Feature checklist
Nearly all AV engines use a combination of signatures that are constantly updated by the vendor, along with heuristics that attempt to identify dangerous attachments that aren't caught by the signatures database. Anti-spam techniques include sender reputation, based on the vendor's database of IP addresses known to be sending spam; certain TCP/IP tricks such as requesting a resend of the message (legitimate mail servers will resend, while most spam engines don't); heuristics of many different varieties; and a host of other specialized techniques, including such oddities as employing optical character recognition to identify image-based spam that doesn't use conventional text in the message. Filtering and spamming techniques evolve through a constant battle between the anti-spam vendors and spammers, who are desperately trying to slip their ads past the filters. Because the spammers are commercially motivated to bypass new heuristic techniques quickly, many vendors are relying more on reputation-based filtering.
While anti-virus and anti-spam are the essence of mail security, there are a number of other features you should expect to find in all e-mail security appliances. These include:
- Policies that can be set per user, per group, or per site to control when users can send and receive mail, to whom, whether whitelists or blacklists can be modified by users or admins, which types of attachments are allowed on incoming and outgoing mail, and so on.
- Support for multiple domains or back-end mail servers.
- "Outbreak" anti-virus, which is designed to snare viruses for which signatures don't yet exist. Outbreak AV filters typically stop messages that have the characteristics of a virus, such as an executable attachment or a suspicious origin, then review them over the next 24 or 48 hours to see if a signature appears; if not, they notify the user or admin to inspect the message and release or delete it.
- Secure content management features that examine outbound messages for specific phrases, types of files, or specific file names, and log or quarantine them for review.
- LDAP/Active Directory synchronization.
- DoS protection, which blocks repeated attempts to ping, send connection request, send directory request, send user verification, or basically any type of request for a response from the server that exceeds a certain frequency threshold, such as more than 100 pings per minute from a particular IP address.
- Directory harvest protection, which is designed to thwart attempts to send messages to all possible addresses on a mail server. By discovering which addresses are not rejected, so-called directory harvest attacks attempt to build a database of valid addresses. To combat this, when the appliance sees a large number of messages going to invalid addresses, it either throttles the connection (limiting the sender to one message per minute, for example) or blocks that IP address entirely.
- Address verification, to block e-mails sent to nonexistent users, and the ability to use reverse DNS to verify that a sender's IP address matches the sender domain. The use of reverse DNS thwarts phishing attacks by preventing forged e-mail from getting through.
Computerworld Buyer's Guide - Vendors Matched to this ArticleUnixpac , Citrix , HAL Data Services , Dimension Data , Trend Micro , Hewlett-Packard , SafeNet , Revelation Software , GFI , SonicWALL , nCircle , Sagem , NetIQ , Secure Computing , Red Hat , MessageLabs , CA , 3ComMore about PGP, Symantec, Secure Computing, Tumbleweed Communications, Proofpoint, IronPort, Red Hat, BorderWare, Citibank, Microsoft, Mirapoint, Evolve, Barracuda Networks, ACT, V7, PLUS, Cisco Systems, Cisco, Gateway, Linux
- +
Blog: Strategies for Accelerating Mobile Workers 15/01/2008 12:52:36
With enterprises rapidly expanding across the country or across the globe, mobility strategies have moved to front and center for most businesses. In fact, a recent Forrester Research "Trends" survey notes that 80% of enterprises plan to set a mobile and wireless strategy policy this year.* - +
Forget Everything You've Learnt About Project Delivery! 29/01/2008 11:25:16
Our current project delivery paradigms are flawed. And so are our approaches to solving this problem. The first in a new 10-part series from project management expert Jed SimmsOur current project delivery paradigms are flawed — and so are our approaches to solving this problem. The first in a new 10-part series from project management expert Jed Simms
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Security Inside Out
Achieving the impossible: Unlimited application scalability
Email Archiving Implementation: Five Costly Mistakes to Avoid
Everything you need to know about email and web security (but were afraid to ask)
Wireless LANs: Is my enterprise at risk?
Discover the advantages of an open architecture multi-vendor network solution
Know thy self: Reduce costs, secure data and ensure compliance with identity management
Solve Exchange Mailbox Storage Issues Once and for All
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Vignette Announces 2008 Excellence Awards 2008-11-21 10:50:00+11
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 2008-11-20 17:34:00+11
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 2008-11-20 12:06:00+11
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 2008-11-20 12:04:00+11
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 2008-11-20 12:02:00+11
Dude! You Say I Need an Application-Layer Firewall?!
Proxy firewall technologies have proven time and again to be more secure than “stateful” firewalls. They will also prove to be more secure than “deep inspection” firewalls. High-performance proxy firewalls are available today which are easily capable of handling gigabit-level traffic. Discover more by reading on.









