TechRepublic : A ZDNet Tech Community

IT Security

Host: Chad Perrin
Contact

Incredibly, out of every 10 e-mail messages sent nine contain spam and that’s a new record.

——————————————————————————————————————-

Every month, Symantec’s MessageLabs releases statistics on the state of e-mail spam. In the May 2009 report, MessageLabs had the dubious honor of reporting that the number of e-mail messages containing spam reached an all-time high of 90.4%:

I’m not sure about you, but to me it’s hard to grasp that nine out of every ten e-mail messages is unsolicited spam. On a brighter note, the number of e-mail messages containing virus code has decreased to one in 317 e-mail messages:

Also the number of e-mail messages containing phishing content is leveling off at one in 279 e-mail messages:

Security experts aren’t surprised at the last two statistics, they even expected it. Users being more cognizant of phishing schemes and improved e-mail scanning are forcing the bad guys to find different tactics to ply their trade. Currently, the preferred methods are via malicious fake Web sites or compromised official Web sites.

Time of day matters

It may not seem like it, but the time you are most likely to get e-mail spam depends on your geographical location. If you live in the United States you can expect the most spam e-mail between 9 and 10 a.m. local time:

People in Europe can expect a fairly consistent increase in spam throughout the day:

People in the Pacific Rim area will be happy to know that their mailboxes will be full of spam right away in the morning.

At first, I didn’t understand the logic behind the sending times. But as I read further, the report came up with three possible explanations for the distribution being the way it is:

  • Spammers are predominantly active during the US working day.
  • Most active spammers are located in the United States
  • Spammers are timing spam delivery to coincide with largest on-line audiences.

Here’s two more interesting tidbits:

  • Sunday must be a day of rest for spam operators as spam levels drop considerably on that day.
  • Monday and Friday are peak spam activity days.

Europe tops the list

The battle for top honors in spam origination is a close race, with Europe taking the top slot in May:

  1. 31.6% from Europe
  2. 27.8% from Asia
  3. 21.4% from South America
  4. 13.4% from North America

Deciding first place is becoming increasingly difficult as 60% of all spam is sent from botnets. Since botnet members are more or less evenly distributed around the world, the spam origination statistic is beginning to lose significance.

Top spamming botnet

What may be more relevant is the amount of spam sent by each botnet:

  1. 18.2% from Donbot
  2. 16.1% from Rustock
  3. 8.6% from Cutwail
  4. 6.3% from Bagle

The report goes on to state that there’s a significant amount of spam (40%) being sent out by smaller and relatively unknown botnets. Also the people controlling these botnets seem to prefer using stolen Web-based e-mail accounts like Gmail for sending spam.

One explanation for that is, using stolen Gmail accounts allow botmasters to apply spear-phishing and social-engineering techniques on the specifically targeted organizations or individuals. This usually increases the success rate. Using Web-based e-mail accounts also increases the likelihood of getting to the intended victim since most administrators don’t filter e-mail emanating from sources like Gmail.

Final thoughts

I know a lot of high-powered groups are working on the spam problem, but these reports show little if any progress on their part. Every day, I check spam filters for several clients and it’s amazing. For example, a spam filter for one client (only 20 users) captures over 5000 spam e-mails each day. What’s going to happen when desired e-mail messages are only a fractional percent of the total amount of those sent?

I hope the experts figure something out soon, as this kind of growth can’t continue much longer. Finally, I’d like to thank MessageLabs for their help in supplying the statistics and graphs.

Michael KassnerMichael Kassner has been involved with with IT for over 30 years. Currently a systems administrator for an international corporation and security consultant with MKassner Net. Read his profile or Twitter at MKassnerNet.

Print/View all Posts Comments on this blog

9 out of every 10 e-mail messages is spam Michael Kassner | 06/12/09
Right now, I can't get into my gmail account... JCitizen | 06/12/09
Blocking all email communications until a counter CG IT | 06/12/09
That seems like a good attitude Michael Kassner | 06/12/09
I'm very tempted to use it on my personal account.. JCitizen | 06/12/09
30 day free trial Michael Kassner | 06/12/09
Great! I will be looking into it.. JCitizen | 06/12/09
Postini issues decalgal | 06/29/09
That's not good Michael Kassner | 06/30/09
I find that method highly frustrating... Forum Surfer | 06/16/09
I never thought Michael Kassner | 06/16/09
Actually... Forum Surfer | 06/16/09
As I see it Michael Kassner | 06/16/09
Not mean or rude at all.. JCitizen | 06/16/09
Red Condor Michael Kassner | 06/12/09
I would definitely been talking about that one.. JCitizen | 06/12/09
Some local ISPs Michael Kassner | 06/12/09
Hopefully Red Condor is more effective.. JCitizen | 06/13/09
Nope Michael Kassner | 06/13/09
greylisting Jaqui | 06/14/09
Web-based services Michael Kassner | 06/14/09
web based Jaqui | 06/14/09
Gotcha Michael Kassner | 06/14/09
Filter on content and also report any found. Deadly Ernest | 06/12/09
To some extent Michael Kassner | 06/12/09
I wouldn't use Gmail in a business environment either, but Deadly Ernest | 06/12/09
I get the occasional glitch with LIve! also, but... JCitizen | 06/13/09
Live =Hotmail? Michael Kassner | 06/13/09
Live = Hotmail: True Technous285 | 06/14/09
Thanks Michael Kassner | 06/15/09
Nothing noticeable Technous285 | 06/15/09
I appreciate Michael Kassner | 06/16/09
It's okay Technous285 | 06/16/09
I was forced, with a lot of other clients... JCitizen | 06/14/09
Wow that's a lot Michael Kassner | 06/15/09
That's a great idea... JCitizen | 06/15/09
If I can Michael Kassner | 06/15/09
Hopefully they don't get into a trademark fight over.. JCitizen | 06/15/09
Already TM'ed Michael Kassner | 06/16/09
One interesting way to deal with spam that I've seen Deadly Ernest | 06/12/09
Interesting process Michael Kassner | 06/12/09
There are a number of possible solutions, but cost and time Deadly Ernest | 06/12/09
Wonder if that would work with Outlook/Express? JCitizen | 06/13/09
It depends on how you set it up Deadly Ernest | 06/13/09
Thank you, Ernest santeewelding | 06/13/09
You're welcome - I aim to please but am not a marksman Deadly Ernest | 06/13/09
I confer upon thee santeewelding | 06/13/09
Interesting, down here Deadly Ernest | 06/13/09
You are not, sir santeewelding | 06/13/09
Curious Michael Kassner | 06/14/09
Yes, they retain copies and every couple of months Deadly Ernest | 06/14/09
That's what I do Michael Kassner | 06/14/09
Thanks DE! That is very interesting! =) ..(nt) JCitizen | 06/14/09
Just curious Michael Kassner | 06/15/09
Michael, the only time I actual access my Gmail account Deadly Ernest | 06/15/09
Still you should Michael Kassner | 06/15/09
Just had a look at that article and tried to go to the Deadly Ernest | 06/15/09
I don't Michael Kassner | 06/15/09
I'm running an experiment for the next few weeks, Deadly Ernest | 06/15/09
Good test Michael Kassner | 06/15/09
Adblock Plus is nice!.. JCitizen | 06/15/09
I'm going to have to Michael Kassner | 06/15/09
Spyware Blaster does the same thing... JCitizen | 06/15/09
You're saying Michael Kassner | 06/16/09
not sure who you were asking, but Deadly Ernest | 06/16/09
Sponsored adds Michael Kassner | 06/16/09
Obviously my ad blocking system works as I don't see any Deadly Ernest | 06/16/09
But, you may Michael Kassner | 06/16/09
Michael, I'm not sure I can do that as I don't have anything Deadly Ernest | 06/16/09
Thanks Michael Kassner | 06/16/09
Thanks DE.. JCitizen | 06/16/09
It's incredible, isn't it? seanferd | 06/12/09
I've been Michael Kassner | 06/13/09
Here's something of Interest CG IT | 06/13/09
Looks like this could be integrated.. JCitizen | 06/13/09
Average here is about 6,000 davidt@... | 06/15/09
How many Michael Kassner | 06/15/09
21, now davidt@... | 06/16/09
Are you Michael Kassner | 06/16/09
Not necessarily davidt@... | 06/16/09
I see that a lot Michael Kassner | 06/16/09
Which version/hardware/firmware?... JCitizen | 06/15/09
Our Barracuda is a bit over a year old davidt@... | 06/16/09
Thanks davidt...very interesting!..(nt) JCitizen | 06/16/09
Subscription? Michael Kassner | 06/16/09
Yeah, I fought for 2 years for it davidt@... | 06/16/09
Symantec needs Michael Kassner | 06/16/09
Not really an option here davidt@... | 06/16/09
Some IT pros who seem to be in the know... JCitizen | 06/16/09
I have the same setup Michael Kassner | 06/16/09
in 1.5 hours today one customer had 5700 CG IT | 06/12/09
Wow Michael Kassner | 06/12/09
Mike believe it or not, only 16 users CG IT | 06/12/09
That's amazing Michael Kassner | 06/12/09
"ineffectual advertising" santeewelding | 06/12/09
If the defects Michael Kassner | 06/12/09
By the wayside.. santeewelding | 06/12/09
If they pay $100 for a million spam mails and get a 0.1% Deadly Ernest | 06/12/09
I realize Michael Kassner | 06/13/09
However cost of transmission is low.. JCitizen | 06/12/09
There's no cost Michael Kassner | 06/12/09
Just the small amount of time to create it... JCitizen | 06/13/09
Botnet or Spam? Michael Kassner | 06/13/09
Yep! I don't think many in the general public know that.. JCitizen | 06/14/09
Much appreciated Michael Kassner | 06/15/09
It would be interesting to bring in laws that made it Deadly Ernest | 06/12/09
Whoever attacks the UK redirects to attack Australia BALTHOR | 06/12/09
I was getting worried Michael Kassner | 06/13/09
If he's like me.. JCitizen | 06/13/09
Hope your OK now Michael Kassner | 06/13/09
Health be to you, and yours. JCitizen | 06/15/09
What ever you're doing Michael Kassner | 06/16/09
I'd love to know how they tell Deadly Ernest | 06/12/09
the enterprise spam filters have reporting CG IT | 06/12/09
Exactly Michael Kassner | 06/12/09
Hey, let's start an anti-spam spam campaign Deadly Ernest | 06/12/09
Two possible issues Michael Kassner | 06/13/09
The question there is Deadly Ernest | 06/13/09
That's actually pretty easy Michael Kassner | 06/13/09
Correct, they could, but the emails I've seen by the spammers Deadly Ernest | 06/13/09
Good point Michael Kassner | 06/13/09
maybe all the spam and the inability to deal with Deadly Ernest | 06/13/09
politics and $$ CG IT | 06/13/09
The basic concept is good for a corporate lan or wan Deadly Ernest | 06/13/09
Not as I see it Michael Kassner | 06/13/09
Michael, i think we're on the same wave length but Deadly Ernest | 06/13/09
Oh your one comment mislead Michael Kassner | 06/13/09
Me too!! JCitizen | 06/13/09
Boy, it's really obvious this weekend Jaqui | 06/14/09
the funny thing is Jaqui | 06/14/09
I love the spam mails telling me UPS has a parcel for me Deadly Ernest | 06/14/09
yeah Jaqui | 06/14/09
I used to love getting the PayPal spam before I got a PayPal Deadly Ernest | 06/14/09
On my one server based email account... JCitizen | 06/14/09
many spam emails are set to automatically Deadly Ernest | 06/14/09
All sorts of tricks Michael Kassner | 06/15/09
Great! We seem to be hitting on a few good ones lately! JCitizen | 06/15/09
Twp points Michael Kassner | 06/14/09
no doubt, Jaqui | 06/14/09
sweet Jaqui | 06/14/09
Thanks for sharing that Michael Kassner | 06/14/09
Cool! Maybe you could put header information... JCitizen | 06/14/09
Don't you be thinking about santeewelding | 06/14/09
There ya go! Just like my clients! =) .... JCitizen | 06/15/09
On a short list Michael Kassner | 06/15/09

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



IT Professional's Guide to Policies and Procedures, Third Ed
Whether you're creating policies for management, training, personnel, support, privacy, Internet/e-mail usage, security, or inventory, you'll meet the needs of your entire enterprise with this one download!
Buy Now
500 Things Every Technology Professional Needs to Know
Did you know Microsoft's RegClean does not work with XP but you can use shareware to clean your registry? Did you know most wireless access points don't have encryption enabled by default? Did you know there are 500 tidbits of information contained in TechRepublic's 500 Things Every Technology Professional Needs to Know that will help you become a successful IT professional.
Buy Now

SmartPlanet

Click Here