About Me

Nick Kelly

Nick Kelly

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Image Spam Part 1 – Explosion in 2006

Friday, January 12, 2007 at 7:02am by Nick Kelly
Nick Kelly

Image spam

Spam containing images, or “image spam” was a major focus of spammers and Anti-Spam vendors during 2006. During the last few years techniques used to detect text based spam, and the computers that were sending it, were effective at detecting almost all spam and spammers were fighting a losing battle getting their spam delivered to inboxes.

During the second quarter of 2005 spammers began to develop a technique of including an image rather than text to carry the spam message. This type of spam started to increase in complexity and volume, and by the start of 2006 image spam accounted for up to 30% of all spam. By October image spam had increased up to 40% of all spam and by the end of 2006 image spam accounted for up to 65% of all spam. With a 100% increase in image spam, which is typically 3-4 times the size of text based spam, there must have been a lot of extra junk clogging up the tubes of the internet last year.

Increase in image spam

At the start of the year image spam consisted primarily of ‘pump and dump’ stock spam. This was more suited to image spam as it did not require recipients to click on a link. By the end of the year image spam was advertising ‘pump and dump’ stock, pharmaceuticals, fake degrees, counterfeit software, loans, mortgages and other kinds of junk usually associated with text based spam.

Image spam, like text based spam, is continually changing and although many of the images appear to be the same at first glance, in most cases each image is unique. Even the older image spam used techniques to avoid detection such as random background noise in the image file, random image file names, random subject lines and ‘hash buster’ message bodies were added to disguise the spam. Some image spam used animated gifs and some used multi-layer image files to hide the spam message in the image.

Over the year McAfee developed a large number of methods to detect image spam accurately. Analyzing the actual content of the image is very slow and CPU intensive, and spammers have already started to obfuscate the text in the spam to prevent OCR techniques from classifying the image (for example by using wavy or broken text as in the examples above.) McAfee Anti-Spam does not analyze the actual ‘picture’ as this is slow and not currently necessary to detect the spam. Instead McAfee Anti-Spam uses a number of techniques to detect image spam, some are based on the (mostly botnet) computers used to send the spam and some are based on analysing the content of the spam message. Current McAfee Anti-Spam detection rates for image spam are around 99%+.

The trend of image spam seems certain to continue in 2007 as spammers continue to build up their botnets and hone the tools used to distribute this type of spam.

Further blogs regarding image spam and some of the techniques used to detect it are planned for the coming weeks/months.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (3)

  • Anti-Spam Info October 3, 2007 2:38AM

    I must say that a great analysis have been done in terms of the number of stocks being spammed. I am myself have been looking for some relavent and useful articles regarding spamming. One of the web page that i certainly found worthful to be shared is Spam-Filtering, Comment Spam, Anti-Spam, Anti-Spam Solutions Website

  • Bla January 22, 2007 2:55AM

    What exactly are the efforts of McAfee on detecting image spam? I cannot confirm the 99+%
    The analysis is quite complex, as image spam never drops in for a second time. If one image spam is not recognized, you will sure adapt your ruels and filters and after a couple of hours THAT one would have been rejected now… however, it would not come again.

    Bla

  • Natraj January 12, 2007 12:20PM

    Thank you for keeping us informed.