The game goes on: an analysis of modern spam techniques

Rob Thomas, Dmitry Samosseiko SophosLabs

Spam is perhaps one of the most rapidly changing forms of communication we see today. The spammers' methods of evading detection evolve constantly, differing significantly now from what was employed even in the recent past.

Content-based filtering - still a necessary part of any broad and proactive anti-spam solution - is by no means immune from their efforts. Whether based on signatures, URL blocking or heuristic rules, these filters are still sometimes thwarted by sophisticated HTML- and CSS-based obfuscation methods, or by placing the entire content of the message in randomized attached images.

Spammers also tirelessly seek loopholes in domain name registration systems that allow them to avoid pre-emptive detection, and in the security measures of free web-hosting providers so they can mass-register thousands of new home pages every day.

The paper will provide an analysis of many modern anti-anti-spam techniques, accompanied by statistical reports and real-life examples. It will also outline some possible approaches to combat these often highly effective and thus increasingly 'popular' spam techniques.

 del.icio.us  digg this! digg this

Quick Links

Poll
The Japanese government is reported to have commissioned a 'defensive virus'. Is 'defensive' malware ever a good idea?
Yes
No
I don't know
Leave a comment
View 11 comments

99 Subscription Promo

VB100 certification
VB100 This month's VB100 test saw some major changes and a radical overhaul of the VB100 test methodology - for the first time allowing products to use their 'cloud' look-up systems. John Hawes has all the details.
See full results.

Virus Bulletin currently has 224,243 registered users.