Weblog entry #288 for simonw

Changes in Spam Levels this week
Posted by simonw on Thu 13 Nov 2008 at 20:56
Tags:

There has been discussion on various forums about the disconnection of McColo, and spam volumes. At work spam attempts have increased, but we are a small sample, and others have a better position to judge.

If you know of online metrics of spam volumes like the graphs linked to below please post a them in a comment!

Initial reports claimed a 75% reduction in spam levels as a step change around 16:00 EST on Tuesday.

The variable experience of Internet spam by different mail servers always hinted that there are a relatively small number of people behind a lot of the spam.

The data from SpamCop and DCC are consistent with each other, suggesting they have enough data to be representative. The results are not a 75% reduction, but still something clearly caused major disruption to the world's spam supply on Tuesday afternoon.

Botnet researchers had said previously that many botnets were fed fairly directly from hosted servers, and the bots were just amplifying proxy servers, and a small number of companies were involved in hosting the back-end servers feeding these bots. They seem to have been right.

Reasonable questions include why did it take so long? Is there any law enforcement action going on in the background?

The compromised PCs, and the vulnerabilities that allowed them to be compromised are still out there. More secure botnets will fill the vacuum. This is an opportunity for those fighting spam to step back, and plan their next steps, and lobby for more enforcement action against online criminals. Not that I think enforcement is the answer, but my email inbox is the only place I'm daily approached by criminals.

Background reading:

 

Comments on this Entry

Posted by Anonymous (62.140.xx.xx) on Fri 14 Nov 2008 at 09:03
Since June of this year we have averaged between 3,500 and 4,000 identified spam each working day. (That's when we introduced our new MailScanner box.)

As of Tuesday, this has not exceeded 2,000. Although I may be described as a bit premature, this sounds quite good to me.

Equally, it may just be that my filters aren't as successful anymore.... I prefer not to think of it that way.

The volume of delivered mail has not changed from the usual 12,000 a day for c. 300 users. (This figure is combined internal and external and includes mailing lists and mail groups.)

[ Parent | Reply to this comment ]

Posted by Anonymous (86.53.xx.xx) on Fri 14 Nov 2008 at 12:46
I've written a bit about it over at http://www.generatesuccess.co.uk/spammers-silenced-by-service-sup pliers/76 - I'd love to see some legal action against them, to fine them whatever profits they made from spam-hosting and then a penalty, but I doubt it will happen. At least this looks like it will cut our data transfer and electricity costs - maybe noticeably so!

[ Parent | Reply to this comment ]

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search