Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Act to Amend the Copyright Act
Want a copyright law that protects spyware and virus writers? If not, sign our petition to amend Bill C-61
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Image spammers try PDFs on for size

Spam filter reports from a couple of months ago suggested the usual barrage of image spam had eased up, but the reality is those images had merely assumed a new identity: Portable Document Format (PDF).

Most vendors of messaging security systems have incorporated some sort of defense against image spam, which has only led spam creators to find novel modes of entry, specifically through what has become the "de facto standard" for sending documents between organizations, said Andrew Graydon, chief technology officer of Mississauga, Ont.-based messaging security vendor BorderWare Technologies Inc.

This latest spam tactic works because most messaging security tools detect images in the form of JPEG, JIF and PNG, for example, but not those in PDF.

"Spammers will always find the vulnerability, and push the limits to find where the majority of vendors are not solving the problem," said Graydon. And it's surprising, he added, how few messaging security systems scan the contents of PDF documents – making the tactic successful across 80 per cent of security solutions on the market.

Currently, he said PDF spam accounts for about 50 per cent of image spam, a marked increase from the initial three per cent when spammers were still testing the waters a couple of months ago before finally opening the floodgates.

PDF spam is just another invasion technique designed to bypass "reasonably effective" defenses against basic image spam, said Larry Karnis, president of Toronto, Ont.-based messaging security provider XPM Software Inc.

"They can put the same image in a PDF document and the PDF document wrapper allows the image to travel through the spam filter undetected," said Karnis.

But as with all forms of malware, PDF spam – currently a simple format of identical images for content – will soon take on different appearances as it morphs to avoid detection, said Graydon. "We're going to start seeing some of the exploits happening on the PDF where they're going to start changing the size of the PDF, and the size of the image inside."

But Karnis believes PDF spam will be a short-term threat because they are relatively easy for vendors to block: companies using an anti-spam tool and are under a maintenance agreement with the product vendor should see the problem going away fairly quickly.

Besides, he added, the impact thus far has been nowhere near as severe as the initial image spam attacks that hit last year. And the tactic is hardly economical from the spammer's point of view, given PDF attachments tend to inflate message size thereby reducing the number of outgoing attacks from a botnet.

Spammers at this point are probably trying to work out the economics of PDF spam given the limited number attacks that can be launched, said Bradley Anstis, director of product management for Basingstoke, U.K.-based Marshal Ltd., a provider of e-mail and internet management solutions.

And although the campaign was initially successful, he said, messaging security vendors will bolster their defenses towards the attacks, resulting in an eventual decline in number.

Currently, Graydon said companies are employing various approaches to the PDF spam problem. Some are passively "grinning and bearing it" because the technology they have in place doesn't solve the issue. Others are quarantining incoming PDF documents and letting users retrieve the 'clean' files from the quarantine.

Karnis isn't keen on the quarantine approach as it's indicative of an inferior anti-spam product, which really only serves as a location for e-mail that the spam filter couldn't decide what to do with.

Others, Graydon added, are making the better decision to deploy superior messaging security systems that can scan the content of PDF documents.

Companies should evaluate the technologies they have in place, agreed Anstis – in particular recommending multi-facetted spam engines to capture multiple forms of spam attacks.

Besides that, he said, "be aware that it's happening and let employees know. It's always better to err on the side of caution."

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.