Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Storm Worm, Other Botnets, Kept 2007 Spam Levels High

Brad Reed, Network World

  • 0 Yes
  • 0 No

Botnets helped keep spam output at consistently high levels last year, and global spam reached rates as high as 96% of all e-mail traffic during 2007, according to a report from Commtouch.

According to data collected by Commtouch, a security firm that specializes in protecting e-mail, the global spam rate averaged around 80% of all e-mail traffic throughout the year (compare antispam products).

Although the spam rate dipped to as low as 60% in the second quarter of 2007, it spiked back up in the third and fourth quarters, peaking at 96% of all e-mail output early in the fourth quarter. Commtouch says that botnets -- which are networks of infected zombie hosts that are used to carry out distributed denial-of-service attacks and massive spam campaigns -- were the major culprits behind the spam outbreaks.

Effect of the Storm

The most disruptive botnet, says the firm, was the Storm worm botnet, which researchers estimate contains more than 1 million infected machines. In the fourth quarter of 2007, for instance, the Storm botnet launched an MP3 spam campaign that enticed unwitting users into downloading malware by offering them free music through infected sound files. The firm says that this particular attack accounted for 7% to 10% of all global spam traffic at its peak.

In addition to its MP3 attacks, the Storm botnet launched a series of holiday-themed spam attacks that included dancing skeleton graphics for Halloween and Christmas e-mails that enticed users with promises of "sexy girls" who would "give you that special Santa treatment."

Commtouch warns that the Storm botnet has yet to be used to its full potential and that its activity in 2007 "may come to be seen as merely the calm before the Storm compared to what 2008 has yet to bring." Part of the reason that the Storm botnet has been so difficult for security pros to tackle, the firm notes, is that it has an elaborate defense system that aggressively attacks anyone who attempts to reverse engineer it. Additionally, Commtouch says it is virtually impossible to track down Storm's botmaster, because its command and control is executed through a peer-to-peer network.

"The only effective way to protect against Storm and other botnets is to dynamically detect and block activity from the infected machines, based on identifying zombie IP addresses," Commtouch says. "Only security solutions capable of detecting and classifying malicious activity in real-time are able to provide a barrier against this growing threat."

For more information about enterprise networking, go to NetworkWorld. Story copyright 2008 Network World Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"Storm Worm, Other Botnets, Kept 2007 Spam Levels High" Comments

  • Great year-end deals for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

People who read this also read:

  • Perfect Printing Solutions Find just the right All-in-One printer for you from HP. Visit the HP Resource Center.
  • Lenovo Laptop Showcase Find out how Lenovo IdeaPads and Thinkpads balance performance and portability. Visit the Lenovo Resource Center for more info...

Sponsored Links