pro exchange spam filter an exchange 2000 based spam filtering solution

11
Pro Exchange Pro Exchange SPAM Filter SPAM Filter An Exchange 2000 based An Exchange 2000 based spam filtering solution spam filtering solution

Upload: clare-chandler

Post on 23-Dec-2015

222 views

Category:

Documents


0 download

TRANSCRIPT

  • Slide 1
  • Pro Exchange SPAM Filter An Exchange 2000 based spam filtering solution
  • Slide 2
  • How does SPAM effect you? In general: In general: Spam is increasing at a rate of 60% per year Spam is increasing at a rate of 60% per year Spam accounts for over 25% of all e-mail Spam accounts for over 25% of all e-mail Time Wasted Time Wasted End users deleting spam End users deleting spam IT staff dealing with users effected by spam IT staff dealing with users effected by spam Legal Issues Legal Issues Many spam messages contain business inappropriate content Many spam messages contain business inappropriate content Wasted Resources Wasted Resources Increased storage space Increased storage space Increased backup and restore times Increased backup and restore times
  • Slide 3
  • Three Type of Solutions Firewall\proxy based Firewall\proxy based Installed between the internet and incoming SMTP mail servers Installed between the internet and incoming SMTP mail servers Prevents spam from getting to mail servers Prevents spam from getting to mail servers Mail server based Mail server based Installed on each incoming SMTP mail server Installed on each incoming SMTP mail server Prevents spam from getting to users mailboxes This is where our SPAM solution operates Prevents spam from getting to users mailboxes This is where our SPAM solution operates Client based Client based Installed or configured on each client independently Installed or configured on each client independently Deletes or moves messages from a users Inbox Deletes or moves messages from a users Inbox
  • Slide 4
  • Features Six levels of spam filtering Six levels of spam filtering From least to most aggressive From least to most aggressive Optional support for: Optional support for: Blacklist server checking Blacklist server checking Dynamic blocking of future spam from newly detected hosts Dynamic blocking of future spam from newly detected hosts Detailed logging of all incoming smtp mail Detailed logging of all incoming smtp mail Web based administration of filters Web based administration of filters Web based reporting of all valid and blocked messages Web based reporting of all valid and blocked messages
  • Slide 5
  • Supported Filtering Levels Blocking verses Tagging messages Blocking verses Tagging messages Supports updating message subjects to indicate a message is possibly spam instead of blocking messages Supports updating message subjects to indicate a message is possibly spam instead of blocking messages Spam detection criteria: Spam detection criteria: Sending servers IP listed in the public Blacklist servers Sending servers IP listed in the public Blacklist servers Keywords in the message Keywords in the message Invalid format of message header Invalid format of message header Known spam hosts Known spam hosts By IP and DNS host names By IP and DNS host names Dynamic blocking of new hosts Dynamic blocking of new hosts
  • Slide 6
  • Supported Filtering Bypasses Sending server DNS host name Sending server DNS host name System messages System messages Locally sent messages Locally sent messages Planned (Not in beta) Planned (Not in beta) Target e-mail address Target e-mail address Group Membership Group Membership
  • Slide 7
  • Logging All valid and blocked messages are logged to a database All valid and blocked messages are logged to a database Local logs exist on each server containing details on all valid and blocked messages Local logs exist on each server containing details on all valid and blocked messages Separate local log files by type of spam Separate local log files by type of spam Blacklisted Blacklisted Keyword match Keyword match Known spam hosts Known spam hosts Single log file that contain all new spam host Single log file that contain all new spam host Log can be used to build a list of known spam hosts Log can be used to build a list of known spam hosts
  • Slide 8
  • Administration & Reporting Web based administration Web based administration Keywords Keywords Good and bad domains Good and bad domains Triggers that cause dynamic blocking of a host Triggers that cause dynamic blocking of a host Management of dynamically blocked hosts Management of dynamically blocked hosts Web based reporting Web based reporting Show all valid messages Show all valid messages Show all blocked messages Show all blocked messages Filter by blocked reason Filter by blocked reason Filter by message recipient Filter by message recipient Statistics of total, blocked, and valid messages Statistics of total, blocked, and valid messages
  • Slide 9
  • Web Based Administration Keyword and Domain Filters
  • Slide 10
  • Web Based Reporting
  • Slide 11
  • Additional Details Supports Access, SQL, or MSDE for data storage Supports Access, SQL, or MSDE for data storage All keywords can be managed via web interface All keywords can be managed via web interface Filter level and other settings are stored in the registry on Exchange server Filter level and other settings are stored in the registry on Exchange server Final version will have a web front end to these settings Final version will have a web front end to these settings Host creation script included to process new hosts log file Host creation script included to process new hosts log file Creates new host records (contact) in the AD to block future messages Creates new host records (contact) in the AD to block future messages Stores the reason why the contact was created, the message header that was flagged as spam, and additional information on the host that is blocked Stores the reason why the contact was created, the message header that was flagged as spam, and additional information on the host that is blocked Queries valid and good domain lists to prevent these hosts from being blocked Queries valid and good domain lists to prevent these hosts from being blocked