►  April (5)
    • ►  March (7)
    • ►  February (5)
    • ►  January (4)
  • ►  2007 (79)
    • ►  December (6)
    • ►  November (7)
    • ►  October (6)
    • ►  September (8)
    • ►  August (4)
    • ►  July (9)
    • ►  June (6)
    • ►  May (10)
    • ►  April (7)
    • ►  March (7)
    • ►  February (1)
    • ►  January (8)
  • ►  2006 (76)
    • ►  December (4)
    • ►  November (6)
    • ►  October (13)
    • ►  September (10)
    • ►  August (6)
    • ►  July (9)
    • ►  June (6)
    • ►  May (7)
    • ►  April (3)
    • ►  March (3)
    • ►  February (7)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile