Home / News

Gary Warner: We Are Well Past Time to Declare a Spam Crisis in China

Gary Warner: We Are Well Past Time to Declare a Spam Crisis in China

In a blog post last week, Gary Warner, director of research in computer forensics at the University of Alabama's (UAB) computer and information sciences department, wrote that it is well past time for someone to declare a "Spam Crisis in China". The warning comes along with UAB's reports that most of the spam they receive has ties to China.

"It is very normal that more than one-third of the domain names we see each day in spam messages come from China," Warner wrote. "When one also considers the many '.com' and '.ru' domain names which are also hosted in China, the problem is much worse. More than half of all spam either uses domain names registered in China, is sent from computers in China, or uses computer in China to host their web pages."

Related Links:
Spam Crisis in China Gary Warner, Jun.20.2009
Chinese Registrars Need Rap on Knuckles, Expert Says PC World, Jun.29.2009

Related topics: Cybercrime, Malware, Security, Spam

Get a weekly summary of postings to CircleID:

 Master Feed (more feeds)      Twitter      Mobile
Bookmark / Email This Post

Comments

I can confirm this Suresh Ramasubramanian  –  Jun 29, 2009 8:23 PM PST

Our statistics indicate that a huge majority of this originates from at the most three or four registrars based in China

Xiamen Ename - which is the registrar for over 50% of domains we find in unsolicited bulk email every week - quite often fastflux

Xinnet is another one that has several such domains (a few hundred compared to over a thousand a week on ename)

Also others like Onlinenic and Paycenter.com.cn

The above statistics are from analyzing domains listed on the SURBL blocklist - http://www.surbl.org Suresh Ramasubramanian  –  Jun 29, 2009 8:24 PM PST

Just to clarify the above data point.

We should clean up our own house first Edward Falk  –  Jun 30, 2009 10:49 AM PST

The spam may be coming through Chinese servers, but if you track it back to its source, half the time you'll find it actually originated here in the U.S.

Remember last November when McColo in San Jose, California was finally disconnected?  Spam dropped 60-70% worldwide over night.  The shutdown of rogue site 3fn, also in San Jose, earlier this month led to another significant drop in spam.

And frankly, if you dropped a nuke on Boca Raton, you'd probably see a huge reduction in worldwide spam.

If the U.S. were to take spam seriously, it would be the single most effective thing that could be done to combat the problem.

Granted / point taken about chinese IP space Suresh Ramasubramanian  –  Jun 30, 2009 5:07 PM PST

The point Gary's making though is a bit different. Domains registered in spam, through registrars (in fact just two or three registrars for the most part) based in China.

As for origins, you'd be closer if you looked at eastern europe than at boca raton.

To post comments, please login or create an account.

Related Blogs

Related News

Other Topics

Access Providers Broadband Censorship Cloud Computing Cyberattack Cybercrime Cybersquatting Data Center DNS DNSSEC Domain Names Domain Registries Email Enum ICANN Internet Governance Internet Protocol IP Addressing IPTV IPv6 Law Malware Mobile Multilinguism Net Neutrality P2P Policy & Regulation Privacy Regional Registries Security Spam Telecom Top-Level Domains VoIP Web White Space Whois Wireless



Industry Updates – Sponsored Posts

ICANN and Cybersecurity: Hot Topics at The First Ever .ORG Forum

Neustar Implements DNS Security Extensions in the .US Registry

Paid Search Ads Can Lead to Fake Goods

Neustar Launches Initiative to Enhance DNS With Faster, More Secure Updates

Registry Stakeholder Group Comments on Latest ICANN Policies

Open Phishing Season

Nominum Announces "DNSSEC Made Easy" Solutions

.ORG Highlighted for Success in Fighting Phishing

Afilias' Matt Pounsett Elected Director-at-Large for DNS-OARC

SEO Poisoning: A Persistent Malware Threat Targeting High-Profile Brands

Nominum CEO: Commercial vs. Open Source - Let Customers Choose

Pharmaceutical Brandjacking for Popular Drug Brands on the Rise

Nominum Broadens Intelligent DNS Impact With SKYE Cloud Services

Afilias Managed DNS Services Adds SiteCertain to Keep Watch on Your Web Site

DNSstuff.com Launches Industry's First Mail Server Test Center

Growing Global Adoption of Nominum's Intelligent DNS Spells Obsolescence for Legacy DNS Systems

Nominum's Intelligent DNS Gives Service Providers Commanding Advantage Against Internet Threats

MarkMonitor to Host New Webinar Series with Noted Trademark Law Authority Anne Gilson LaLonde

ISC, Afilias and Neustar Bring DNSSEC One Step Closer

Afilias Secures Millions of Internet Domains from BIND 9 Vulnerability with DNS Diversity Strategy