Live data from Hacker News

Using BGP data to find Spammers

bgpmon.net

1–10 of 17 posts

Re: Using BGP data to find Spammers

#4

The bit I had hoped to see at the end of this article: "and here's how we stopped these bogus routes at their upstream links, to prevent this problem from recurring". Disappointing to see so much analysis and no solution.

This has been a problem people thought had been happening for a while. It's only with this detailed analysis that the light is being cast on it.

Now we can work on solutions. And we will.

Re: Using BGP data to find Spammers

#5
The data does however show a few cases where actively routed address space was announced by the Spam networks, making this a hijack.

So on top of everything, you can get blacklisted for mail that didn't even come from your network?

Re: Using BGP data to find Spammers

#7
post #4

The bit I had hoped to see at the end of this article: "and here's how we stopped these bogus routes at their upstream links, to prevent this problem from recurring". Disappointing to see so much analysis and no solution.

This has been a problem people thought had been happening for a while. It's only with this detailed analysis that the light is being cast on it. Now we can work on solutions. And we will.

No,

This has been looked at pretty extensively before. Confusingly enough, a lot of the research was done by the creators of BGPmon (http://bgpmon.netsec.colostate.edu/ - same name, concept, and primary functionality with no connection between the two as far as I can tell).

The solution is easy enough, secured peering to prevent hijacking, and a centralized certification process to prevent rogue AS's. We've known this stuff for a good decade now, but the exploitation has never been serious enough to overcome push-backs on the costs (both in terms of hardware and reachability issues) from ISPs.

Re: Using BGP data to find Spammers

#9

Interesting that people sophisticated enough in internet routing protocols to squat on unused IP space can get paid more working for spammers than legitimate companies.

It'd be interesting to figure out where their money is coming from. A guess (completely speculative) is that these aren't pure spamming operations, but rather sending spam as one piece of a spam/botnet/phishing mess.

Re: Using BGP data to find Spammers

#10

The data does however show a few cases where actively routed address space was announced by the Spam networks, making this a hijack. So on top of everything, you can get blacklisted for mail that didn't even come from your network?

If by "network" you mean your IP assets then unfortunately the answer is yes.
Post reply on HN