Paul Wood Senior Analyst, MessageLabs. Email summary.

11
Paul Wood Senior Analyst, MessageLabs

Transcript of Paul Wood Senior Analyst, MessageLabs. Email summary.

Page 1: Paul Wood Senior Analyst, MessageLabs. Email summary.

Paul WoodSenior Analyst, MessageLabs

Page 2: Paul Wood Senior Analyst, MessageLabs. Email summary.

Email summary

Spam rate

Last Month:

76.8%

Six Month Average:

73.5%

73.9%

Virus rate

Last Month:

1 in 170.1

Six Month Average:

1 in 218.9

1 in 157.9

Phishing rate

Last Month:

1 in 265.6

Six Month Average:

1 in 206.1

1 in 188.3 2005 2006 2007 2008

1 in 170.1

1 in 265.6

83.1%

50.3%

76.8%

1 in 161.5

1 in 12.9

1 in 87.2

1 in 603.2

Page 3: Paul Wood Senior Analyst, MessageLabs. Email summary.

Factors: CAPTCHA finally broken

Page 4: Paul Wood Senior Analyst, MessageLabs. Email summary.

Example of a Google Docs link in a spam email leading to Google Docs spam content

4

Page 5: Paul Wood Senior Analyst, MessageLabs. Email summary.

Targeted Attacks: Who Is At Risk?

5

2005

2

per week

2006

1

per day

January2007

10

per day

514

in 2 hours

December2007

30

per day

May 2008

80

per day

Large Multinational Corporations

Includes Small/Medium Businesses

Page 6: Paul Wood Senior Analyst, MessageLabs. Email summary.

Factors: Shadow Economy

6

Page 7: Paul Wood Senior Analyst, MessageLabs. Email summary.

Factors: Botnet Evolution – P2P e.g. Storm

Page 8: Paul Wood Senior Analyst, MessageLabs. Email summary.

Storm Botnet

Page 9: Paul Wood Senior Analyst, MessageLabs. Email summary.

Web Security Threats

9

Web Security Services (Version 2.0) Activity:Policy-Based Filtering Web Viruses and Trojans Potentially Unwanted Programs

Web Security Services (Version 2.0) Activity:Policy-Based Filtering by Vertical New Malware Sites per Day

New sites with spyware

New sites with web viruses

Total

261/day

1,050/day

1,311/day

Top 5

Exploit-IFrame 9.2%W32/Winko.worm!cfg 7.5%Exploit-MS07-004 7.2%Trojan-Downloader.JS.Agent.bwo 7.1%VBS/Psyme 6.4%JS/ForcePopup 4.9%MalWarrior 4.3%Trojan-Downloader.JS.Iframe.ib 3.9%Suspicious IFrame.b 3.0%PWS-WoW.gen.a 2.4%

Advertisements & Popups 50.0%Chat 21.2%Unclassified 5.4%Streaming Media 4.0%Games 3.7%Spam URLs 1.8%Downloads 1.7%Adult/Sexually Explicit 1.7%Proxies & Translators 1.3%Gambling 1.3%

PUP:Server-FTP.Win32.Tftpd.274 37.2%PUP:AdTool.Win32.MyWebSearch.bn 13.3%PUP:Adware-Mirar 13.0%PUP:Adware-GAIN 8.0%PUP:AdWare.Win32.Mirar.w 4.1%PUP:Downloader.Win32.FraudLoad.ar 3.5%PUP:AdWare.Win32.Mirar.k 2.5%PUP:RemoteAdmin.Win32.WinVNC.4 2.4%PUP:FraudTool.Win32.MalWarrior.r 1.2%PUP:Downloader.Win32.FraudLoad.al 1.1%

1-500 2500+501-2500Advertisements & Popups 42.4% 62.9%42.1%Chat 13.1% 13.3%41.0%Unclassified 16.0% 0.1%1.8%Games 0.4% 11.7%0.6%Streaming Media 6.9% 1.6%3.9%Adult/Sexually Explicit 1.6% 2.5%2.3%Spam URLs 5.8% 0.0%0.0%Personals & Dating 1.5% 1.6%1.0%Downloads 3.5% 0.0%0.2%Gambling 0.7% 1.7%1.2%Blogs & Forums 1.5% 0.0%2.1%

SQL Injection Attacks

Social Networks

Page 10: Paul Wood Senior Analyst, MessageLabs. Email summary.

Social Networks: Phishing and Spam

10

Page 11: Paul Wood Senior Analyst, MessageLabs. Email summary.

SecondLife: A New World or a New Risk?