Find White Papers
Home
About Us
List Your Papers
    
> MessageLabs > Block Evolving Spam, Secure Your Network

Block Evolving Spam, Secure Your Network

White Paper Published By: MessageLabs

New spamming techniques are upon us -  419 spam, botnets, CAPTCHA cracking – what’s next from the 'bad guys'? Spam remains the biggest email-born threat to businesses. Learn how to protect your business.  FREE Whitepaper (PDF/40KB)



Tags : 
messagelabs, secure network, block spam, spamming techniques, spam, business threat, networking, security

MessageLabs
Published:  Jan 13, 2009
Type:  White Paper
Length:  4 pages

Block Evolving Spam,
Secure Your Network
A MessageLabs Whitepaper; November 2008have adopted to get around this problem is to create Managed Block Evolving Spam, thousands of webmail accounts on services such Services or Secure Your Network as hotmail, gmail and yahoo (although not limited Email Spam is Growing Faster Every Year, to these). It is impossible for most receiving sites "in-the-cloud Especially in the United States. to blacklist these sources, so they are limited to content filtering to detect the spam. In order to create scanning" is Today new forms of spam are much more these thousands of accounts the spammers have dangerous than their predecessors, presenting developed computer software designed to break the fast becoming serious threats to any business that happens to so called "CAPTCHA" (Completely Automated Public receive them. Managed Services or "in-the-cloud Turing test to tell Computers and Humans Apart) the most scanning" is fast becoming the most effective way images which are placed on these sites to prevent to proactively protect the corporate network.effective way automated sign-ups. The spammers are able to decode CAPTCHAs at a success rate of higher than to proactively This whitepaper will give you insight into the most 30%, giving them almost limitless accounts.prominent spamming techniques used during protect the 2008 including CAPTCHA Cracking, SQL Injection Increased Botnet Power Botnets and 419 spam. This paper will also Modern botnet spam sending engines such as the corporate highlight why stopping these threats at the internet Srizbi botnet engine are multi-threaded and use layer via a managed service is the only way to very low level kernel hooks to allow them to send network. combat new evolving spam attacks. spam even faster than before. By bypassing the normal Windows networking functions these botnets can go undetected by software firewalls, and send A New Generation of Spam and volumes of spam up to millions of emails per day the Related Risks using a single consumer PC. The new botnets also Spammers are constantly evolving and incorporate techniques for going to sleep if they enhancing their tactics to thwart traditional detect that the computer is in use by its owner. This corporate defences. The latest of which are prevents the often cited technique for knowing your outlined below. PC is infected of checking whether it is going slower than normal.CAPTCHA Cracking Spammers have a finite set of resources, one of Furthermore, the volume of botnets around the world which is machines from which to send their spams continues to increase, with Srizbi now the largest from. The common spammer way around this botnet we have ever tracked, with over 1.2 million has been to create huge botnets of infected PCs, active spam sending machines, and millions more however these often get blacklisted quickly and inactive. (See figure 1 below to understand how become hard to use. One technique spammers botnets function).
Fig. 1: The Anatomy of a Botnet
2 WHITEPAPER: Block Evolving Spam, Secure Your NetworkSQL Injection Botnet The multi-layered technology approach includes four The Asprox botnet has an interesting technique for preventative layers (see Figure 2 below): MessageLabs propagating itself to more hosts. Rather than sending Email Anti-Spam emails out to achieve this it will attack random Inboundweb sites on the internet using a technique known emailservice is a fully as SQL Injection. This is a widely known security vulnerability that many web sites have. The Asprox managed service botnet will seek out and find vulnerable web sites, Traffic Managementinjecting Javascript into the web pages of these that provides perfectly legitimate sites, causing visitors to become Connection Managementinfected with the botnet. unparalleled siegCommercial Scanners loo ability in keeping nAsprox's email system is specifically designed for hcesending phishing emails. SkepticT TT all kinds of ticpeIncreased level of 419s: kS spam away Related to the CAPTCHA cracking is the increased volume of 419 or "Nigerian Scam" emails. These Cleanfrom corporate inboxare simple advanced fee frauds which often appear to be too good to be true (either in the form of networks; vast sums of money available for the taking, or as Fig. 2: The MessageLabs Multilayered Email Anti-Spam Servicelottery winnings). The scammers almost exclusively d... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search