Re: Web host spam vs spam filters
Steve Atkins <[email protected]> Wed, 19 Jun 2013 17:51:52 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Jun 18, 2013, at 1:30 PM, Martijn Grooten <[email protected]> wrote: > So. I had promised I'd do some research into spam sent from web hosts. Which I did. > > I used 64,000 spam messages sent between 27 April and 13 May 2013. > > They were sent through 20 spam filters in parallel and real-time. > > I defined a 'web host' as an IP address that was listening on port 80 around the time the email was sent. > > About 30% of the spam in this corpus was sent from web hosts. > > Web host spam bypasses a filter with a probability of 1.04%. > > Other spam does so with a probability of 0.29%. > > That's a significant difference. (Note that the spam I use tends to be easy to filter. Relatively little snowshoe spam and dodgy ESPs.) > > There's the usual correlation versus causation disclaimer. It could well be that those spammers who use web hosts (most of which I assume to be compromised, but I didn't look into this) for sending spam are better at sending spam. One obvious difference between a botnet compromised windows desktop and a botnet compromised unix webserver would seem to be that the webserver probably has a perfectly functional MTA, meaning that it'd be less likely to have some of the obvious giveaways (protocol and headers) that the mail from compromised desktops often has. Cheers, Steve- This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org