Spam surges hurt SMBs

By Tom Espiner, ZDNet UK
Tuesday, June 05, 2007 07:00 AM

Spammers are increasingly targeting individual companies' domains with large volumes of concentrated spam.

This could put small businesses' mail servers at risk of suffering denial-of-service conditions, said messaging security firm MessageLabs.

"Increasingly we've seen spam runs take place in a burst of activity lasting a few hours," said Paul Wood, senior analyst at MessageLabs. "Spammers are sending large volumes of spam destined for individuals within organizations, to try to get round signature-based antispam [products]."

For example, MessageLabs witnessed a series of spam spikes against one particular company's domain. The company, which MessageLabs did not name, had fewer than 200 employees and would typically receive approximately 730 messages per day. This number went up to several million messages during spam spikes. While the company knew its mail servers weren't operating efficiently, it found it difficult to pinpoint the cause of the problem.

MessageLabs said the company was being targeted in a dictionary attack, which involved the spammers sending a large amount of spam to e-mail addresses compiled from common first and last names, combined with the company domain, in the hope that they would hit upon a number of valid email addresses. As the mail server still had to deal with both valid and invalid mail, the spam spikes caused denial-of-service conditions.

"The company was spending a lot of money upgrading memory and bandwidth," said Wood. "And legitimate mail wasn't being delivered."

While Wood admitted that spammers causing denial of service would ultimately be self-defeating, because their spam was not being delivered, he said the technique was being increasingly used. Wood added that small companies who are experiencing slow mail servers should go to their ISP for traffic analysis.

Graham Cluley, senior technology analyst for antimalware company Sophos, said that attacks against company domains would be specific to individual companies and ISPs. Cluley said Sophos has seen a real growth in the amount of spam which attempts to direct users to malicious Web sites, with a quarter of a million new Web pages hosting malicious code per month. According to Cluley, of those Web pages, 70 percent are legitimate sites that have been hacked to contain malware.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Export project data for future effort estimation

Tech Management

Learn to tweak your estimation matrix even further by analyzing the project data from your Microsoft Project schedule.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Are telcos new drivers of outsourcing industry?

Blog thumbnail

The recent TPI Index from TPI highlighted an interesting trend where a few very large telco-to-telco contracts--instances where one telecommunications carrier outsources its network operations requirements to another telecommunications service..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web