On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

March 19th, 2007

Microsoft researchers follow Web spam money trail

Posted by Ryan Naraine @ 7:40 am

Categories: Botnets, Browsers, Data theft, Hackers, Microsoft, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research

Tags: Web, Advertisement, Researcher, Domain, IP, Spam, Microsoft Corp., Advertiser, Ryan Naraine

Using a homegrown tool called Fiddler, researchers at Microsoft have come up with a system to track the money that flows from big-name advertisers to search engine spammers.

The methodology, created by Microsoft Research in partnership with the University of California, Davis, has already uncovered a complex scheme where a small group using false doorway pages are able to profit by  redirecting traffic passed from search engines in one direction and then sending advertisements acquired from syndicators in the opposite direction.  (More at the New York Times).

According to a research paper released by Microsoft, a "five-layer, double-funnel model" can be used to pick apart the end-to-end redirection spam and analyze the layers to follow the money trail.

The five-layers (and findings) explained:

Layer #1 (Fake doorway sites) — Doorway domains at Google's free Blogger (blogspot.com) site had an-order-of-magnitude higher spam appearances in top search results than other hosting domains in both benchmarks, and was responsible for about one in every four spam appearances (22% and 29% in the two benchmarks respectively, to be exact). In addition, at least three in every four unique blogspot URLs that appeared in top-50 results for commercial queries were spam (77% and 75%). The researchers also found that over 60% of unique .info URLs in search results investigated were spam, which was an-order-of-magnitude higher than the spam percentage number for .com URLs.

Layer #2 (Redirection domains) — The researchers fond that the spammer domain topsearch10.com was behind over 1,000 spam appearances in both benchmarks, and the 209.8.25.150~209.8.25.159 IP block where it resided hosted multiple major redirection domains that collectively were responsible for 22-25% of all spam appearances. The majority of the top redirection domains were syndication-based, serving text-based ads-portal pages.

Layer #3 (The aggregators) — Two IP blocks 66.230.128.0 ~ 66.230.191.255 and 64.111.192.0 ~ 64.111.223.255 appeared to be responsible for funneling an overwhelmingly large percentage of spam-ads clickthrough traffic. In the study, the researchers collected over 100,000 spam ads that were associated with these two IP blocks, including many ads served by non-redirection spammers as well. These two IP blocks occupy the “bottleneck” of the spam double-funnel andmay prove to be the best layer for attacking the search spamproblem.

Layer #4 (The syndicators) — The study found that a handful of ad syndicators appeared to serve as the middlemen for connecting advertisers with the majority of the spammers. In particular, the top-3 syndicators were involved in 59-68% of the spam-ads clickthrough redirection chains sampled. By serving ads on a large number of low-quality spam pages at potentially lower prices, these syndicators could become major competitors to mainstream advertising companies who serve some of the same advertisers’ ads on search-result pages and other high-quality,non-spam pages.

Layer #5 (The advertisers)  — The study showed that even well-known websites' ads — bizrate.com, shopping.com, dealtime.com, and shopzilla.com — had a significant presence on spam pages. "Ultimately, it is advertisers' money that is funding the search spam industry, which is increasingly cluttering the web with low quality content and reducing web users' productivity. By exposing the end-to-end search  spamming activities, we hope to educate users not to click spam links and spam ads, and to encourage advertisers to scrutinize those syndicators and traffic affiliates who are profiting from spam traffic at the expense of the long-term health of the web," the researchers explained.

The project has been dubbed Strider Search Ranger and is the work of the research team at Microsoft that created the HoneyMonkey exploit detection system and URL Tracer, a system to track large-scale domain squatters.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 43 Talkback(s)
Has anyone used this?
I had a look at the web site suggested. I wonder has anyone else used this? (Read the rest)
Posted by: brucelparsons@... Posted on: 04/10/07 You are currently: a Guest | | Terms of Use
Why aren't the sellers being held accountable?  No_Ax_to_Grind | 03/19/07
Ar you sure that you want to go after the companies?  B.O.F.H. | 03/19/07
i doubt adobe/MS is fronting the marketing budjets for software pirates....  JoeMama_z | 03/19/07
those aren't the companies sending you the spam  Valis Keogh | 03/19/07
Read what No_Ax_to_Grind suggested.  B.O.F.H. | 03/19/07
I think yiou should read it again.  No_Ax_to_Grind | 03/19/07
I don't care who it is  No_Ax_to_Grind | 03/19/07
They would just go offshore  Been_Done_Before | 03/19/07
Not really...  No_Ax_to_Grind | 03/19/07
But what about these?  James T. Kirk | 03/19/07
Who is selling the stock?  No_Ax_to_Grind | 03/19/07
RE: Who is selling the stock?  James T. Kirk | 03/19/07
One problem..  Patrick Jones | 03/19/07
Again, go back against the SELLER  No_Ax_to_Grind | 03/19/07
YES...go against the manufacturer  jdervin | 03/20/07
Because that would fall a step short..  D-Ram | 03/20/07
I've said that forever  merc2dogs` | 03/20/07
10 to 15 yeears late to the game!  B.O.F.H. | 03/19/07
LMAO  James T. Kirk | 03/19/07
Since 90% of what I get is spam, it is already filtered!  B.O.F.H. | 03/19/07
Amen, brother. (nt)  James T. Kirk | 03/19/07
Filters don't reduce the intenet load  No_Ax_to_Grind | 03/19/07
And?  Patrick Jones | 03/19/07
No...  waterhzrd | 03/20/07
The cost for access is not that expansive.  B.O.F.H. | 03/20/07
slight difference  merc2dogs` | 03/20/07
The cost for access is not that expensive.  B.O.F.H. | 03/20/07
Amen!  Patrick Jones | 03/19/07
Ummm, so what?  No_Ax_to_Grind | 03/19/07
Why don't you stop it then?  TonyMcS | 03/19/07
Well, he needs a reason to rant  No_Ax_to_Grind | 03/19/07
What sort of a juvenile response is that?  B.O.F.H. | 03/20/07
use this  Been_Done_Before | 03/19/07
Has anyone used this?  brucelparsons@... | 04/10/07
Interestingly enough...  jdriddle | 03/19/07
Simply publish co names & products....  dusty_reed@... | 03/19/07
ISPs at fault  cls@... | 03/19/07
Kill Spam at the Source  jdervin | 03/20/07
Is this a decoy for MS Live failure?  Solid Water | 03/20/07
holy sheepdip...  D-Ram | 03/20/07
Revealing and Revelation  Zonny | 03/20/07
Long Time Coming  DistinctDispatches@... | 03/20/07
Advertising Site Review  rtb | 03/20/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc