Sudden spam drop leaves experts baffled

Social media could be new focus

By John E Dunn, Techworld |  Security, Internet, spam Add a new comment

Spam volumes appear to have dropped to averages last seen in 2008 after an expected surge in bogus email over the Christmas period failed to materialise.

Estimating real spam volumes is a notoriously difficult exercise thanks to a tendency of spam to naturally ebb and flow over time and the fact that no agency has a single view on the phenomenon. However, figures revealed in recent weeks by a number of companies that have compiled stats make curious reading - every vendor's figures show a fall of some sort.

According to Cisco's IronPort SenderBase, spam volumes for 2010 peaked in late summer before dropping by around a third month-on-month between September and December. The total volumes were also noticeably lower in November and December than they had been for any month during 2010.

Over at Commtouch, after a year-high spike in September, spam volumes fell by around 30% between September and December 2010, mirroring a fall in the number of zombie PCs detected by the company during the same period.

According to UK-US outfit M86 Security, its spam volume index measured using honeypot domains fell by as much as half during December when compared to the numbers for the spring and summer.

None of the vendors' numbers showed the expected surge in spam over the Christmas period, traditionally a time when spammers boost their output.

As yet, no security company has come up with a reason for the fall, which is larger than the fall registered in late 2009, but still modest compared to the historic plunge that happened in late 2008 after rogue ISP McColo was shut down.

Given that no large ISPs or botnets have been shut down in the corresponding period, it could simply be a seasonal lull. It could also mark a change in tactics by spammers towards using channels other than conventional email, such as social media, to reach computer users. According to a report by Websense in November, noted a marked rise in spam on Facebook and Twitter with as much as 10% of status updates on the former containing spam.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question