Research to reduce spam emails and increase online security

The U. Texas campus newspaper pretty much gets it. I’ve added a few links and images.

Julia Brouillette wrote for the Daily Texan today, UT researchers work to reduce spam emails, increase online security,

A group of UT faculty members and graduate students have teamed up with UT’s Center for Research on Economic Commerce (CREC) to expose the companies that send out millions of spam emails every day.

SpamRankings.net, a website launched by the University’s Center for Research on Economic Commerce, displays rankings of companies by number of outgoing spam messages generated from roughly 18,000 U.S. and international organizations. The project creates models for email providers to reduce spam and is funded by two grants from the National Science Foundation, totaling approximately $1 million.

Head researcher John Quarterman said UT students, in particular, are at a high risk for identity theft because of spam.

“UT has had a big problem with student information being leaked to the outside world because of bad security,” Quarterman said. “Spam is getting out that may contain private information, like your identity.”

Quarterman said the easiest way for students to prevent spam from entering their inboxes is to maintain up-to-date software.

“Make sure you have all the updates to your operating system,” Quarterman said. “Antivirus software is worth running as well.”

According to Andrew Whinston, the center’s director and a management information systems professor, students are susceptible to deceptive links as they surf the Internet. Once the link is clicked, malicious software enters the computer system and new spam is generated.

“You have to be careful and not go to websites on the Internet that you are not really familiar with, or websites that are not authenticated in some way,” Whinston said.

Whinston said preventing spam starts Continue reading

SIRA Security Event in VERIS Community Database of breaches

I’ve provoked an example breach report in the VERIS Community Database by the Verizon Risk Team, recorded in this JSON file, with this summary:

A secondary domain hosted by Bluehost was defaced by an opportunistic attack. We are consolidating the secondary domains in our primary provider and all domains will be pointing to our web site.

Last week I was looking to join SIRA’s email list and mistyped .com for .org. Finding www.societyinforisk.com had “HaCKeD By : brkod” on it, I mentioned that to SIRA. They fixed it as above.

The interesting part is that the VERIS Community Database is an effort to expand the annual Verizon Data Breach Investigations Report (DBIR) into something more timely and comprehensive: It’s not very big yet (63 commits and 1546 incidents), but it’s a welcome start. It doesn’t have nearly the comprehensiveness, frequency, nor regularity of the spam blocklist data underlying SpamRankings.net, but it has, or it can have, more depth in reporting what happened and why.

The VERIS Community Database

Continue reading

Botnets and Reputation Ranking at APWG in San Francisco 2013-09-17

On the agenda for APWG eCrime Tuesday 17 September 2013 in San Francisco:

Birds of a Feather (BOF)
Botnet Data Exchange for Botnet Node Remediation and Network Reputation Ranking
–Pat Cain, APWG
–John S. Quarterman, Quarterman Creations

I’ll be talking about SpamRankings.net among other reputational rankings.

APWG PR of 29 August 2013 says:

Global cybercrime-fighting association APWG is hosting its eCrime 2013 members meeting and research conference in San Francisco next month to launch its second decade of leading the global engagement with cybercrime, assembling commercial leaders from multinational technology and financial services companies, government and law enforcement agencies and industrial and academic researchers from around the world to update the global agenda for the long-term containment of the cybercrime scourge.
This is the tenth year of APWG, and the seventh year of the eCrime Researchers Summit.

I presented at Continue reading

#1 third time: University of Pittsburgh Medical Center, July 2013

University of Pittsburgh Medical Center‘s AS122 U-PGH-NET-AS is #1 again in the July 2013 worldwide medical SpamRankings.net from CBL volume data.

July 2013 line chart

It’s also been #1 in June 2013, when it also spiked over 1,000, Continue reading

Detection is much more important than prevention –Bruce Schneier

Reviewing Bruce Schneier’s 2004 book Secrets and Lies, much of which was written in 2000, reminds us of something really basic. You can’t just fix security. Security is a process, most of which is about knowing what’s going on. Detection is more important than prevention. To which I add that for detection we need comparable Internet-wide metrics on security performance so every organization can see what’s going on and will have incentive to do something about it because its customers and competitors can see, too. Sound familiar? That’s what SpamRankings.net is about.

Joe Zack posted in Joezack.com on Bastille Day, 14 July 2013, Secrets and Lies: Nine Years Later,

2. “Detection is much more important than prevention”

Schneier keeps coming back to this point. He had this epiphany in 1999 that “it is fundamentally impossible to prevent attacks” and “preventative countermeasures fail all the time.” Security is “about risk management, that the process of security was paramount, that detection and response was the real way to improve security.” (emphasis mine)

I had formerly thought of security as largely being about prevention. A year ago, if you have asked me about “InfoSec” I might have prattled on about firewalls, injection attacks, encryption and good passwords. That’s still important, but now I know that there’s a lot more to it.

Zack says he thinks Schneier was like Nostradamus for having such insight before NSA PRISM and even before Facebook. Sure, Bruce has always been ahead of his time. But that basic insight was not unique to him, and Continue reading

Codero 2nd most reliable (Netcraft) and 3rd spammiest (SpamRankings.net)

Codero jumped from #137 in May to #3 in the June 2013 U.S. U.S. SpamRankings.net from CBL volume. For that same month, Netcraft ranked Codero #1 for hosting reliability. Netcraft ranks worldwide, and in the worldwide SpamRankings.net, Codero came in #9, which is still very impressive. I guess spammers prefer reliability. Who wouldn’t?

-jsq

Germany 3 of the top 5 in June 2013 SpamRankings.net

German German companies took 3 of the 5 top spots in the June 2013 World SpamRankings.net from CBL volume.

  • #2 Hetzner Online Online AG RZ‘s AS 24940 rose from #35, and
  • #4 Internet AG‘s AS 8560 rose from #51.
  • #5 Strato AG‘s AS 6724 actually got better; it was #2 last month.
Together those three German firms accounted for almost a third of spam from the top 10 ASNs worldwide. Germany kept the #2 spot in the world rankings, while increasing spam by 2/3.

-jsq

Relizon from nowhere to #3 for Canada in May SpamRankings.net

Relizon Canada Inc.’s AS 40034 RELIZON-CDN jumped from #134 to #3 in the May 2013 SpamRankings.net for Canada All from CBL data. On May Day CBL saw 1 spam message from AS 40034 and more than 3 million on May 31.

Relizon was not visible in the May Canada rankings from PSBL data, although internally we do see AS 40034 going from #208 to #109 by going from 11 spam messages in April to 26 in May. Relizon logo CBL’s heuristics or spam traps or both were apparently much better at detecting this particular spam source.

Relizon’s own website doesn’t seem to be responding at the moment, but Bloomberg Businessweek says they do business process outsourcing solutions, and were formerly known as Crain-Drummond Inc., with the name change coming on acquisition by the Carlyle Group.

-jsq

Canada’s Hospital for Sick Kids stopped spamming

Canada Canada’s The Hospital for Sick Children The Hospital for Sick Children AS 46626 SICKKIDS-AS-01 dropped out of the May 2013 SpamRankings.net for world medical organizations from CBL data. In April they ranked #1 with 21,912 spam messages, April 2013 World Medical SpamRankings.net from CBL Volume and in May they dropped to #27 with only 28 messages. In April they really only spammed for one week, as you can see in the big spike in the graph. Of course, the hospital itself probably didn’t knowingly send the spam; usually they’ve been compromised by botnets or phishing or some other breach, but hospital patients and other customers won’t necessarily know that if they receive some of it. And if their security is lax enough to let in things that emit spam, what else has been compromised? This is why hospitals are quick to squelch outgoing spam and fix the underlying security problems.

-jsq

Zerofail from nowhere to #2 in April and May 2013 SpamRankngs.net for Canada

Zerofail’s AS 40191 AS-PRE2POST-1 jumped from 5 per day April 1st to more than a million spam messages many days in April, and from 413 total in March to almost 22 million in April. That made it #2 in the April 2013 SpamRankings.net for Turkey Canada from CBL data, and Zerofail kept second place in May with more than 18 million spam messages. This AS actually sent proportionally more of top 10 spam from Canada in May than in April because #1 iWeb’s AS 32613 sent a lot less in May. Where does all this Zerofail spam come from?

AS 40191 has six netblocks currently assigned, of which the netblock 173.246.64.0/19 is producing almost all of the spam seen from AS 40191.

-jsq