Free Newsletters




   
CIO magazine chief information officer ERP IT strategy  research  analysis business technology e-business CRM customer relationship management e-business   enterprise resource management leadership
CIO.com
About
Search
Awards Programs
Subscribe
Magazine
Current
Previous
Print Links
Newsletters
CIO Store
CIO Conferences
CIO Executive Council
Blogs
News Alerts
CEO Reading
IT Strategy
Tech Linkletter
Tech Policy
Viewpoints
Experts
Alarmed
Analyst Corner
Beneath the Buzz
Consultant Briefing
Higher Learning
In the Know
Leading Questions
Weigh-In
Discussion Forums
Career
CIO Wanted
Counselor
IT Events Calendar
Movers & Shakers
Research & Polls
CIO Research Rpts
Quick Poll
Tech Poll
Reports & Guides
CIO Bookmark
Reading Room
Special Reports
Compliance
RITLAB
State of the CIO
Webcasts
White Papers
About Us
Advertise at CIO
Conference Info
Editorial Calendar
Editorial Staff
List Services
News Bureau
Reprints
Sales
Related Sites
CSO
CMO
Darwin
IDG Network
Feedback to CIO
© CXO Media Inc.
subscribe to CIO Magazine



Home > CIO Metrics
Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Spam and Viruses

Bot Wars: The Spam Bots Strike Back

By Todd Wasserman

Email is an indispensable tool for most organizations, but it's also the source of more and more headaches for CIOs as spammers continue to up the ante with new technologies.

Analysts who study email and spam agree there's nothing that can be done to block 100% of all spam. Instead, spam might be likened to diabetes, a chronic condition that can be managed but not eradicated. However, spam is not only dangerous because it can result in the transmission of viruses, worms and other threats, but it also diverts essential computing power. And the advent of new types of spam -- including image spam and botnet spam -- is now slowing down the Internet connections upon which organizations have come to rely.

"We're continuing to hear that around 90 to 95% of email is spam and the spammers are using a bunch of new techniques to break in," says Arabella Hallawell, a vice president of research for Gartner. "It's really slowing connections and eating up a lot of bandwidth."

New flavors of spam
One reason for the increase in spam is botnets, which are ordinary desktop computers that are taken over by a virus that churns out spam. Vint Cerf, one of the co-developers of the Internet protocol standards, estimates that between 100 million to 150 million of the world's 600 million or so PCs are part of botnets. Most organizations don't even realize their computers may be part of botnets. That's troublesome because a concentrated botnet denial-of-service (DoS) attack can cripple a network by flooding it with data and preventing legitimate network traffic.

The other major email threat is image spam, which was devised to foil filters looking for specific spam keywords. But when such text is presented in a JPEG or PDF format, such text-seeking filters are rendered useless.

One way to battle image spam has been to look for "signatures" like a certain color scheme, but spammers have gotten wise to that tactic and have created "snowflake spam," in which every image is unique, at least from a spam filter's viewpoint. Thanks to its ability to confound filters, image spam has grown in popularity. Some firms estimate that up to 30% of all spam today is image spam.

Ways to limit image spam and botnets
What can a CIO do to limit image spam and exposure to botnets? Analysts suggest the following methods:

  • Block all image-based spam, except those that come from pre-approved email addresses. This method is likely the most effective, although it may be too extreme for many organizations. The danger of using such a blunt instrument is that legitimate emails will inevitably be trashed along with the spam. "That's really kind of a hammer to crack a nut," says Natalie Lambert, a senior analyst with Forrester Research. One variant on this is greylisting, where a software system flags potential spam and lets users determine if it should be blacklisted.
  • Use reputation analysis, a technique that traces the source of the spam and creates a blacklist of spam addresses. Reputation analysis is considered to be a CIO's best weapon against spammers. Instead of looking for keywords or signatures, reputation analysis programs map out the route an email travels by assessing the IP address of the connecting host and the emailer's address. Hallawell says reputation analysis or "reputation management" is one of the most effective ways to fight spam: "You can block 30 to 70% of spam just like that."
  • Limit the server's exposure to email. Another way of reducing the spam threat is by denying direct access to an email server. That can be done with a firewall or an email appliance, which is a hardware device used to handle emails.
  • Outsource all email functions. In some cases, it might make sense to outsource email, the argument being that spam has grown too complex for most IT departments. There are two downsides to this approach, though: cost and privacy. Outsourcing email can cost thousands of dollars a month, but privacy may ultimately be a bigger concern. "This is one of the areas that can very easily be outsourced," Lambert says. "But some organizations don't want that email to hit anyone but themselves."

Whatever method of fighting the new strains of spam that a CIO decides is best for the organization, analysts note that it is important to address the threats now.

"The sheer magnitude of what botnets can do is frightening," Lambert says. "They are often the source of a big phishing or spam attack."

Todd Wasserman has more than 15 years' experience writing for The New York Times, The Industry Standard and Business 2.0, among other publications. He is currently news editor for Brandweek magazine.

CIO Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

"We're continuing to hear that around 90 to 95% of email is spam and the spammers are using a bunch of new techniques to break in."

-- Arabella Hallawell a vice president of research at Gartner

Sponsor Tools
Podcast Audio Content

CIO Strategy Center is now available in audio format.

This week's feature topic is:


Preparing for a Disaster
Playtime: 8 min 07 sec



Download | Subscribe







Advertisers



Free Newsletters
Sponsor Content
 Domains
Compliance CIO Partner Domain for I.T. Productivity
The domain for everything you need to assess, measure and improve
IT Productivity within your organization, Whitepapers, Books, Research, Benchmarking tools and lots more.
 Webcasts
Compliance Failure is not an option: Why online compliance and security can’t wait.
Compliance BI Standardization: Attend our virtual conference for real advice.
Compliance Getting Smart about Offshoring: How Visual Simulation Gets It Right the First Time
Compliance Turning Best Practices to Best Projects
Compliance Securing Enterprise Data In An Unsecured World
Compliance A New Game—The Fast Emerging World of IP Convergence
Compliance All CIO Webcasts
 White Papers
Compliance Organizations Shift Focus to Information Management
Compliance Tera-Scale Data Warehouse Appliances Overcome the Technology Bottleneck
Compliance Knowing the Risk
Compliance Why Asset Management and Discovery are Core Contributors to Effective Business Service Management
Compliance Start your ERP upgrade with a distinctive master data advantage
Compliance Putting your Spend Data Warehouse on steroids
Compliance All CIO White Papers

IDG ENTERPRISE NETWORK

NetApp launches expanded NAS line - Infoworld Staff
IBM, BEA lay out new Java specs - Infoworld Staff
  »More  

Phishing scams rocket
Wi-Fi switches: breakthrough year, future fear
  »More  

Users get going on SP2 rollouts
Shark Tank: Just one more thing to remodel
  »More  

SPONSORED LINKS:
Align IT with business goals. Introducing PlanView Enterprise.
A data warehouse 10-50x faster at ½ the cost. Learn more!
How do you compare with 565 IT organizations?
For real advice on BI Standardization attend the Virtual Conference on Feb 22
Manage IT Change. Manage the Business. Free white paper.
Ten Principles for Knowledge Management Success" - Get the free white paper from ServiceWare
Audit the Data or Else: Un-audited data increases business risk Grid
See Qualcomm, EPL, and Deutsche Post on the Oracle Grid
Preventing Client/Vendor Mismatch: click here to learn more

Free Newsletters

Dated: March 01, 2005
http://www.cio.com/blog_view.html?ID=221


About CIO.com | Welcome | Privacy Policy | Terms of Service | Linking to us

CIO.COM complies with the ASME Guidelines with IDG extensions for new media.

CIO magazine chief information officer ERP strategy IT research analysis business technology management e-business knowledge management intranet CRM cio.com CRM customer relationship management e-business ERP enterprise resource management leadership management measuring IT value outsourcing supply chain

© 1994 - 2005 CXO Media Inc.

An International Data Group (IDG) Company



 HOME  CURRENT ISSUE  ARCHIVE   About CIO :: Advertise :: Subscribe :: Conferences 

Reprints, IDG Network, Privacy Policy

THE IDG NETWORK
CSO :: CMO :: Darwin :: Computerworld :: Network World :: Infoworld :: PC World :: Bio-IT World
IT Careers:: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp



Problems/complaints/compliments about this site can be sent to deiben@cio.com.