Technology Review - Published By MIT
Advertisement

Catching Spammers in the Act

Continued from page 1

By Robert Lemos

Wednesday, July 15, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

Many end users protect themselves against e-mail harvesting using simple obfuscation techniques--for example, using "-at-" to replace the "@" symbol in an e-mail address. The researchers found that these methods frustrate current spam techniques surprisingly well. In addition, they found that submitting an e-mail address to a legitimate website rarely resulted in spam. "If you sign up with reputable organizations, you will be fine," Shue says. "If you go to less reputable sites, then you will get spam."

In a separate paper to be presented at the same conference, researchers from the Federal University of Minas Gerais (UFMG), in Brazil, and Brazil's Network Information Center show that spammers tend to combine different techniques to hide the origin of their junk e-mail messages. While many spam groups have adopted the use of botnets to anonymize the source of their e-mail messages, a significant number use a chain of different compromised machines, according to Pedro Calais Guerra, a PhD student at UFMG.

"The key factor for a spammer to succeed in terms of hiding his identity on the network is to spread his activity as much as he can," says Guerra, who believes that the team's study could be used to help fight spam by identifying which messages should be blocked. "We think it may have an impact on the design of blacklists."

Guerra and five other researchers monitored special servers, known as honeypots, collecting 525 million spam e-mail messages sent from more than 216,000 Internet addresses over a 15-month period. They found, for example, that nearly 95,000 machines used by spammers were end-user computers that relayed messages and not mail servers, a third of which were in the United States and a quarter in Taiwan.

The chains of computers used by the spammers to anonymize the origins of spam fell into two categories: open proxies and open relays. The open proxies are compromised servers that forward data to other computers on the network, hiding the sender's address; open relays receive e-mail messages for another domain, passing the message to the next server. The researchers found that spammers typically use each open relay to forward e-mail for only a short time, to avoid having the e-mail server added to a blacklist.

"We show in our paper that spammers send high volumes of spam to open proxies but low volumes of spam to open relays," UFMG's Guerra says.

Comments

  • spam
    If ALL of us deleted ALL our spam messages, they would become unprofitable and might stop.  Don't buy anything, don't even look at them.  Just delete them.

    timbrady
    07/15/2009
    Posts:1
    Avg Rating:
    2/5
    • Re: spam
      When you send out millions of spam messages, it takes only a very small percentage of fools to make the enterprise profitable. I don't see the number of fools declining as time goes on.

      Perhaps if we had laws making the advertisers (who are easier to locate) liable for violating anti-spam statutes, we could discourage some of the abuses.  Charging a nominal voluntary fee for email (a tenth of a cent per message), and filters that block unpaid-for transmissions, would probably put an immediate end to the problem.

      jpdemers
      07/15/2009
      Posts:40
      Avg Rating:
      4/5
    • Re: spam
      Aren't you tired of subsidizing spammers? You know your cost of using the Internet pays for their usage of the majority of the bandwidth?

      fiberman
      07/17/2009
      Posts:74
      Avg Rating:
      3/5

This discussion has been moved to our discussions forum.

Log In

Forgot your password?     Register »
Advertisement
Advertisement
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.