‘Dark traffic’ is a major problem, vendor study shows

Opinion
May 19, 20052 mins

* Tumbleweed’s study of e-mail traffic

Tumbleweed Communications recently undertook a significant study of a problem it calls “dark traffic” in e-mail systems. The study – which represented a combination of interviews with 104 IT professionals conducted by Osterman Research, as well as analysis of port 25 traffic at major enterprises – found that about 70% of inbound e-mail traffic to the enterprise consists of non-valid types of communications.

These messages, which typically are focused on things like denial-of-service attacks, dictionary harvest attacks (DHA) and e-mail to invalid recipients, are often not detected as unacceptable SMTP messages by firewalls and other messaging security systems, and so pass through these defenses easily. Consequently, e-mail servers end up as the last line of defense and must process these messages, resulting in delayed e-mail delivery, server failure, additional work for IT staff and other problems.

Tumbleweed’s study also found that during the year preceding the survey, more than 60% of organizations had experienced at least one denial-of-service attack with a large percentage experiencing multiple such attacks. Denial-of-service attacks had also disabled at least one e-mail security server in more than one-half of organizations. The response to denial-of-service attacks is generally ineffective; while about 70% of organizations blocked the IP addresses that launched the attacks, one in three organizations simply turned off incoming e-mail until the attack had subsided.

Similarly, Tumbleweed’s study discovered that more than two in five organizations had experienced DHAs during the 12 months preceding the survey and that for most organizations the DHA had caused a delay in e-mail delivery.

More ominous, however, is the fact that if an organization uses an employees’ e-mail addresses as the network logon ID, a hacker that guesses at a password – even with a limit of three tries per logon attempt – can be expected to gain access about 1% of the time. That means that in an organization of 3,000 users, a hacker has about 30 likely opportunities to gain access to the corporate network.

The ease with which this can be done was underscored by last week’s revelation that “Stakkato,” a kid in Sweden, had infiltrated U.S. government computers last year, albeit not through a DHA.

The bottom line of Tumbleweed’s study is that many enterprises are not doing enough to prevent malicious attacks on their most valuable communications resource: their e-mail systems.