You are here: silicon.com > Software > Security Strategy

Security Strategy

"Lighthouse Afghan" fools Outlook spam filter

Spammers using hidden words to slip through Bayesian filter…

By Munir Kotadia

Published: 5 April 2004 09:40 GMT

Spammers are inserting hidden words into their email messages to fool Microsoft Outlook's built-in anti-spam technology.

As spam-filtering technologies become more common, spammers have altered the construction of their messages to avoid detection. Although spam is very simple for a human to spot, the artificial intelligence systems used by junk filters rely on spotting obvious keywords, applying statistical theories to messages, and using rule-based systems to try and differentiate between wanted and unwanted emails.

The latest version of Microsoft Outlook is armed with a Bayesian filter, which tries to recognise spam by looking at the words used in an email and, depending on the frequency of certain key words, calculating the probability of that email being spam.

John Cheney, CEO of email security firm BlackSpider Technologies, said to get past the Bayesian methods, spammers have started hiding words that are not usually associated with spam at the bottom their emails: "At the bottom of the message they have included a whole load of keywords that are used to fool the Bayesian filters - they are in a tiny font and in the same colour as the background," he said.

"These messages are designed to fool the Outlook 2003 filters because there are a lot of words in there that don't look spam-like and they would weight the email as a normal email rather than a spam email," he said.

Another trick used by spammers to bypass junk-email filters is to write their messages using accented characters in their messages to makes obvious spam keywords, such as Viagra, look like a legitimate word written in a foreign language.

Some of the most recent examples of anti-junk-mail combine accented characters to make messages written in English look like they are written in a foreign language. Because the majority of Spam originates in the US, most spam is written in English, so many email filters ignore non-English spam. For example, if a spam keyword was "enhancer" and the spam included the word "čnháncer", the message would be allowed to pass.

Alun Davies, European VP of marketing at internet software firm Rockliffe, said his company's products will soon be updated to filter out this relatively recent development: "A large percentage of our MailSite email server customers do not use English as their main language, so for some time we have been aware of the need for spam filtering technology that can recognise accented characters and non Latin characters," he said.

Blackspider's Cheney said that yet another relatively successful spamming technique hides the spammers message by inserting HTML code between the words. Because most mail clients automatically render HTML messages, users don't see the tags, just the message: "HTML tags are typically used to make words bold or red or something like that, but these are general tags that don't actually affect the appearance of the message but they do confuse the lexical analysers," he said.

Munir Kotadia writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
IT Trainer (Bilingual - French & English) - LONDON

You will have materials & information provided for you, you will then be expected to create the training with some creative flair * You will be ...

Web Developer

Comfortable working with FTP technology • Vast MS Office skills including Outlook, Access, Word, Excel, PowerPoint. Internet-related technology ...

Marketing Web Developer

Outlook, Access, Word, Excel, Powerpoint * An aptitude and passion for Internet-related technology * Good command of English and strong written and ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: