Risk

11/18/2010
11:53 AM
50%
50%

Researchers Link Most Spam To Only 50 ISPs

Discovery that spammers are using only a relative handful of Internet providers suggests new ways of stopping botnets.

How Firesheep Can Hijack Web Sessions
(click image for larger view)
Slideshow: How Firesheep Can Hijack Web Sessions

Only 50 Internet service providers (ISPs) host the majority of the world's spam, according to a new study, and that finding could reshape private and public approaches to combating the botnets that infect computers and then use them as spam mailers.

The study was conducted for the Organization for Economic Cooperation and Development (OECD) by researchers at Delft University of Technology in the Netherlands and Michigan State University, who examined 109 billion spam messages from 170 million unique IP addresses, gathered via a "spam trap" from 2005 to 2009.

One major finding is that where there's spam, you'll find an infected -- aka zombie -- machine. That's because according to the study data, on average 80% to 90% of the world's spam comes from infected machines.

Researchers also found that the 33 member countries that comprise the OECD, as well as Estonia, the Russian Federation, Brazil, China, India, Indonesia, and South Africa, "harbor over 60% of all infected machines worldwide registered by the spam trap." In other words, the majority of infected machines aren't laying low in countries nearly off the grid.

But perhaps the biggest surprise, said the researchers, was that "we discovered that infected machines display a highly concentrated pattern." In particular, "the networks of just 50 ISPs account for around half of all infected machines worldwide." In other words, "the bulk of the infected machines are not located in the networks of obscure or rogue ISPs, but in those of established, well-known ISPs."

The results suggest a formidable new way to block botnets. With a caution that historical data is no guarantee of future botnet behavior, the researchers said that "current efforts to bring about collective action -- through industry self-regulation, co-regulation, or government intervention -- might initially achieve progress by focusing on the set of ISPs that together have the lion's share of the market."

In other words, if policymakers want to maximize their bang for buck, start by improving the security practices of the 50 ISPs that host half the world's spam.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11506
PUBLISHED: 2018-05-28
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer.
CVE-2018-11507
PUBLISHED: 2018-05-28
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp.
CVE-2018-11505
PUBLISHED: 2018-05-26
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
CVE-2018-6409
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVE-2018-6410
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.