1. A Survey of Spam
Mel Huang
Copyright 2009 Trend Micro Inc. 1
2. Outline
• Introduction
• As a Spammer
– Target
– Path
– Content
• Spam Ecosystem
• Anti-spam Solutions
• Do Anti-spam Solutions Work?
Copyright 2009 Trend Micro Inc. 2
3. Introduction
traditional spam
Copyright 2009 Trend Micro Inc. 3
4. Introduction
search social
messaging blog/wiki phone/SMS
engine networking
spam spam spam
spam spam
Copyright 2009 Trend Micro Inc. 4
5. 62T spam emails sent
Introduction 33B kWh energy usage
(could support 2.4M home in US)
17M tons of CO2
% of emails (0.2% of global emissions)
100
90 ?
80
70 Business cost US$130B
60 Spammers earned US$780M
50 Anti-spammers earned US$5B
40
30 Filtering saves 135B kWh
20
10
0
1971 … 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010
1998 "Spam and the Ongoing Battle for the Inbox,” Communications of the ACM, 2007
2001 "Ending Spam's Free Ride," ACM Networker, 2003
2003 "Spam and the Social-Technical Gap," IEEE Computer, 2004
2004 "Bot Software Spreads, Causes New Worries," IEEE Distributed Systems Online, 2004
2005 "Scalable and Reliable Collaborative Spam Filters: Harnessing the Global Social Email Networks," CEAS 2005
2006 "The E-Mail Honeypot System - Concept, Implementation and Field Test Results," IEEE International Conference on the Digital Society, 2008
2007 "Spam and the Ongoing Battle for the Inbox," Communications of the ACM, 2007
2008 "The Economics of Botnets," Kapersky Lab, 2009
2010 "Correlating Spam Activity with IP Address Characteristics," IEEE Conference on Computer Communications, 2010
Related statistics http://ferris.com/reports/industry-statistics/
McAfee’s report http://www.mcafee.com/us/resources/reports/rp-carbonfootprint2009.pdf
Copyright 2009 Trend Micro Inc. 5
6. As a Spammer
social
economic
moral “Freakonomics,” 2005
Copyright 2009 Trend Micro Inc. 6
8. As a Spammer
path
target
content
Screenshot from Angry Birds by Rovio ®
Copyright 2009 Trend Micro Inc. 8
9. ?
As a Spammer
• Target
– web crawler
– dictionary trial and error
– steal member list “Who gets spammed?” Communications of the ACM, 2006
– buy from others
“Do Zebras get more Spam than Aardvarks?“ CEAS, 2009
“Understanding How Spammers Steal Your E-Mail Address,” CEAS, 2005
Copyright 2009 Trend Micro Inc. 9
10. As a Spammer
• Path
ESP/ISP
open proxy/relay
botnet
Copyright 2009 Trend Micro Inc. 10
11. As a Spammer “The E-Mail Honeypot System,” CEAS, 2008
“Spamming Chains,“ CEAS, 2009
“On the Spam Campaign Trail,” 2008
“Spamalytics,” Communications of the ACM, 2009
• Path
ESP/ISP
open proxy/relay
botnet
Copyright 2009 Trend Micro Inc. 11
12. As a Spammer “Anti-Honeypot Technology,” IEEE Security and Privacy, 2004
“Spamming Chains,“ CEAS, 2009
• Path
Copyright 2009 Trend Micro Inc. 12
13. As a Spammer
• Content
salad
jbvxc8b890
fjdaslioejw
jvcxzjvo bxjcv0g9d
jvsd9jowe rkstjkfs
fjew09as vcx89gjdf
bvxciobd bcvxklmkwr
random characters
“A Survey of Modern Spam Tools,” CEAS 2008
Copyright 2009 Trend Micro Inc. 13
14. Spam Ecosystem
EU$199 free to EU$599
“Anti-Honeypot Technology,” IEEE Security and Privacy, 2004 “A Survey of Modern Spam Tools,” CEAS 2008
response rate 0.0001% to survive
“Who Gets Spammed?” Communications of the ACM, 2006
“Spamalytics,” Communications of the ACM, 2009
honeypot hunter
spam tools providers
US$70 for 1000+ spammers US$1000-2000/month
“The Ecomonics of Botnets,” Kaspersky Lab, 2009
US$1000 for 10M+
“The Ecomonics of Botnets,” Kaspersky Lab, 2009
phishing hosting
rent for US$20/month/online bot
sell for US$0.5/bot
target harvesters average sending rate: 10 messages/min/bot
“The Ecomonics of Botnets,” Kaspersky Lab, 2009
botnet owners
Copyright 2009 Trend Micro Inc. 14
15. Unsolicited Bulk Email
Unsolicited Commercial Email Excuse me!
I’m a newsletter.
Anti-spam Solutions
Unsolicited Email
• Law
Junk Email
– spam definition?
• Pricing
– Microsoft Penny Black Project
Student Home Professional Enterprise
– Yahoo! CentMail US$99 US$999 US$9999 US$99999
“Spam and the Ongoing Battle for the Inbox,” Communications of the ACM, 2007
• Technology
“Spam and the Social-Technical Gap,” IEEE Computer, 2004
Copyright 2009 Trend Micro Inc. 15
16. Anti-spam Solutions
• Technology
– social networks
– content solutions “Leveraging Social Networks to Fight Spam,” IEEE Computer, 2005
“Scalable and Reliable Collaborative Spam Filters,” CEAS, 2005
• Bayesian filter “Saving Private E-mail,” IEEE Spectrum, 2003
• rules-based filter
– network solutions
• rule-based filter (black/gray/whitelist)
• authentication (DKIM, SenderID, …) “Filtering Spam E-mail on a Global Scale,” WWW Alt., 2004
“Stopping Spam by Extrusion Detection,” CEAS, 2004 “IPv6 and Spam,” MIT Spam Conference, 2009
“Stopping Outgoing Spam by Examining Incoming Server Logs,” CEAS, 2005
“Using Early Results from the spamHINTS Project to Estimate an ISP Abuse Teams Task,” CEAS, 2006 “Understanding Address Usage in the Visible Internet,” 2009
Copyright 2009 Trend Micro Inc. 16
17. Do Anti-spam Solutions work?
“Spamalytics,” Communications of the ACM, 2009 < 0.0001% > 0.0001% > 0.0001%
Copyright 2009 Trend Micro Inc. 17
18. Ah… Ah… Ah…
Copyright 2009 Trend Micro Inc. 18