Computerworld

IIA: Funding needed for ISPs to crack-down on unruly spammers

Government may be asked to open coffers to support industry code
Tags | spam | isp | Internet Industry Association (IIA)

The Federal Government may be asked to fund an upcoming code requiring Internet Service Providers (ISPs) to crack-down on spamming computers.

The Internet Industry Association (IIA) draft code proposes ISPs take action against customers whose computers are pumping out spam over their networks or may have been hijacked for use by online criminals.

IIA chief executive Peter Coroneos said the industry-backed voluntary code will be released for further public consultation by the end of March this year.

“We would consider a joint-funded initiative,” Coroneos said.

He added the move was not aimed at stopping the individual computers responsible for the highest rates of spam but instead looks to target the spread of botnets.

“Legislation is not the ideal approach. It is much better to have an industry code,” he said, adding the government said it would mandate ISP intervention if an industry code is not adopted.

The draft code, if it were adopted, would effectively formalise an existing code held by the Australian Communications and Media Authority (the ACMA) which requires ISPs to take action against customer computers that are sending out spam.

Coroneos said it would introduce consistency across intervention actions which may require providers to notify customers and provide remedial support via telephone, email and technical house-calls.

He said 68 ISPs have supported the code which was developed through input from telecommunications providers, the Privacy Commission, and industry experts. The first month of public consultation was held last September.

Internode network engineer Mark Newton said the draft code would likely be supported by ISPs.

“They were the ones who created it and it would seem they would not have designed a code that would inevitably send them broke,” Newton said.

Infected computer owners' details would likely be supplied to ISPs by GovCERT which is in part fed IP addresses of botnet computers by various darknets or greynets. It would then be up to the ISP to contact a customer about remediation.

The code proposes that customers who do not comply could have their Internet connections terminated.

Security vendor Sophos head of technology Paul Ducklin said some ISPs could not afford to contact and possibly disconnect customers.

“A customer might be paying $40 for a DSL connection and it could cost $20 in support calls and letters to notify a user,” Ducklin said.

“It’s not right for the government to demand ISPs foot the bill and not provide funding. Surely there would be some left over from the $43 billion [National Broadband Network].”

Ducklin said ISPs could likely afford to take action against the worst offenders, but could not be expected to pay the cost of removing the problem entirely. He cited the take-down of the McColo hosting service last year that removed 500,000 infected bots and produced an estimated 70 percent drop in global spam.

He poured cold water on reports that Australia holds the third largest amount of botnets, claiming that the nation has consistently ranked in 40th place and is responsible for 0.4 per cent of global spam.

More about: CERT, IIA, Internet Industry Association, Internode, Sophos
References show all

Comments

1

Brian Lorentzen

Mon 25/01/2010 - 16:26

The following is an extract from a new political party launching in Australia..
End of SPAM..
We will assist Email providers to develop a system that will only forward email to you from registered users..
No registered users will be allowed to send more that 50 emails a day without special registration.
The registration database will be similar to the Australian "No Phone Spam" system where you register your phone number in a national database. Registration will be free.. The first time your existing contacts try to email you, they will receive back a simple registration form that they have to click "OK" to. Large scale Spammers employ random "From" addresses that obviously cannot be registered. The 50 emails a day limit will prevent hijacked PCs from proliferating spam.
If you need to send more than the 50 emails a day, you will need to apply for an upgraded license.

2

Ben

Mon 25/01/2010 - 19:36

@Brian - nice troll mate

3

Matt

Tue 26/01/2010 - 11:54

How's it going to cost money? Exetel has been doing this for years with next to no cost. I don't think we need another government department telling us how to run our businesses. Coroneos, that is a stupid idea.

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Community Comments
Whitepapers
All whitepapers
 
Featured Whitepapers
Enhancing Worker Productivity in a Business 2.0 World

New generations of IT-savvy, always-connected workers are entering the workforce with the expectation that their IT tools at work should be at least as powerful and adaptable as their IT tools at home. Learn to optimise IT for productivity - read on.

Zones
SAS Resource Centre

This Resource Centre hosts a wealth of thought leadership articles, whitepapers, and success videos, to help you make the most out of your corporate information in order to swiftly make sound business decisions to survive and thrive in the current economic climate.

Oracle Resource Centre

News, Features and the latest whitepapers on SOA, Application Grid, Enterprise Management and Database

Computerworld newsletter
Join the most dedicated community for IT managers, leaders and professionals in Australia
Sponsored Links
 
Copyright 2010 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.