Re: Web host spam vs spam filters
"Neil Schwartzman" <[email protected]> 20 Jun 2013 05:49:07 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Jun 19, 2013, at 5:51 PM, Steve Atkins <[email protected]> wrote: > > On Jun 18, 2013, at 1:30 PM, Martijn Grooten <[email protected]> wrote: > >> So. I had promised I'd do some research into spam sent from web hosts. Which I did. >> >> I used 64,000 spam messages sent between 27 April and 13 May 2013. >> >> They were sent through 20 spam filters in parallel and real-time. >> >> I defined a 'web host' as an IP address that was listening on port 80 around the time the email was sent. >> >> About 30% of the spam in this corpus was sent from web hosts. >> >> Web host spam bypasses a filter with a probability of 1.04%. >> >> Other spam does so with a probability of 0.29%. >> >> That's a significant difference. (Note that the spam I use tends to be easy to filter. Relatively little snowshoe spam and dodgy ESPs.) >> >> There's the usual correlation versus causation disclaimer. It could well be that those spammers who use web hosts (most of which I assume to be compromised, but I didn't look into this) for sending spam are better at sending spam. > > One obvious difference between a botnet compromised windows desktop and a botnet compromised unix webserver would seem to be that the webserver probably has a perfectly functional MTA, meaning that it'd be less likely to have some of the obvious giveaways (protocol and headers) that the mail from compromised desktops often has. Also, better connectivity and thus speed, and thus an IP can get more out before it is blacklisted by say the Spamhaus CBL. Also, many of these IPs have heretofore reasonable reputations at Senderscore/Senderbase and receivers, I'd imagine. it'd be interesting to track those rep scores before and after.
smime.p7s
(application/pkcs7-signature, 4 KB) - not displayed