Feeds

Honeynet research lifts the lid on spam trends

Busy bees reveal a hive of junk mail activity

Securing Web Applications Made Simple and Scalable

Stats from the one billion spam messages blocked by Project Honey Pot over the last five years provide an insight into junk mail trends and spamming practices.

The Honey Pot project was formed by a community of web administrators as an alliance against online fraud and abuse back in 2004. The group now numbers 40,000 members in 170 countries, making it the biggest effort of its kind on the web.

Last week, the group trapped its one billionth spam email message - an IRS phishing scam junk mail - since when the group has been poring through its archives, teasing out trends.

Stats from the project reveal that Monday is the busiest day of the week for email spam, and Saturday the quietest. Spam volumes peak around 12:00 (GMT) and reach a low around 23:00 (GMT). Spam volumes drop nearly 21 per cent on Christmas Day and 32 per cent on New Year's Day, a sign that junk mailers take time off over the holidays just like everyone else.

The project reckons it takes the average spammer around two and a half weeks from harvesting an email address to sending the first spam message to this address, twice as fast as junk mailers operated five years ago. Every time a user's email address is harvested from a website, it results in an average of 850 spam messages.

Over the last five years, the Project Honey Pot group has seen nine times more phishing email for Chase Bank than Bank of America. However, Facebook is gaining rapidly on the rails and is set to overtake Chase to become the most phished online organisation next year.

Project Honey Pot's full report is due to be released later on Tuesday and will be available here.

The Project Honey Pot community, which started off with an attempt to systematically figure out how spammers harvest email addresses, has moved on towards working with law enforcement organisations and security companies to provide anti-spam intelligence.

Much of the spam tracked by Project Honey Pot flows out of botnet networks of compromised PCs. Figures from MessageLabs, published on Tuesday, provide one of the most detailed breakdowns of the size and spam volumes associated with the world's ten worst spam-spewing botnets.

The Rustock botnet tops the pile, generating an estimated 19 per cent of global junk mail, from somewhere between 540K and 810K compromised hosts, MessageLabs estimates. Other big junk mail sources include Cutwail (17 per cent of global spam), Bagle (16 per cent), Bobax (14 per cent) and Grum (9 per cent). ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.