Catching Spammers with IDS

From: Greg Martin (greg_at_ddos.com)
Date: 04/12/05

  • Next message: Dobbelaere, David [NCSBE]: "RE: MPLS IDS question"
    Date: 12 Apr 2005 03:10:12 -0000
    To: focus-ids@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    I am interested in hearing some of your stories on how to catch spammers on your network.

    I know some of their possible characteristics are a definable pattern such as massive # of MX queries on local dns resolver

    or common of late with the big spammers is to use compromised hosts (proxy spamming) which will be thousands of outgoing or incoming reverse DNS lookups at high rate.

    A quick google returns very little on this subject, so how are _you_ using current IDS technology to proactively look for spammers?

    Please share your knowledge, snort rules, bpf's anything to help bring and end to this nuisance

    - Greg Martin

    --------------------------------------------------------------------------
    Stop hurting your network!
     
    The NeVO passive vulnerability sensor continuously finds vulnerabilities,
    applications and new hosts without the need for network scanning.
    It also finds compromised systems with application-based intrusion detection.
    Go to http://www.tenablesecurity.com/products/nevo.shtml to learn more.
    --------------------------------------------------------------------------


  • Next message: Dobbelaere, David [NCSBE]: "RE: MPLS IDS question"

    Relevant Pages

    • Re: Newsgroups: MS should WARN us FIRST not to use real email addresses here!!
      ... Just a quick note to add: it does appear that MS is concerned about spammers ... Had Microsoft offered this very simple instruction in the beginning, ... This is on their network afterall, and their NEGLIGENCE to provide this ... dangerous security breach. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: ANI vs. Caller ID [Telecom]
      ... have to be installed and used on a switch-by-switch basis, ... So even if there is a law requiring all IDs sent to the network to be ... Then the good-guy telco could use one bit in the CLID strings it ... The Fax Spammers are already on the network; ...
      (comp.dcom.telecom)
    • Re: oh oh, bot nets
      ... packets are coming from some "other" country, ... It's a variation on the response to spammers by ... mail administrators - "my network, ... We rarely bother logging rejected ...
      (comp.security.firewalls)
    • Re: Broadcasting over a network
      ... > possibly a reply) to an individual PC or all PC's on a network. ... Unfortunately abuse of this feature by spammers ... to work being disabled on most Windows machines by default. ... Messenger Service. ...
      (microsoft.public.windowsxp.network_web)
    • RE: SIM Tools, and endpoint security.
      ... If you are a Cisco shop neuSECURE does a very good job of integrating with Cisco products. ... syslog type perspective to complement our Network Intrusion plan. ... dump OS logs, app logs, fw logs, router and switch logs to the SIM and would ... The NeVO passive vulnerability sensor continuously finds vulnerabilities, ...
      (Focus-IDS)