Spam Wars
Computerworld - You know from looking at your e-mail lately that it's possible to be debt-free, have perfect skin and be a babe magnetwith a little help from your new friends.
But at least employees at Stamford, Conn.-based Xerox Corp. are shielded from such revolutionary offersthough the process hasn't been easy. Last summer, Xerox's firewall team was blocking 150,000 spam e-mails a month. By early fall, it was 60,000 messages a day, seven days a week, says Linda Stutsman, manager of corporate information security and risk management.
In the past year, spam has moved beyond personal e-mail accounts, invading business systems and graduating from societal pest to corporate enemy. Companies are stockpiling their arsenalslists of legitimate senders and known spammers, tools that pick up on spamlike content or behavior, digital fingerprints and decoy e-mail addressesto fight this invasion. On the other side, however, new and resourceful recruits lured by spam's promise of big financial returns are constantly devising counterattacks.
"There's 10 times as much [corporate] spam this year as there was last year," says Joyce Graff, an analyst at Stamford, Conn.-based Gartner Inc. "It's mind-blowing. And the economics are on the spammers' side."
And, says Jason Catlett, president of Junkbusters Corp., a Green Brook, N.J.-based antispam organization, the problem is getting worse. "Spam is growing at a slightly faster rate than e-mail traffic," he says.
Weapons of War
The spam weapons that Graff finds most difficult to defend against are harvesting tools. For $39.95, marketers can buy a "spambot" that searches message boards and lists, culling up to 100,000 e-mail addresses in an hour. Spambots also get into the relay game with organizations' message transfer agents (MTA) by sending messages to, for example, georgebrown@whitehouse.gov, georgebuckley@whitehouse.gov and so on, until they find matches.
To combat these spambots, Graff says, organizations need to set up their MTAs so they automatically disconnect as soon as they detect harvesting attacks.
But, says Steve, a Washington-based spammer who asked to be identified by only his first name, spammers are continually findingand sharingnew ways to hide their identities. For instance, he's created a filter-evading script that randomizes subject lines and source addresses so they're not easily identified as bulk mail. Big-time spammers buy servers that can randomize entire domains, says Steve.
Spammers scan the Internet for open relays in foreign countries so their messages will be hard to trace. Or they set up free e-mail accounts and dump them before they're caught. Spammers can blast out hundreds of thousands of messages, each with customized content and source addresses, and then quickly log out, says Mark Bruno, enterprise product manager at Brightmail Inc., a San Francisco-based vendor that got its start filtering e-mail for service providers but has since shifted its focus to corporations.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- NetApp, VMware, Cisco, Wyse, Fujitsu 50,000 Seat VMware View deployment
- NetApp, VMware, Cisco, Fujitsu, and Wyse joined forces to create an architectural design for a 50,000-seat VMware View™ architecture built on VMware vSphere...
- Desktop Modernization eBook
- This eBook looks at the challenges involved in delivering and managing desktops, today and in the future. Its goal is to demonstrate how...
- 10 Reasons to Modernize the Desktop: CIO
- IT departments need a solution that meets the evolving needs of both the employees and IT- something not possible with a traditional PC...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in... All Desktop Apps White Papers
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Introduction to VMware View 5
- VMware View™ 5 simplifies IT management while increasing end user freedom by delivering desktop services from your cloud. Building upon VMware's leadership in...
- Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity
- End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Desktop Apps Webcasts