By Renay San Miguel E-Commerce Times
11/13/08 2:02 PM PT
Rather than wait for the cops to go to a judge and get a subpoena, a group of security researchers took their case directly to the ISPs that serve McColo, which the researchers identified as a major enabler of an eastern European spam botnet.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
If you notice less spam in your e-mail inbox today, you can thank a coalition of cybersecurity researchers who have made it their mission to sew up spam-based "botnets" on the Web.
Earlier this week, HostExploit.com gave a Washington Post reporter information about a hosting company, McColo, that was allegedly providing command-and-control capabilities for a network of remote-controlled computers sending out spam for child pornography, fake pharmaceuticals and identity theft "phishing."
The reporter and HostExploit then notified McColo's Internet service providers, and those ISPs pulled the plug on McColo. The result: an estimated 40 percent dropoff in worldwide spam, "and some people, from their vantage points, saw an even greater drop than that," said Paul Ferguson, a Trend Micro (Nasdaq: TMIC) advanced threat researcher who contributed intelligence on McColo to HostExploit.
Not Vigilantes
The coalition had similar success in September with another hosting company, Atrivo. HostExploit's role is not to become vigilantes, Ferguson told the E-Commmerce Times. "We kind of hate that word," he said, because the group cooperates with law enforcement and notifies authorities when it finds evidence of illegal activities. But the intent is to allow the industry to police itself by notifiying ISPs who may not be aware of what's happening on their networks.
"We need to clean up our own backyard," Ferguson said.
Pulling the Rug Out
"I have the graph sheets right in front of me. It's like the volume (of spam) fell off a cliff," Matt Sergeant, senior anti-spam technologist with Message Labs, told the E-Commerce Times. "What I'm looking at is a graph from our Message Labs spam traps, which on a regular day gets about 60 million e-mails a day. This probably literally dropped to about 10 million a day." Sergeant's spam traps receive botnet-produced spam, so "it focuses strongly on the type of stuff that taking down McColo would reduce."
(click on image to enlarge)
The victory will be short-lived, Ferguson admits. The botnet will end up in use by some other criminal entity, probably within days. "They're not going to go down silently. They're just like cockroaches, they'll scatter and pop up somewhere else," Ferguson said. "But by having their hand forced, we can see them and track them."
Here's what Ferguson and HostExploit know about the group using McColo: it is based in Eastern Europe and uses well-connected ISPs to either set up shell companies that appear to be legal Web hosting services, or trying to dupe legitimate hosting providers into running their content. "They've done this around the world."
The Relationship With Law Enforcement
HostExploit kept law enforcement apprised of its investigation and provided evidence at all times, Ferguson said. "We would have certainly complied with any request from law enforcement to not publicize the information if that request had been made." But that request never came, and HostExploit knows that it can take a lot longer for authorities to make their cases and get subpeonas, "especially when it's against persons unknown in Eastern Europe. We had to try a different tactic, to work within the community at large."
That tactic: Make ISPs aware when hosting companies suspected of illegal activities are in possible violation of their contractual agreements. "We certainly wanted to make sure that law enforcement could conduct their investigations, but at some point in time we agreed that the evidence had to be presented to the ISPs, because people are being victimized on a daily basis."
Sergeant agrees, and hopes that incidents like the McColo case serve as a wake-up call for authorities. "The anti-spam community knows a lot about the technical side of this and just got tired of waiting for law enforcement to take action. They've had to take matters into their own hands. If it were any other issue than just spam -- that was more of a political hot button, if you like -- then the law would be down there immediately, grabbing those (server) boxes."
Because of the profits involved in cybercrime, Ferguson knows that HostExploit won't have a lot of time to celebrate. "We're not disillusioned by the fact that this is a small victory. We'll enjoy it when we get them. The real thing is to hit these guys where it hurts -- to make the costs of doing business so high that they have to go somewhere else to do it. Taking money out of their pockets is what they understand."
FTC Busts Spam Gang October 15, 2008
Checked out your spam folder lately? You might find the handiwork of a couple of big-time spammers there: messages offering miraculous male-enhancement and weight-loss pills -- or brand-name prescription drugs at impossible prices. Two of the big-time spammers behind such sham offers have been shut down, but it's likely that others will step in to keep taking advantage of gullible consumers.
Related Stories
ICANN Almost Cracks Down on Spammy Domain Registrar October 31, 2008
An Estonian domain name registrar received a late stay of execution from the international body that regulates the domain name system. The Internet Corporation for Assigned Names and Numbers was threatening to pull EstDomains' registrar status because EstDomains' president was convicted of fraud.
Virginia SC Scuttles Spam Law September 12, 2008
The Virginia Supreme Court has declared the state's antispam law unconstitutional, turning loose a notorious spammer who had been sentenced to nine years in prison for violating it. The law did not distinguish sufficiently between protected and unprotected speech, the Court found.
Related News Alerts
More by Renay San Miguel
Sony Talks Up Plans for Digital Media Superstore November 20, 2009
Sony is one of the few companies in the world with an ecosystem of hardware and services that could match Apple's. It just doesn't mesh together nearly as smoothly as Cupertino's. Sony executives want to change that. They've announced plans to build an online network that ties in many of the company's products and allows users to download a wide variety of content.
Playboy's Bunny Couldn't Make the Hop to the Web November 20, 2009
The party may be winding down for Playboy. Buyers may be attempting to wheel a deal for Playboy Enterprises, which could in turn bring an end to a publication long past its heyday. It seems that a magazine that was one of the first to storm the barricades of censorship couldn't conquer 21st-century cyberspace.
AOL Spinoff May Send Third of Workforce Reeling November 19, 2009
When it parts ways with Time Warner next month, AOL will likely begin laying off as many as 2,500 workers, about a third of its staff, the company said. The once-mighty portal and Internet service provider faces the task of redefining itself and deciding which of its assets to keep and which to let go. There's still some hope for the company that gave millions their first glimpse of the Internet.