SPAM Turning the tide Gregory Massel iWeek 2004.

Slides:



Advertisements
Similar presentations
How Lawsuits Against Spammers Can Aid Spam-Filtering Technology: A Spam Litigators View From the Front Lines Jon Praed Internet Law Group
Advertisements

Virtual Conference on Anti-spam Regulation and Policy Development Sharing The Singapore Experience By Low Boon Kiat Policy & Competition Development Group.
An Anti Spam Action Strategy John Haydon, Australian Communications Authority.
Anti-SPAM activities in Malaysia - Current Situation, Regulatory Environment and Future Developments ITU virtual conference on anti-spam regulation and.
By Andy Scott, Michael Murray and Adam Kanopa
CHAPTER 4 E-ENVIRONMENT
Addressing spam and enforcing a Do Not Registry using a Certified Electronic Mail System Information Technology Advisory Group, Inc.
Anti Money Laundering (AML) An Overview for Staff Prepared by MSM Compliance Services Pty Ltd.
An Overview of the Law on Spam Anti-Spam Research Group San Francisco, CA March 20, 2003 Jon Praed Internet Law Group
E-Business Technologies BCM SPAM Rafael Quiroz Vázquez Professor Eduard Heindl.
Marketing: Comply with the Law 28 th February 2007 Liz Rowe.
Fraud and Identity Theft: The United Nations Crime Commission Intergovernmental Expert Group on Fraud and the Criminal Misuse and Falsification of Identity.
New Canadian Anti-Spam Legislation Robert Lipson – April 8, 2014.
By The Blank Mind Group Dana Fellows Jason Kohut Rick Barton Darrell Fraser Kuo-Luen Chang Darrell Fraser Kuo-Luen Chang.
1 Securing the Net: Where the Holes Are Steven M. Bellovin AT&T Labs – Research
From Spam to Cyber Security Roles and Challenges for Operators CANTO 13 August 2014 Karen Mulberry.
How To Make Marketing Work for Your Small Business or Non-Profit Presented by Milton Zlotnick SCORE Counselors to America’s Small Business Chapter.
1 Unsolicited Electronic Messages Ordinance An Overview of Implementation and Enforcement 28 May 2007.
Preparedness for cybersecurity threats domestic aspects of cyber security Jaan Priisalu.
Spam Sonia Jahid University of Illinois Fall 2007.
MIT Info Group, January 19, 2005 Page 1 The CAN-SPAM Act and what it means for MIT communicators MIT Info Group, January 19, 2005 Marsha Sanders Senior.
ICASAS206A Detect and protect from spam and destructive software Identify and Stop Spam Warren Toomey North Coast TAFE Port Macquarie campus.
Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Untouchable?: A Canadian Perspective on the Anti- Spam Battle Michael Geist Canada Research Chair in Internet & E- commerce Law University of Ottawa, Faculty.
Should there be a law that forbids people from sending to thousands of people (spam)? By: Bennett Moss Daniel Hoyt Hizkias Neway Junyu Wang.
Spam and E-Security Bruce Matthews Manager, Anti-Spam Team International Training Program 11 September 2006.
Presented by Bishop & McKenzie LLP May 30, Vancouver Sun, “Anti-Spam Legislation Has Businesses Scrambling to Comply”, May 26, 2014.
Spam / Phishing Björn Bittins Sebastian Kühnau FHTW-Berlin.
1 The Business Case for DomainKeys Identified Mail.
XP New Perspectives on The Internet, Sixth Edition— Comprehensive Tutorial 2 1 Evaluating an Program and a Web-Based Service Basic Communication.
TOGOLESE CONSUMERS ASSOCIATION (ATC ) Fifth Annual African Consumer Protection Dialogue Conference (Zambie september 2013) “ Moving Cross Border.
2 nd International Summer School Risks and Challenges of the Network Society Karlstad University and HumanIT Theme: Service Provider Responsibility for.
Africa, on the Road to Athens, Cairo september 2006 SPAM in Africa: Problems and Solutions? Adel GAALOUL, Président Directeur Général Agence Tunisienne.
The Internet and Access to Information Why is it so difficult to eliminate SPAM? By:Juan C. Vargas Computer Science 450.
Canada’s Anti Spam Legislation. What is CASL? CASL was intended to combat negative online behaviour  spam  phishing  malware  spyware  It will create.
ACMA - regulating spam and telemarketing Dannielle Evans Senior Lawyer International Training Program Melbourne, 4 September 2006.
1 OECD anti-spam initiatives Anti-SPAM Strategies – The Way Forward for the ASEAN Telecommunications Regulators’ Council (ATRC) 3-4 May 2005, Cyberjaya,
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
Unsolicited Commercial Meeting of Oftel Internet Forum 22 July 1999 EU Distance Selling Directive provisions on unsolicited .
Spam Act 2003 Consumer Education and Awareness. About the ACA Independent government regulator Ensures industry compliance with legislation (Telecommunications.
SPAMMING BY VASILIS ODONTIDIS Please read carefully, This is secret and confidential. “It is true that I pray to GOD before I was pushed forward.
Chapter 6 International crime. In this chapter, you will study the concept of international crime. You will be introduced to the main categories of international.
Anti-Spam update Unsolicited Electronic Messages Bill and ISP Spam Code of Practice 2 February 2006 Keith Davidson Executive Director.
Privacy Issues In Market Research Duane L. Berlin, Esq. General Counsel, CASRO Principal, Lev & Berlin, P.C. PL&B Annual Conference Cambridge, MA 22 August.
A FRICA INTERNET GOVERNANCE FORUM TH SEPTEMBER,2015 AFRICA UNION COMMISSION HQS, ADDIS ABABA,ETHIOPIA Presented By: Michael Ilishebo, ZAMBIA.
Regulation of Personal Information Sally Brierley & Emma Harvey.
SCAMS and SPAM John Corker Senior Associate. Oz NetLaw  National Internet legal practice of the Communications Law Centre.  Website at oznetlaw.net.
Do Not Call Register scheme Peter Sutton Manager Do Not Call Taskforce International Training Program 12 September 2006.
Introduction Spam in Society Spam IM Spam Text Spam Blog Spamming Spam Blogs.
Federal Trade Commission FTC & Spam. Federal Trade Commission CAN-SPAM Act of 2003 (“Controlling the Assault of Non-Solicited Pornography.
Durban, South Africa, 8 July 2013 Outcome of WTSA-12 on spam Xiaoya Yang, Head, WTSA Programmes Division ITU-TSB ITU Workshop on “Countering.
Topic 5: Basic Security.
Using for Marketing ISPA 8 September 2004 John Arnesen.
RECENT DEVELOPMENTS IN DIGITAL MEDIA ADVERTISING LAW : CANADIAN EDITION VALERIE WARNER DANIN, ESQ.
Spam. Is spam a problem? Bandwidth hogging -> slower, costlier Discourages use of net ( , e-commerce) Productivity -> loss of time and money Receiver.
Rules of Engagement Mark Dwyer. AGENDA 1.Spam and Consent 2.Privacy 3.Advice Warnings and Notices 4.Disclosures 5.Other Matters.
U.S. Businesses Targeted Randy Wolverton Brian J. Koechner.
Anti-spam activities in Korea Billy MH Cheon / Korea Network Information Center.
Serving the Public. Regulating the Profession. CANADA’S ANTI-SPAM LEGISLATION (CASL) Training for Chapters Based on Guidelines for Chapters First published.
Extra Credit Presentation: Allegra Earl CSCI 101 T 3:30.
Handling Spam In Government Administration – The Singapore Approach Presented to ICA Annual Conference 2004 Presented by Wu Choy Peng (Ms) 20 October 2004.
Information and Network security: Lithuania Tomas Lamanauskas Deputy Director Communications Regulatory Authority (RRT) Republic of Lithuania; ENISA Liaison.
[ Direct marketing – an introduction to data protection and privacy] For [insert name of organisation] presented by [insert name of presenter] on [date]
Created by the E-PoliceSlide 122 February, 2012 Dangers of s By Michael Kuc.
E-C OMMERCE : T HE E -C ONSUMER AND THE ATTACKS AGAINST THE PERSONAL DATA Nomikou Eirini Attorney at Law, Piraeus Bar Association Master Degree in Web.
Countering Spam in a Digital World
The Challenge of Spam Spam is a harmful, costly, and evolving threat to Internet users. A collaborative approach is needed to provide the best spam-mitigation.
ethical issues in business
Richard Hill Partner, Hill & Associates
EU Data Protection Legislation
Presentation transcript:

SPAM Turning the tide Gregory Massel iWeek 2004

The threat to the Information Society One of the greatest plagues affecting the digital world One of the greatest plagues affecting the digital world More prevalent then legitimate More prevalent then legitimate Causes significant financial costs and productivity losses for ISP’s, business and end-users Causes significant financial costs and productivity losses for ISP’s, business and end-users Undermines user confidence in and online activities Undermines user confidence in and online activities Can seriously hamper the development of the digital economy and society Can seriously hamper the development of the digital economy and society

State of the Problem Spam is increasing Spam is increasing July % of July % of July 2004 – 65% of July 2004 – 65% of Growing criminal element Growing criminal element >95% have falsified senders>95% have falsified senders 17% inappropriate for minors17% inappropriate for minors 9% scams (eg. 419)9% scams (eg. 419) 6% fraud (phishing)6% fraud (phishing) ~50% via hacks (open relay, open proxy, exploited pc’s)~50% via hacks (open relay, open proxy, exploited pc’s) Spreading beyond Spreading beyond SMS, IM (SPIM), IRC, VoIP, etc.SMS, IM (SPIM), IRC, VoIP, etc. GSM Association lists spam in top four threats to the future of the mobile phone industryGSM Association lists spam in top four threats to the future of the mobile phone industry Source:

Spam and Fraudsters " It is a well-known fact that no other section of the population avail themselves more readily and speedily of the latest triumphs of science than the criminal class.“ (Inspector John Bonfield, Chicago Police Department, 1888) Source:

Lessons to be learned Spammers are technologically adept Spammers are technologically adept As quickly as we develop anti-spam solutions, they improve their techniquesAs quickly as we develop anti-spam solutions, they improve their techniques Legislation alone does not stop spam Legislation alone does not stop spam Heavy penalties are a deterrenceHeavy penalties are a deterrence Empowers people to trace and take action against spammersEmpowers people to trace and take action against spammers International co-operation is required to to fight a threat that knows no borders International co-operation is required to to fight a threat that knows no borders

Turning the tide Legislate against spam (world-wide) Legislate against spam (world-wide) Colaborate globally to fight the threat Colaborate globally to fight the threat Through industry bodies (eg. ISPAs, ITU, IETF)Through industry bodies (eg. ISPAs, ITU, IETF) Through LEAs (eg. Interpol)Through LEAs (eg. Interpol) Develop technical solutions Develop technical solutions Preferrably IETF-endorsedPreferrably IETF-endorsed Must be widely implementedMust be widely implemented Educate end-users, marketers, businesses and ISPs about anti-spam measures and good Internet security practices Educate end-users, marketers, businesses and ISPs about anti-spam measures and good Internet security practices

Legislation - Overseas Most countries have introduced anti-spam legislation Most countries have introduced anti-spam legislation EU region governed by directive 2002/58/ECEU region governed by directive 2002/58/EC Governs all bulk communications (including , sms, fax, automated calling machines). Governs all bulk communications (including , sms, fax, automated calling machines). Explicit consent of recipient required PRIOR to contact Explicit consent of recipient required PRIOR to contact Exception: within the context of an existing customer relationship by the same company that obtained the customer’s details Exception: within the context of an existing customer relationship by the same company that obtained the customer’s details Prohibits the use of false identities or return addresses Prohibits the use of false identities or return addresses AustraliaAustralia Covers , sms/mms and IM but not fax Covers , sms/mms and IM but not fax Explicit consent of recipient required PRIOR to contact Explicit consent of recipient required PRIOR to contact Exception: within the context of an existing relationship Exception: within the context of an existing relationship Requires accurate identification of the sender Requires accurate identification of the sender Requires a functional unsubscribe facility Requires a functional unsubscribe facility Penalties up to $1.1 million per day for professional spammers Penalties up to $1.1 million per day for professional spammers Covers spam originated in Australia, or commission in Australia (but originated elsewhere), or sent to an address accessed in Australia Covers spam originated in Australia, or commission in Australia (but originated elsewhere), or sent to an address accessed in Australia Exemptions: Government, political parties, charities, religious organisations, educational institutions (sent to attending and former students) Exemptions: Government, political parties, charities, religious organisations, educational institutions (sent to attending and former students) USA governed by the CAN-SPAM ActUSA governed by the CAN-SPAM Act Implements an opt-out approach Implements an opt-out approach Prohibits the use of an invalid sender address Prohibits the use of an invalid sender address Prohibits bulk inappropriate for minors Prohibits bulk inappropriate for minors

Legislation – South Africa Bulk is legal provided you Bulk is legal provided you Provide an ‘unsubscribe’ facilityProvide an ‘unsubscribe’ facility Inform the recipient where you obtained their address (on their request)Inform the recipient where you obtained their address (on their request) Loopholes Loopholes No requirement for a valid sender addressNo requirement for a valid sender address Who does one contact to request where your address was obtained if there is no valid sender? Who does one contact to request where your address was obtained if there is no valid sender? It is almost impossible to prove that two mail shots came from the same sender, therefore difficult to prosecute on the basis of a dishonored unsubscription It is almost impossible to prove that two mail shots came from the same sender, therefore difficult to prosecute on the basis of a dishonored unsubscription Effectively legitimises spam Effectively legitimises spam Similar approach to the USA Similar approach to the USA USA is the biggest source of spam world-wide!USA is the biggest source of spam world-wide! Dire need for stricter legislation Dire need for stricter legislation

Collaboration & Education Global forums Global forums ITU / WSIS meetings on countering spamITU / WSIS meetings on countering spam AntiSpam-Forum 2004 (CABASE)AntiSpam-Forum 2004 (CABASE) South Africa South Africa ISPAISPA Anti-spam list Anti-spam list Technical committee Technical committee iWeek sessions iWeek sessions Participation in international forums Participation in international forums Spam SummitSpam Summit MFSA spam guidelinesMFSA spam guidelines Department of CommunicationsDepartment of Communications

Final thought "The spam wars are about rendering useless for unsolicited advertising before unsolicited advertising renders useless for communication." - Walter Dnes & Jeff Wynn (in news.admin.net-abuse. )

References & Links ITU activities on countering spam ITU activities on countering spam Euro Coalition Against Unsolicited Commerial Euro Coalition Against Unsolicited Commerial SpamLaws.Com SpamLaws.Com Australian Communication Authority - Information on SPAM Australian Communication Authority - Information on SPAM mhttp:// mhttp:// mhttp:// m Anti-Phising Working Group Anti-Phising Working Group AntiSpam-Forum 2004 (Spanish) AntiSpam-Forum 2004 (Spanish) SpamHaus SpamHaus