30.05.2013 Views

internet security tHreAt rePOrt GOVernMent 2013

internet security tHreAt rePOrt GOVernMent 2013

internet security tHreAt rePOrt GOVernMent 2013

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

p. 122<br />

Symantec Corporation<br />

Internet Security Threat Report <strong>2013</strong> :: Volume 18<br />

SPAM AND FRAUD ACTIVITy TRENDS<br />

Analysis of Spam Delivered by Botnets<br />

Background<br />

This section discusses botnets and their use in the sending of<br />

spam. Like ballistics analysis in the real world can reveal the<br />

gun used to fire a bullet, botnets can similarly be identified<br />

by common features within the structure of email headers<br />

and corresponding patterns during the SMTP transactions. 3<br />

Spam emails are classified for further analysis according to the<br />

originating botnet during the SMTP transaction phase. This<br />

analysis only reviews botnets involved in sending spam and does<br />

not look at botnets used for other purposes, such as for financial<br />

fraud or DDoS attacks.<br />

Data<br />

Figure c.6. Percentage of Spam Sent from Botnets in 2012<br />

Source: Symantec.cloud<br />

90%<br />

80<br />

70<br />

60<br />

50<br />

40<br />

30<br />

20<br />

10<br />

JAN<br />

FEB<br />

MAR<br />

APR<br />

MAY<br />

JUN<br />

JUL<br />

AUG<br />

Methodology<br />

Symantec.cloud spam honeypots collected between 5–10<br />

million spam emails each day during 2011. These are classified<br />

according to a series of heuristic rules applied to the SMTP<br />

conversation and the email header information.<br />

A variety of internal and external IP reputation lists are also<br />

used in order to classify known botnet traffic based on the<br />

source IP address of the sending machine. Information is shared<br />

with other <strong>security</strong> experts to ensure data is up to date and<br />

accurate.<br />

SEP<br />

OCT<br />

NOV<br />

TREND<br />

DEC

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!