Академический Документы
Профессиональный Документы
Культура Документы
Commtouch Approach
www.commtouch.com
Zombie Web Threats
Phishing – Hosting spoofed web sites
to acquire sensitive information
DDoS – Enormous financial losses by
paralyzing critical online systems
Click Fraud - 15.8% of all advertising
clicks are fraudulent(Click Forensics Q2-07)
www.commtouch.com 4
Anatomy of a Zombie
Number of active zombies per day 5-10 million
Typical number of zombies per
10,000-200,000
single botnet
New zombies that come ‘alive’ every
200,000-500,000
24 hours
www.commtouch.com 5
Newly Active Bots per day
377,000 zombies/Bots are activated each day, on average
www.commtouch.com 7
Source: Commtouch Online Lab, http://www.commtouch.com/Site/Resources/ZombieMonitor.asp
Active Zombies: Activity Level Breakdown
www.commtouch.com 8
Source: Commtouch Online Lab, http://www.commtouch.com/Site/Resources/ZombieMonitor.asp
Using “In-the-cloud” Pattern Detection
to Identify Threats
Recurrent Pattern Detection™ (RPD)
Patent #6-330-590
2. Pattern Analysis:
• Email structure patterns –
identify that a message is
being sent in high volume
(plus speed of distribution)
• Distribution patterns –
detecting source(s) of
distribution for threat
classification
www.commtouch.com 11
“In the Cloud” Pattern Detection
www.commtouch.com
Comprehensive Traffic Coverage
Traffic Source Traffic Types
Backbone service Consumer, SMB, enterprise
providers
Desktop SW vendors Consumer
MSPs SMB
60.1.5.10 70.1.5.10
123.1.88.11 123.1.88.10
10.1.1.10
10.1.1.10 64.9.88.100
64.9.88.100 42.12.12.220
42.12.12.220
8.12.100.51
8.12.100.51 77.100.1.1
77.100.1.1 8.12.100.51
8.12.100.51
70.1.5.10
70.1.5.10 77.100.1.2
77.100.1.2 8.12.100.51
8.12.100.51
60.1.5.10
60.1.5.10 10.1.1.10 87.12.9.66
10.1.1.10 87.12.9.66
123.1.88.10
123.1.88.10 35.2.2.150
35.2.2.150 87.2.5.114
87.2.5.114
123.1.88.11
123.1.88.11 88.21.0.14
88.21.0.14 8.12.100.51
8.12.100.51
www.commtouch.com 15
Crossing Phishing and Zombie Sources
Risk Level
IPs
www.commtouch.com
Zombies & Commtouch Offerings
Zombie Data
Detection Center
www.commtouch.com
About Commtouch (NASDAQ: CTCH)
Messaging vendor since 1991
Developing outbreak detection technology since
1998
“In-the-cloud” computing pioneers (since 1996)
More than 50,000,000 mailboxes protected by
Commtouch via appliances, gateways, managed
services, desktop applications
About 100 OEM Partners, including Check Point,
Openwave, Tumbleweed, Watchguard, Sendmail,
F-Secure, Proofpoint…
Profitable company, positive cash flow, double
digit growth
www.commtouch.com 18
Partners Are Our Business
Email Security Network Security Anti-Virus Managed Services
www.commtouch.com
Thank You
Amir Lev
amir.lev@commtouch.com