PDA

View Full Version : Spam blocking



yogi_hm
June 10, 2003, 01:50 PM
I stumbled across the following article and while reading I started to wonder how good are spam filters and which ones are really good? And another thing came up, can microsoft really do anything good?


April 15, 2003
Microsoft Focuses on Antispam for Exchange 2003
By Thor Olavsrud

With spam on track to become one of the biggest drains on companies' network resources, Microsoft Monday
used the RSA Conference in San Francisco as a platform to introduce a new antispam tool for Exchange Server 2003.

The tool opens up Exchange Server to allow partners to integrate their own antispam modules with the server, and Microsoft said that integration will drive better content filtering with fewer false positives. In addition, Microsoft unveiled an updated version of its virus-scanning application protocol interface (VSAPI 2.5), which also allows partners to integrate their complementary offerings with the product.

"We know customers' pain," said Kevin McCuistion, director of Exchange marketing and business development at Microsoft. "Security and privacy are more important than ever right now and, as an industry leader, we know Exchange and its industry partners have to offer an end-to-end solution to customers that will help fend off security threats at the gateway, on the mailbox server and at an end user's mailbox. Microsoft's philosophy is to stop viruses and spam at the network perimeter, keeping end users focused on the task at hand."

Research firm Gartner, in its November 2002 report "E-Mail in 2003: The Risk Level Rises," said spam is increasing at a rate of 1,000 percent per year, and is on track to become more than 50 percent of e-mail message traffic by 2004. The report "Anti-Spam for Businesses and ISPs: Market Size 2003-2008," by Ferris Research, found that spam will cost U.S. businesses more than $10 billion in 2003.

Even leading anti-virus software vendors like Network Associates, Symantec and Trend Micro are recognizing the trend and adding antispam products to their lineups. All three are working on antispam products that integrate with Exchange Server 2003, and Network Associates used Microsoft's Exchange 2003 announcement Monday as an opportunity to unveil its own McAfee SpamKiller line.

"Spam clogs users' inboxes and e-mail storage devices, and creates significant security and liability concerns for the enterprise," said Eric Hemmendinger, research director for security and privacy at Aberdeen Group. "IT buyers should evaluate antispam solutions in terms of fit with the existing infrastructure, detection rates, and false positives rates. Ignoring one or more of these factors may well lead to a choice that is hard to use, and does not solve the problem for the customer."

To answer the spam threat, which promises to become a drain on network resources and productivity, Microsoft's new antispam tool for Exchange Server 2003 allows partner offerings to scan incoming e-mail messages and then attach each one with a numeric score dubbed a Spam Confidence Level (SCL). The SCL denotes the probability that a particular message is spam, and network administrators will be able to set a threshold SCL which will determine whether a message is forwarded to a recipient's inbox or junk mail folder.

A number of partners have already signed on to integrate their offerings, including: Brightmail, GFI Software, Network Associates, Sybari Software, Symantec and Trend Micro.

"Spam has become the No. 1 pain point for our enterprise messaging customers due to its negative impact on messaging infrastructure as well as end-user productivity," said Chris Miller, group product manager at Symantec. "Microsoft's antispam innovations in Exchange 2003, such as the Spam Confidence Level, will make it easier for vendors like Symantec and customers to address this challenging and complex problem."

In addition to the new antispam tool, Exchange 2003 has been architected to work directly with the junk mail filters in the forthcoming Microsoft Office Outlook 2003 application. Microsoft said the filters will allow users to block HTML content by default, assign "safe" and "block" lists, automatically file junk mail to the trash, and profile spam by assigning points or scores to identifiers such as keywords or patterns. Additionally, the company said users will be able to save Outlook 2003 and Outlook Web Access "safe" and "block" senders lists on the Exchange server, allowing the preferences to work for mobile users on any desktop or device connected to the network.

Finally, for the network administrator, Exchange 2003 allows the assignation of enterprise-wide allow/deny lists and the integration of real-time black hole list (RBL) services.

On the viruses front, VSAPI 2.5 will allow partners' antivirus offerings to scan e-mail messages at the entry point of customer networks, before it even reaches the Exchange mailbox server. In addition, with VSAPI 2.5, Microsoft said it is possible to prevent infected e-mail from leaving an organization by scanning outgoing mail. The API will give antivirus products more options when it comes to deleting infected messages, and the ability to automatically send a warning message back to the sender that a virus was detected and the mail deleted.

GFI, Network Associates, Panda Software, Symantec and Trend Micro are already designing their products to take advantage of the capabilities of VSAPI 2.5.

This story originally appeared on internetnews.com.

Chris
June 15, 2003, 08:58 PM
If you want to fight spam, don't reply to them ;). Also, don't go around the Net leaving your e-mail address everywhere. Another suggestion for those who own or admin websites - be careful where you leave your e-mail address on your site.

wheelman
June 15, 2003, 10:56 PM
Disguise e-mail addresses posted in public electronic places (chat rooms, forums that kinda stuff)

Read carefully when filling out online forms requesting your e-mail address, if its optional dont enter it.

Use multiple e-mail addresses.

Use a filter.

Short e-mail addresses are easy to guess, and may receive more spam.

Try not to subscribe to any ,magazine articles as they may sell your email address to spammers.

deakie
June 16, 2003, 07:01 AM
liste, the bets way is to create a spam email addy.
the one you can leave everywhere and then just go there for the info you expect and then delete the entire inbox.
i have one on lycos just for that. :D
my mailboxes on my dsl account is configurable by me. if they begin to look messed, i delete them and use something else. 8)

sandor
June 16, 2003, 07:06 AM
yeah, i use my cwjamaica account as my 'spam account' .. sign up for every god thing using it. but from way back in 1999 i'd left my main email addy on my site and it was harvested and sold and res-sold numerous times since then i figure. what to do ... way of life now for me to come up with new filters ::)

Arch_Angel
June 16, 2003, 11:21 AM
That's one of the reasons I didn't post my msn messenger email address on here, in my profile. The hotmail email address is shown in the url. That's baaad. :(

yogi_hm
June 16, 2003, 02:36 PM
another thing which I find sorta useful is not allowing bounce backs on your mail server, spammers will send an e-mail and spoof the from address in order to generate a bounce back to the from address .

Nastrodamus
June 16, 2003, 06:10 PM
Indeed Yogi-san,

Some spammers send annonymous mail to address the are in the public address book or randomly created address. At the end of this email they put the "Click here to unsubscribe" or "Click here if you where sent this mail in error". The second that you click that link will be hell for you, for you will be informing such spammers that your email is Live. So go even further to ask you for your email address that they can "remove" you from their "database". HA!!! RIGHT

Best reponse, check, delete and block the addresses. (Blocking all of them is important. It returns the all the junk the sender. If you block only some they will know that the email is Live and you are just trying to block them. If you keep on blocking them they will think that you have not checked your email in awhile and your email server has temporarily closed your account.

You will have to do this for a while, but they will stop as the company that are paying them to spam won't pay for dead addresses.

yogi_hm
June 16, 2003, 11:47 PM
I have seen where a guys e-mail account got filled with over 1800 bounced back e-mail which he didn't send, but they had his e-mail address as the from address. I'm telling you putting up your e-mail address on your website is a dangerous thing.

Chris
June 17, 2003, 09:36 PM
.... I'm telling you putting up your e-mail address on your website is a dangerous thing.

Tell me about it. Everyday I receive e-mail offers to get rich by giving some Nigerian my bank account info so that they can pass money thru it and leave behind a tidy commission. Yeah right. If I ever gave them one of my account info they'd realise that they're wasting their e-mail on me ;D.

Nastrodamus
June 18, 2003, 11:17 AM
Chris,

Let us in on your newly found African wealth nuh?

I had turned them down ;D

Chris
June 18, 2003, 11:32 AM
Chris,

Let us in on your newly found African wealth nuh?

I had turned them down ;D


Sure Nastro, you know that I'm always willing to share. Post your account info here and I'll be sure to recommend you to them ;D ;D

yogi_hm
June 20, 2003, 11:19 AM
Hey I wonder how genuine are those e-mails saying to forwarding them because they are in aid of some health found of some sort.