Showing posts with label spam and security trends. Show all posts
Showing posts with label spam and security trends. Show all posts

Thursday, October 1, 2009

Q3'09 Spam & Virus Trends from Postini

Editor's note: The spam data cited in this post is drawn from the network of Google email security and archiving services, powered by Postini, which processes more than 3 billion email connections per day in the course of providing email security to more than 50,000 businesses and 15 million business users.

Back in 2007, we saw the first variants of a big virus attack later labeled the "Storm" virus. During that summer, Storm attacked with force, pushing payload spam activity to then-unprecedented levels and sustaining them for several months. The security community eventually caught up, and payload spam activity fell to nominal levels and held there. That is, until this year: Q2'09 saw a significant surge in payload spam activity, and now Q3'09 levels have made the 2007 Storm virus attack look small in comparison. Postini data centers have blocked more than 100 million viruses every day during what has so far been the height of the attack.


The majority (55%) of these viruses are messages like the one you see below, a fake notice of underreported income from the IRS (which the IRS distributed an alert on earlier this week). Another large contingent (33%) have come in the form of fake package tracking attachments, which were already on the rise in Q2. You might think a spoofed IRS notice or package tracking email is obviously spam, and wonder who would fall for it and actually click on the attachment.

However, at these volumes, it takes only a tiny fraction of the recipients being fooled for the spammers to add hundreds of computers to their botnets every day.


ISP takedowns continue, overall spam levels steady

Last quarter we saw a temporary 30% drop in overall spam levels following the 3FN ISP takedown, and the ISP takedown trend continues into Q3 with a new culprit called Real Host, a large Latvia-based ISP that was disconnected by upstream providers on August 1. This takedown didn't have the same drastic effects of McColo (last November), but it was comparable to 3FN. Ultimately, the effects of the Real Host takedown lasted only two days, with an initial 30% drop in spam followed by a quick resurgence.

Overall, spam levels remained steady this quarter, with little growth or decline since the Real Host incident. In Q3, spam as a percentage of total message volume is hovering around 90%, down from the Q2 average of around 95%. Q3'09 average spam levels were down 8% from Q2'09 and on par with levels in Q3'08. Spam levels also saw smaller ups and downs than in previous quarters.


Older spam techniques driving message size up

Last quarter we reported on the trend toward larger message sizes, measured in bytes. The trend has continued into this quarter, making 2009 a year of resurgence in old techniques such as image spam and payload viruses. When considering the spam bytes processed per user, growth has been steep in 2009, with Q3'09 rates up 123% from Q3'08.

Organizations that process spam inside their network should pay attention to this trend. The larger sizes create a bandwidth burden that can impact speed across your network. As the chart shows, Q2'09 delivered the record high to date for spam size – and subsequently for bandwidth drag for teams that manage spam in-house, potentially forcing those organizations to upgrade their capacity limits.


Best practices to optimize your enterprise spam filter

A common piece of feedback we get from our customers is that many of the messages in their spam folder or quarantine seem to come from "them" – from what appear to be valid email addresses from their own domain. These email addresses are actually spoofed (a common technique to mask the real origins of a message), and spammers employ this technique to take advantage of a mistake organizations sometimes make in configuring their spam filters: adding their own domain to their approved sender list.

While this might seem like a good idea at first glance – we want to make sure we don't block email from our colleagues, right? – in practice all it does is open your organization up to spoofed email. With that in mind, we strongly recommend that organizations not add their own domains to their approved sender lists. (Don't worry – legitimate mail from within your domain is correctly identified by filters and generally gets through just fine.)

For more information on how Google email security services, powered by Postini, can help your organization provide better spam protection and take a load off your network by halting spam in the cloud, visit www.google.com/postini.

Posted by Adam Swidler, Google Postini Services team

Wednesday, July 1, 2009

Q2 2009 Spam Trends

Editor's Note: The spam data cited in this post is drawn from the network of Google email security and archiving services, powered by Postini, which provide email security to more than 50,000 organizations, including businesses of all sizes, government agencies, and educational institutions. To learn more about what the Gmail team is doing to keep spam out of your inboxes, check out this post.

Our "Spam Trend" update last quarter summarized the rise in both levels and types of spam, with new players and techniques entering the market. This quarter, proliferation continues, with an unpredictable pattern of drops and spikes as 2009 moves along. Overall, spam is measurably up: Q2'09 average spam levels are 53% higher than in Q1'09 and 6% higher than in Q2'08.

After last November's McColo ISP takedown, when spam volumes dropped by 70%, spammers worked overtime to fill the void. They succeeded: Within four months, spam levels rose back to pre-McColo levels. This upward trend continued through June 4, when another large ISP spam source, 3FN, was reported to have been dismantled. Spam volume immediately dropped 30% – not as extreme as McColo, but still significant. Although this created a sudden dip in spam levels, it also created an open invitation for opportunistic spammers to once again seize a market opportunity.

Over the coming months, we anticipate watching new players once again drive spam levels back up. Since June 4, spammers have already made up a significant amount of ground, climbing 14% from the initial drop.

Here's what the trend looked like, as tracked through Postini filters, over the past six months:


"Unpredictability" summarizes the overall trend as Q2'09 winds down and spammers test both new and "retro" techniques. For example, on June 18 we tracked a new attack that unleashed 50% of a typical day's spam volume in just two hours' time. This attack used a simple "newsletter" template – somewhat "old school" by today's spam standard – with malevolent links and images inserted into the content. Google's Postini filters detected more than 11,000 variants of this spam during those two hours. Because this spam enabled spoofing of the recipient domain (meaning the "from" field was falsified), distribution lists were especially hard-hit by this attack.


Resurgence of image spam

One of the other trends we're watching closely is the sudden popularity of "image spam"a form of spam that rose to prominence in 2007, before most anti-spam filters learned how to block it. It's simple stuff: basic email with advertising content, usually containing a related image. They can also include malicious links or contentand either way, the large file size of an image spam can place a heavy load on an email network.

An image spam email might look something like this:



Evidence of the resurgence in image spam can be seen in the graph below, which shows that the actual size of spam messages, measured in bytes, is back on the rise:


There are a couple of possible explanations for the resurgence in image spam, despite the fact that most spam filters out there have adapted to the technique. One theory is that this wave is designed to test the defenses
of the different spam filters out there, so that spammers can do statistical analysis on what subject lines and content have the highest probability of success.

Another is that there may be some new players entering the spam game, following the McColo and 3FN takedowns, and these new players are opening with some well-tested techniques. Either way, we're watching this trend and will share insights as we gain them in the weeks and months ahead.

Spike in payload viruses

June was also an active month for viruses sent as email attachments, otherwise known as "payload viruses." Volumes rose to their highest level in almost two years as spammers returned to yet another tried-and-true technique to expand their botnets.

As you can see in the chart below, June's activity is almost as high as the two-month payload virus surge seen in Q3'07. Fortunately, Google's Postini zero-hour heuristics detected this uprise early and kept payload attacks in the cloud and away from users' email networks.


Everything old might be new again

In summary, Q2'09 saw continued unpredictability and the resurgence of old-style spam attacks. Are spammers finally running out of original ideas? And if so, like Hollywood, are we now starting to see spam "remakes," based on originals of a few years ago? And what are spammers looking to accomplish as they unleash these remakes? Only time will tell.

For more information on how Google email security services, powered by Postini, can help your organization provide better spam protection and take a load off your network by halting spam in the cloud, visit www.google.com/postini.

Posted by Amanda Kleha, Google message security and archiving team

Tuesday, March 31, 2009

Spam data and trends: Q1 2009

Editor's Note: The spam data cited in this post is drawn from the Google enterprise security and archiving security network (Postini), which delivers an added layer of security for standalone mail servers and Google Apps Premier Edition customers. For a discussion of the anti-spam measures included in Gmail, please see this post from the Gmail blog.

In providing email security to more than 50,000 businesses and 15 million business users, Google security and archiving services, powered by Postini, process and cull spam from more than three billion enterprise email connections every day. This gives us strong insights into the state of the spam industry, some of which we share in regular posts to this blog.

R
ead on for a quick overview of spam trends and events in the first quarter of 2009.

What we saw in the Postini data centers

The most significant spam-related event in the first quarter of 2009 occurred when spam volume returned to pre-McColo takedown levels. By the second half of March, seven-day average spam volume was at the same volume we saw prior to the blocking of the McColo ISP in November 2008.


Spammers have clearly rallied following the McColo takedown, and overall spam volume growth during Q1 2009 was the strongest it's been since early 2008, increasing an average of 1.2% per day. To put that number into context, the growth rate of spam volume in Q1 2008 was approximately 1% per day – which, at the time, was a record high.

Of course, like every year before it, 2008 set a new record for overall spam volume. But in 2008 spam growth flattened over the summer and early fall, and then fell off a cliff after the McColo takedown (daily growth declined to .8%, .3%, and then .01% in the last three quarters of the year). This pattern raises some interesting questions regarding what we can expect in the rest of 2009: Will spam growth once again flatten or decline after a strong first quarter? Or have spammers – as part of their recovery from the McColo takedownrebuilt botnets to be capable of sustaining or even accelerating this early growth spurt?

It's difficult to ascertain exactly how spammers have rebuilt in the wake of McColo, but data suggests they're adopting new strategies to avoid a McColo-type takedown from occurring again. Specifically, the recent upward trajectory of spam could indicate that spammers are building botnets that are more robust but send less volumeor at least that they haven't enabled their botnets to run at full capacity because they're wary of exposing a new ISP as a target.

New types of spam

The most significant development in spam vectors this quarter was the appearance of location-based spam. In this type of attack, users click on a link in a spam message and are directed to a page that contains a fraudulent news headline describing a crisis or disaster in a major city nearby. The attack customizes the location for each user by determining the geolocation of the user's source IP and then identifying the nearest major city. The addition of location creates a heightened level of interest, and the user is tempted to click on the embedded video – which in turn downloads a virus to his or her machine.

Meanwhile, the economy, financial markets, job cuts, and resume help continue to be the most prominent topics spammers are employing as lures for more traditional attacks. We also saw increased spam activity around the U.S. presidential inauguration and St. Patrick's Day, in keeping with the recent propensity spammers have demonstrated for reading the news and keeping their eyes on the holiday calendar in targeting their attacks.

Virus roundup

In early 2008, a trend emerged in which we saw spam messages with attached viruses (otherwise known as "payload viruses") spiking every Sunday, possibly targeting a maintenance window to catch corporate defenses when they were undergoing scheduled updates.


This year we've seen the payload viruses spread out across every day of the week, with no immediately obvious pattern in their distribution. It's difficult to say for certain what prompted the change, but one possible explanation is that spammers switched tactics because they weren't seeing the success they'd hoped for from the focused attacks.


Of course, p
ayload viruses have also seen a recent spike overall -- in the month of March we saw a 9x increase from February. This pales in comparison to the highs we saw last summer, but it may indicate a developing trend that's worth keeping a close eye on.

Viruses delivered as a blended threat (when a spam message directs a user to a malicious website, which then results in a virus being downloaded to the user's computer) continue to be popular with spammers. E-cards are one of the best examples of this vector, and Valentine's Day saw a flurry of activity using e-cards to direct users to malicious websites.

Conclusions

Spammers continue to prove their resilience -- whether it's bouncing back from the biggest takedown on record or finding new ways to exploit the ways we communicate for malicious purposes, they're clearly here to stay. And Google believes firmly in the power of the cloud to protect your enterprise from them: Outsourcing message security to Google enables you to leverage our technical expertise and massive infrastructure to keep spammers from your door. See how much spam is costing your business, learn how much you could be saving with Google Message Security, or contact us for more information.

Posted by Amanda Kleha, Google security and archiving team

Monday, January 26, 2009

2008: The year in spam

[Ed. Note: The spam data cited in this post is drawn from the Postini Message Security network, which processes and culls spam from more than 2 billion enterprise email connections per day, giving Google strong insight into the state of the spam industry overall. For a discussion of what Google is doing to keep spam out of your Gmail inboxes on the consumer side, check out this post.]

In November 2008 a large source of the world's spam, the McColo network, was taken offline. Prior to that, spam levels had been holding relatively constant. But when McColo went offline, we saw spam drop by 70% compared with previous levels. However, spammers are recovering with vigor.

While spam is still down overall, it's important to note its rate of growth. Spam levels are up by 156% since November 2008. As spammers recover, the increased rate of spam growth will likely have total spam volumes back to pre-McColo levels within a few months.



Although McColo received a lot of attention, the highest volume of spam in 2008 actually came on April 23, which was an all-time high spam level for Google Message Security data centers. That day, the average number of spam messages blocked per user was 194. This peak was driven by an unprecedented number of non-delivery receipt (NDR) attacks we saw in April. One customer who was the target of a specific NDR attack said that their users were receiving an average of 100 emails every minute.

As spammers fill the void left by McColo, it's reasonable to anticipate a decreasing rate of growth as spam reaches November 2008 levels. However, since the November levels weren't even the peak for the year, and since spammers appear to be quickly recovering, the question remains: Where will spam volume top out in 2009? Will it be near the November 2008 level? the April 2008 level? Or higher?



One way to approach that question might be to compare 2008 overall levels with previous years. Spam threats rose visibly in 2008, reflecting the overall trend of rising attacks. Even with the drop in November 2008, spam levels climbed 25% over 2007. Our statistics show that the average unprotected user would have received 45,000 spam messages in 2008 (up from 36,000 in 2007). All indicators suggest this trend will continue as virus, malware, and link-based attacks become both more frequent and more ingenious.



Looking ahead to the rest of 2009, we expect viruses sent via email and in blended attacks (email and web) to continue to be a serious threat. During the second half of 2008, virus volume increased six-fold from the first half of the year. These spam messages would often try to fool users by mimicking legitimate emails such as package tracking notifications or invoices that included virus attachments. Another popular technique in 2008 was emailing spoofed news alerts with URLs that would link to a website hosting the virus.

We can also expect that viruses and malware will continue to be a key tool and area of focus for spammers to upgrade their platforms. Even though virus attachment volumes have been low so far this year, we expect spammers to work hard to rebuild their networks to replace what was lost in the McColo shutdown.

Of course, the only thing we can really say with certainty about 2009 is that spam and viruses will continue to be unpredictable. And given that uncertainty, virus detection and blocking technologies become even more important. Last year we released advanced new anti-virus heuristics that specifically targeted zero-hour vulnerability (the period of time between when a new virus enters the wild and the release of the anti-virus signature file). When the zero-hour protection identifies a suspicious message, the message is scanned using the new anti-virus heuristics, and if confirmed as a virus, the message is quarantined.

The chart below is an example of our new heuristic virus detection and blocking at work. On October 1, 2008, our automated technology detected a viral message pattern (later identified as new strain of the Downloader-AAP!zip) in the wild and started quarantining messages with this virus. Five hours later we received the new virus signature file from one of our anti-virus partners and the signature-based blocks began to take effect.



As seen from the roller-coast ride of spam and viruses in 2008, spam has again demonstrated its resiliency. Despite eliminating a major source, spam keeps coming back. Spammers are re-investing with increasing speed to evolve their systems into decentralized, harder-to-detect ecosystems. If you'd like to know more about Google's anti-spam solution for businesses, visit us at www.google.com/a/security.

Wednesday, November 19, 2008

Calculating the true cost of fighting spam

In today's economic climate you need to be more efficient with your IT budget. And since email is a key tool for almost every businesses, keeping spam and malware out of inboxes remains a top priority. In our experience, companies often overlook the productivity costs that spam and viruses have on their business. This simple ROI calculator lets you see how much spam can impact expenses and productivity, particularly if your current anti-spam solution is waning in effectiveness.

Once you quantify how much spam is costing your company, it makes sense to re-evaluate the IT options for managing spam. The first, and perhaps biggest, decision is whether to keep spam filtering in-house or use a hosted service. It can be difficult to add up the true expenses of each solution. On the surface, the cost of an appliance may seem reasonable, but the up-front costs are just the beginning in a complete cost-of-ownership calculation.

At Google, we believe that email security makes sense as a hosted service for several cost-related reasons:

* A cloud computing solution provides you with a predictable expense. A spike in spam can hit at any time, and companies using an in-house solution may find themselves dealing with the unexpected capital expense of a new appliance to deal with the load.

* You save on maintenance costs. After installation, most in-house appliances require regular upgrades and maintenance. With a hosted solution, all the updates are handled through the cloud. Nothing to worry about or budget for.

* Using the cloud makes email security more effective. With a hosted service such as Google Message Security, you tap into a network of intelligence that spans more than 40,000 businesses and 14 million users, reaping the benefits of the economies of scale that come with that.

To help you understand the whole cost of spam, we're introducing a TCO (total cost of ownership) calculator, which lets you compare expenses for in-house appliances versus hosted services. Using a three-year time horizon and considering both start-up and maintenance costs, companies can save thousands by choosing a hosted service. The graph below models the results of one cost scenario, for a 100-user company:



Let's look at a customer who was re-evaluating their spam solution last year: Gaines, Wolter, & Kinney, P.C. is a civil litigation firm in Birmingham, Alabama, that specializes in tort defense. They needed a solution that would reduce the inflow of network traffic and be cost effective. David Hebert, an IT administrator for GW&K, recalls, "Our limits on connection bandwidth meant that a service that filtered out spam was a no-brainer decision." But David needed data to convince management that a change was essential. He used a ROI calculator and found that they were losing 122 hours per employee in productivity each year to spam. With the hourly rate of their lawyers, this meant that choosing Google Message Security paid for itself in 1 day.

If your business is interested in learning more about how hosted services like Google Message Security can save you money and increase productivity, visit us at www.google.com/a/security.

Monday, November 17, 2008

Fighting spam just got a little easier

Last week, a web hosting service that was a significant source of spam was taken offline by the combined efforts of Security Fix and several Internet providers. Google would like to congratulate Security Fix for leading this effort and striking another blow in the battle to stamp out spam on the web. The removal of this service helps "clean up" the web for everyone, and dovetails with efforts like Google's to make web communications safer and more secure in all of the ways that people use it.

We'll continue to monitor spam traffic, as we always do, but here's what we've seen in the past few days:


On November 11, when the spam source was taken down, we saw a 70% drop in spam from levels seen at the beginning of the month. However, we've seen drops like this before. In late July this year there was a similar drop that was reversed within a few days.



Gmail servers, which also noticed a drop in spam on November 11, are now showing an upward trend as new sources of spam, as always, continue to emerge.
The team at Google stays "on guard" as the fight continues!

Tuesday, September 30, 2008

Google Positioned in Leaders Quadrant

In their recently released Magic Quadrant for Email Security Boundaries (published September 11, 2008), Gartner Inc., an information technology research and advisory company, placed Google in the "Leaders Quadrant." Quadrant leaders, as Gartner defines them, are "performing well today, have a clear vision of market direction, and are actively building competencies to sustain their leadership position in the market." Quadrant leaders also "offer a comprehensive and proficient range of email security functionality, and show evidence of superior vision and execution for current and anticipated customer requirements.

Leaders typically have relatively high market share and/or strong revenue growth, own a good portion of their threat or content-filtering capabilities, and demonstrate positive customer feedback for anti-spam efficacy, and related service and support.
" The report goes on to say that "The email security market is rapidly maturing, yet continues to show strong growth and remains a 'must have' security purchase."

We're pleased to be included in this report and recognized in the leaders quadrant, as it underlines, in our opinion, the importance we attach to protecting against email-based threats and the ways we're helping our customers do so. Since the integration of the Postini email security product line in 2007 into Google's Enterprise Apps, Google has continued to innovate these products with functionality for our customers, including a new early detection quarantine that uses our own heuristics to detect new virus strains before virus signatures are available. We have also added new content filter types, policy prioritization for messages that trigger more than one policy, and new policy engine interface features.

The Gartner Magic Quadrant is copyrighted 2008 by Gartner, Inc., and is reused with permission. The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner’s analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Gartner does not endorse any vendor, product or service depicted in the Magic Quadrant, and does not advise technology users to select only those vendors placed in the "Leaders" quadrant. The Magic Quadrant is intended solely as a research tool, and is not meant to be a specific guide to action. Gartner disclaims all warranties, express or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Tuesday, August 12, 2008

Security Spotlight: July Virus Attacks

In July, our Postini datacenters saw the biggest volume of email virus attacks so far in 2008, with a peak of nearly 10 million messages on July 24. One of the more prominent attacks in the month involved a spoofed UPS package-tracking link that was intended to lure recipients into clicking on it and downloading malware. Our zero-hour virus protection technology first started catching these emails on July 20.



Many of the viruses we see follow a similar format, in which an email with an embedded website link in the message is changed from what the link displays. Another recent example was a spoofed CNN newsletter sent out by spammers. In this case, the content included current news stories with numerous links in the message. The majority of the links were valid, but there were some that were replaced with malicious links. As soon as our technology started detecting these messages, we implemented a filter to stop these elusive viruses and voila! -- all of our 14 million business users were protected. This network effect and rapid protection against these new tactics is why businesses are increasingly moving their email security into the cloud.

Viruses tend to increase during the summer months, and August is already showing some new types of viruses. On August 5, we saw a large inflow of messages with an encrypted .RAR attachment. The overall 2008 trend has been a decrease in the use of attachments, so this new virus is confirmation that spam doesn't follow trends for long.
These examples are also a good reminder about the importance of educating our colleagues, friends, and family on how to safely interact with email -- namely, that we should all be careful about clicking on links in emails, even if those messages appear to be from people or organizations we know.

Join Google security experts for an upcoming webinar for IT professionals that will explore the topic "How spam is changing your business email, and what to do about it" on Friday, August 15, at 10:00 am PDT.

For more information on how Google can help your business secure its email and web traffic, visit us at www.google.com/a/security.