Re: [Rucus] article: Six botnets churning out 85 percent of all spam

Otmar Lendl <ol@bofh.priv.at> Thu, 06 March 2008 09:07 UTC

Return-Path: <rucus-bounces@ietf.org>
X-Original-To: ietfarch-rucus-archive@core3.amsl.com
Delivered-To: ietfarch-rucus-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 27B7828C822; Thu, 6 Mar 2008 01:07:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.485
X-Spam-Level:
X-Spam-Status: No, score=-100.485 tagged_above=-999 required=5 tests=[AWL=-0.048, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_ORG=0.611, RDNS_NONE=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EWZRRzHh07QH; Thu, 6 Mar 2008 01:07:32 -0800 (PST)
Received: from core3.amsl.com (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 717CB28C3A6; Thu, 6 Mar 2008 01:07:32 -0800 (PST)
X-Original-To: rucus@core3.amsl.com
Delivered-To: rucus@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 30DC43A6A04 for <rucus@core3.amsl.com>; Thu, 6 Mar 2008 01:07:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wtT-c9C-jkKw for <rucus@core3.amsl.com>; Thu, 6 Mar 2008 01:07:30 -0800 (PST)
Received: from mail.bofh.priv.at (fardach.bofh.priv.at [88.198.34.164]) by core3.amsl.com (Postfix) with ESMTP id 6F9C928C170 for <rucus@ietf.org>; Thu, 6 Mar 2008 01:07:30 -0800 (PST)
Received: by mail.bofh.priv.at (Postfix, from userid 1000) id BDB9B4C975; Thu, 6 Mar 2008 10:07:17 +0100 (CET)
Date: Thu, 06 Mar 2008 10:07:17 +0100
From: Otmar Lendl <ol@bofh.priv.at>
To: rucus@ietf.org
Message-ID: <20080306090717.GA15733@bofh.priv.at>
References: <04fb01c87f05$cdd8a330$c4f0200a@cisco.com>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <04fb01c87f05$cdd8a330$c4f0200a@cisco.com>
User-Agent: Mutt/1.5.13 (2006-08-11)
Subject: Re: [Rucus] article: Six botnets churning out 85 percent of all spam
X-BeenThere: rucus@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "Reducing Unwanted Communication Using SIP \(RUCUS\)" <rucus.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/rucus>, <mailto:rucus-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/rucus>
List-Post: <mailto:rucus@ietf.org>
List-Help: <mailto:rucus-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rucus>, <mailto:rucus-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: rucus-bounces@ietf.org
Errors-To: rucus-bounces@ietf.org

On 2008/03/05 22:03, Dan Wing <dwing@cisco.com> wrote:
> To get a feeling of botnets and their contribution to today's email spam:
> 
>         "...
>         At its peak, the Storm network accounted for 21 percent of all spam
> and contained an estimated 85,000 bots. Mega-D, on the other hand, grew to
> encompass 32 percent of the spam network in early February, but contained only
> an estimated 35,000 bots.
>         ..."

If we think that the threat to open SIP proxies is comparable to the
spam problem in the current email ecosystem, then this bodes ill for any
approach which is based on trust between originating and terminating SIP
provider. (e.g. interface (b) from draft-niccolini-sipping-spitstop-01)

/ol
-- 
-=-  Otmar Lendl  --  ol@bofh.priv.at  -=-
_______________________________________________
Rucus mailing list
Rucus@ietf.org
https://www.ietf.org/mailman/listinfo/rucus