rpclogo

 

To beat spam, turn its own weapons against it

SPAMMERS' own trickery has been used to develop an "effectively perfect" method for blocking the most common kind of spam, a team of computer scientists claims.

Most of the billions of spam messages sent each day originate in networks of compromised computers, called botnets. Unbeknown to their owners, the machines quietly run malicious software in the background that pumps out spam.

Researchers have now come up with a system that deciphers the templates a botnet is using to create spam. These templates are then used to teach spam filters what to look for.

The system, developed by a team at the International Computer Science Institute in Berkeley, California, and the University of California, San Diego, works by exploiting a trick that spammers use to defeat email filters. As spam is churned out, subtle changes are typically incorporated into the messages to confound spam filters. Each message is generated from a template that specifies the message content and how it should be varied. The team reasoned that analysing such messages could reveal the template that created them. And since the spam template describes the entire range of the emails a bot will send, possessing it might provide a watertight method of blocking spam from that bot.

To test their idea, the team installed a previously captured software bot onto a machine. After analysing 1000 emails generated by this compromised machine - less than 10 minutes' work for most bots - the researchers were able to reverse-engineer the template. Knowledge of that template then enabled filters to block further spam from that bot with 100 per cent accuracy.

High accuracy can be achieved by existing spam filters, but sometimes at the cost of blocking legitimate mail. The new system did not produce a single false positive when tested against more than a million genuine messages, says Andreas Pitsillidis, one of the team: "The biggest advantage is this false positive rate."

"This is an interesting approach which really differs by using the bots themselves as the oracles for producing the filters," says Michael O'Reirdan, chairman of the Messaging Anti-Abuse Working Group, a coalition of technology companies. But he adds that botnets have grown so large that even a 1-minute delay in cracking the template would be "long enough for a very substantial spam campaign".

The research will be presented in March at the Network and Distributed System Security Symposium in San Diego.

Courtesy Computer Crime

 

 

  HOW DOES THIS WORK ?
call1 Call our agents at 209-642-4483 and log your issues to us
age Our agent gets connected to your system remotely
che Sit back and relax or watch out our service
kno Once the issues are solved, the agent feeds you the knowledge transfer and disconnects from your computer
comm You can send your feedback / comments / expereince to support@remotepccure.org

 

Virus Removal Tool Names
Vcleaner
Removes the following viruses:
I-Worm/Stration, Worm/Generic.FX, Agent.A-AN, BackDoor.Agent.A-Z, BackDoor.Agent.AA-BG, Downloader.Agent.AS, I-Worm/Atak.A-I, Bagle.DA-IU, I-Worm/Bagle.A-Z, I-Worm/Bagle.AA-JD, I-Worm/Bugbear.D, I-Worm/Mytob.A-GC, I-Worm/Netsky.A-Z, Worm/Netsky.AA-AD, I-Worm/Sasser.A-F, I-Worm/Zafi.A-E, PSW.Bispy.A-E, Win32/Gaelicum, Win32/Hidrag
Worm/Downadup (Worm/Conficker)
Removes the following viruses:
Worm/Downadup (Worm/Conficker)
Downloader.Stubby.A
Removes the following viruses:
Downloader.Stubby.A
I-Worm/Bugbear.C
Removes the following viruses:
I-Worm/Bugbear.C )
I-Worm/Ganda
Removes the following viruses:
I-Worm/Ganda, papaDog Download remover:
rmganda.exe
Win32/Expiro
Removes the following viruses:
Win32/Expiro
I-Worm/Happy99
Removes the following viruses:
I-Worm/Happy99
I-Worm/Lovgate.C
Removes the following viruses:
I-Worm/Lovgate.C
I-Worm/Luder
Removes the following viruses:
I-Worm/Luder
Win32/Dundun
Removes the following viruses:
Win32/Dundun
I-Worm/Mydoom.A and B
Removes the following viruses:
I-Worm/Mydoom.A and I-Worm/Mydoom.B
I-Worm/Mydoom.F
Removes the following viruses:
I-Worm/Mydoom.F
I-Worm/Navidad
Removes the following viruses:
I-Worm/Navidad
I-Worm/Nimda
Removes the following viruses:
I-Worm/Nimda
I-Worm/Pretty_Park
Removes the following viruses:
I-Worm/Pretty_Park
I-Worm/Sircam.A
Removes the following viruses:
I-Worm/Sircam.A
I-Worm/Sober.A
Removes the following viruses:
I-Worm/Sober.A
I-Worm/Swen
Removes the following viruses:
I-Worm/Swen
I-Worm/Verona.B
Removes the following viruses:
I-Worm/Verona.B
LOP.AH/Backdoor.Generic3.SVX
Removes the following viruses:
LOP.AH/Backdoor.Generic3.SVX
Packed.Protector.C
Removes the following viruses:
Packed.Protector.C
Win32/Vampiro
Removes the following viruses:
Win32/Vampiro
VBS/Iloveyou
Removes the following viruses:
VBS/Iloveyou
Win32/Alman
Removes the following viruses:
Win32/Alman
Win32/Delf.2.B
Removes the following viruses:
Win32/Delf.2.B
Win32/Dupator
Removes the following viruses:
Win32/Dupator
Win32/Elkern, variants A, B and C
Removes the following viruses:
Win32/Elkern.A, Win32/Elkern.B, Win32/Elkern.C
Win32/Gaelicum
Removes the following viruses:
Win32/Gaelicum
Win32/Kriz
Removes the following viruses:
Win32/Kriz
Win32/Mabezat
Removes the following viruses:
Win32/Mabezat
Win32/Magistr, variants A and B
Removes the following viruses:
Win32/Magistr.A, Win32/Magistr.B
Win32/Parite
Removes the following viruses:
Win32/Parite
Win32/Prepender
Removes the following viruses:
Win32/Prepender
Win32/Sality
Removes the following viruses:
Win32/Sality
Win32/Tanatos, variants A, H, I and M
Removes the following viruses:
Win32/Tanatos A, Win32/Tanatos H, Win32/Tanatos I, Win32/Tanatos M
Win32/Valla.2048
Removes the following viruses:
Win32/Valla.2048
Win32/Virut
Removes the following viruses:
Win32/Virut
Worm/Lovsan
Removes the following viruses:
Worm/Lovsan

 

 

SERVICES FROM RPC

Antivirus Software

Computer Troubleshooting

Dell Computer Support

Toshiba Computer Support

Other Articles