Edward Ferrara serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
The Power Of Data Analysis - "Spamalytics"
Posted by Edward Ferrara on June 1, 2011
Some of you may have seen the article in the New York Times by John Markoff (endnote1) announcing a paper to be presented at last week’s IEEE conference. This paper is an update to research conducted by a team at the International Computer Science Institute in Berkeley, California. The institute is associated with the University of California, San Diego and the University of California, Berkeley. A paper published by the team in 2008 Spamalytics: An Empirical Analysis of Spam Marketing Conversion outlines interesting research in the area the research team has coined as “spamalytics.”
The paper describes a methodology to understand the architecture of a spam campaign and how a spam message converts into a financial transaction. The team looks at the “conversion rate” or the probability an unsolicited email will create a sale. The team uses a parasitic infiltration of an existing botnet infrastructure to analyze two spam campaigns: one designed to propagate a malware Trojan, the other marketing online pharmaceuticals. The team looked at nearly a half billion spam emails to identify:
- the number of spam emails successfully delivered
- the number of spam emails successfully delivered through popular anti-spam filters
- the number of spam emails that elicit user visits to the advertised sites
- the number of “sales” and “infections” produced
In their latest paper, "Click Trajectories: End-to-End Analysis of the Spam Value Chain," the ICIS team addresses the technical and business transaction that makes spam pervasive and the ability of the spammers to monetize a successful response from a spam email.
“Each click on a spam-advertised link is in fact just the start of a long and complex trajectory, spanning a range of both technical and business components that together provide the necessary infrastructure needed to monetize a customer’s visit.” (endnote2)
This research is important. If we can trace the financial transactions of spammers then we can in theory shut down their efforts because we, through a variety of means, can compel banks to not process their financial transactions.
However, the real story from a broader perspective is the power of data and the traceability of spam back to the financial transaction. Admittedly not all hacking is for financial gain. However, much is. Using data analysis techniques and tracing the transaction back to the banks that collect the funds, transfer the money, etc. will be key to stopping this type of cybercrime.
The information security industry has spent billions fighting cybercrime from a technical perspective. We now need to go further, and, like the team from the International Computer Science Institute, look at the financial elements of cybercrime and how the cybercriminal gets paid.
Endnotes
Markoff, John. (2011). Study Sees Way to Win Spam Fight, New York Times.
Levchenko, Kirill; Pitsillidis, Andreas; Chcachra, Neha; Enright, Brandon; Felegyhazi, Mark; Grier, Chris; Halvorson, Tristan; Kanich, Chris; Kreibich, Christian; Liu, He; McCoy, Damon; Weaver, Nicholas; Paxson, Vern; Voelker, Geoffrey; Savage, Stefan. (2011). Click Trajectories: End-to-End Analysis of the Spam Value Chain. Monograph. Department of Computer Science and Engineering, University of California, Sand Diego; Computer Science Division, University of California, Berkeley; International Computer Science Institute, Berkeley, California; Laboratory of Cryptography and System Security (CrySyS), Budapest University of Technology and Economics. San Diego, California, USA.
search forrester's blogs
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (19)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (21)
- Eve Maler (21)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Masami Kashiwagi (1)
- Nick Hayes (5)
- Rick Holland (21)
- Stephanie Balaouras (50)
Top Categories
- Information Security (4)
- Managed Security Services (2)
- Revenue and Growth (2)
- The Value of Data (2)
- business value (1)
- Creating Business Value (1)
- Data privacy (1)
- endpoint security (1)
- enterprise architecture (1)
- Managed Services (1)
- See all
Archives
- June 2013 (1)
- May 2013 (1)
- October 2012 (3)
- August 2012 (2)
- July 2012 (1)
- May 2012 (1)
- April 2012 (2)
- February 2012 (1)
- January 2012 (1)
- December 2011 (1)
- October 2011 (2)
- June 2011 (1)
- May 2011 (2)
- See all
Comments
.Net
Hi,
Thanks for taking the time to discuss this...really awesome blog...