Published

M3AAWG Report

:2014
M3AAWG Bot Metrics Report — Report #1 — 2012 and 2013
Version 1
Updated September 2014
Report

Messaging, Malware and Mobile Anti-Abuse Working Group

M3AAWG Bot Metrics Report — Report #1 — 2012 and 2013

1

September 2014


M3AAWG Bot Metrics Report — Report #1 — 2012 and 2013

1.  Executive Summary

This is the first industry report with data provided directly by service operators and ISPs detailing the number of subscribers identified as having a system infected by malware, also known a “bot,” and the percentage of those subscribers notified of the problem. It is the first cooperative effort by network service providers to quantify the extent of malicious bots infecting their subscribers. The Messaging, Malware and Mobile Anti-Abuse Working Group will periodically issue updated reports.

Based on the data provided to M3AAWG, in 2012 participating network operators reported the number of infected subscribers ranged from .84 % to 1.18 % with 99.13 % to 99.21 % of those subscribers being notified they had a bot. In 2013, the number of infected subscribers varied from 1.04 % to .80 % with 99.82 % to 93.99 % of consumers being notified.

2.  About the M3AAWG Bot Metrics Program

These metrics are the first cooperative effort by the network companies that directly provide end-users Internet access, and thus see the data first hand, to quantify the extent of malicious bots afflicting their subscribers. The metrics cover only end-user connections and do not include enterprise business networks.

This is a voluntary program with data provided confidentially by ISPs and service providers. The data is shared at the discretion of each company and is reported here as aggregated monthly metrics summarized by quarters. While the report represents the contributions of ISPs and network operators working within M3AAWG to address malware and bots, M3AAWG members are under no obligation to supply this information or to participate in this program.

The M3AAWG Bot Metrics Program is an objective tool for tracking industry and government efforts at controlling the spread of bots and we are committed to continuing this important work. Similar to the M3AAWG Email Metrics Report on abusive messaging, we expect these reports will become an important resource for understanding the extent of bot infections and to measuring the effectiveness of the industry’s efforts to protect end-users.

3.  Observations

While definitions of bots can differ from country to country, the metrics below report on malware, or malicious code, discovered by a network operator while processing a subscriber’s email or other Internet activities. Bots are installed directly on end-users’ systems, often without their knowledge. Once deployed, the “botted” machine can be controlled by commands from a “bot master,” a person who uses infected machines as a network to send spam or carry out fraudulent activities. The malicious code is often designed to run in background mode, so subscribers are usually unaware their systems are infected.

While Internet service providers and network operators are able to identify infected users on their networks, subscribers must remove the malware from their systems. Based on the data in this report, network operators are notifying about 98.7 % of end-users when they are infected. This points out the importance of the entire Internet ecosystem working together to address this problem, including security software vendors and end users.

4.  Report #1 — 2012 and 2013 Results Summarized by Quarter

The statistics reported below are compiled from confidential monthly data provided by participating M3AAWG member ISPs and network operators summarized here by quarter from 2012 through 2013. Our reporting basis covers a quarterly average of up to 43.5 million subscribers.

2012Q1 2012Q2 2012Q3 2012Q4 2012
Subscribers Represented37,707,43537,358,20636,991,51637,383,662
Subscribers Deemed Infected317,064402,585249,492440,746
% Infected0.84 %1.08 %0.67 %1.18 %
Infected Subscribers Notified314,295400,439245,522437,253
% Notified99.13 %99.47 %98.41 %99.21 %
2013Q1 2013Q2 2013Q3 2013Q4 2013
Subscribers Represented37,270,26537,735,19537,639,02243,550,674
Subscribers Deemed Infected388,152435,921493,572346,615
% Infected1.04 %1.16 %1.31 %0.80 %
Infected Subscribers Notified387,221435,149492,382325,787
% Notified99.76 %99.82 %99.76 %93.99 %

5.  What is Measured?

As with all M3AAWG documents that we publish, please check the M3AAWG website (www.m3aawg.org) for updates to this paper.

© 2014 copyright by the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)