The Game Goes On: An Analysis of Modern Spam Techniques

Technical paper

Spam is perhaps one of the most rapidly changing forms of communication we see today. The spammers’ methods of evading detection evolve constantly, differing significantly now from what was employed even in the recent past. Content-based filtering – still a necessary part of any broad and proactive anti-spam solution – is by no means immune from their efforts. Whether based on signatures, URL blocking or heuristic rules, these filters are still sometimes thwarted by sophisticated HTML- and CSS-based obfuscation methods, or by placing the entire content of the message in randomized attached images.

Spammers also tirelessly seek loopholes in domain name registration systems that allow them to avoid pre-emptive detection, and in the security measures of free web-hosting providers so they can mass-register thousands of new home pages every day.

The paper will provide an analysis of many modern anti-anti-spam techniques, accompanied by statistical reports and real-life examples. It will also outline some possible approaches to combat these often highly effective and thus increasingly ‘popular’ spam techniques.

This paper was presented at the VB Conference 2006

Download The Game Goes on: An Analysis of Modern Spam Techniques

Spam is perhaps one of the most rapidly changing forms of communication we see today. The spammers’ methods of evading detection evolve constantly, differing significantly now from what was employed even in the recent past. Download now

Authors

Dmitry Samosseiko

Dmitry has been with Sophos since 2001 where he is responsible for anti-spam initiatives. He is an expert on messaging security and has spoken at numerous user group forums and education security events.

Ross Thomas

Ross focuses on designing and prototyping new anti-spam technologies for Sophos's gateway security products, as well as implementing the back-end software to support them.

download Download our free Virus Removal Tool
Find what your antivirus missed