ETH Zürich - Mail Filtering Service



Similar documents
Exim4U. Server Solution For Unix And Linux Systems

Objective This howto demonstrates and explains the different mechanisms for fending off unwanted spam .

Guardian Digital Secure Mail Suite Quick Start Guide

Government of Canada Managed Security Service (GCMSS) Annex A-5: Statement of Work - Antispam

AntiSpam QuickStart Guide

Frequently Asked Questions for New Electric Mail Administrators 1 Domain Setup/Administration

How To Configure Forefront Threat Management Gateway (Forefront) For An Server

Advanced Settings. Help Documentation

Configuring Your Gateman Server

MDaemon configuration recommendations for dealing with spam related issues

eprism Security Appliance 6.0 Intercept Anti-Spam Quick Start Guide

Analysis of Spam Filter Methods on SMTP Servers Category: Trends in Anti-Spam Development

How to Use Red Condor Spam Filtering

Hosted CanIt. Roaring Penguin Software Inc. 26 April 2011

Core Protection Suite

one million mails a day: open source software to deal with it Charly Kühnast Municipal Datacenter for the Lower Rhine Area Moers, Germany

Microsoft Exchange 2003

CipherMail Gateway Quick Setup Guide

Security. Help Documentation

Enhanced Spam Defence

security

What is a Mail Gateway?... 1 Mail Gateway Setup Peering... 3 Domain Forwarding... 4 External Address Verification... 4

Avira Managed Security AMES FAQ.

Content Scanning with Exim 4

A D M I N I S T R A T O R V 1. 0

English Translation of SecurityGateway for Exchange/SMTP Servers

ASAV Configuration Advanced Spam Filtering

Configuration Network Management Card-2

SPAMfighter SMTP Anti Spam Server

Configuration Information

How To Set Up Comendo.Comendo.Org For A Spammer To Send To Your Domain Name From Your Domain From Yourdomain.Com Or Yourdomain From Yourmail.Com To Yourdomain (For A Domain Name)

Chapter 6: ScanMail emanager

When Reputation is Not Enough: Barracuda Spam & Virus Firewall Predictive Sender Profiling

SpamPanel Level Manual Version 1 Last update: March 21, 2014 SpamPanel

SPAM FILTER Service Data Sheet

Solutions IT Ltd Virus and Antispam filtering solutions

Serial Deployment Quick Start Guide

ESET Mail Security 4. User Guide. for Microsoft Exchange Server. Microsoft Windows 2000 / 2003 / 2008

Migration Project Plan for Cisco Cloud Security

Trend Micro Hosted Security Stop Spam. Save Time.

Configuring Security for SMTP Traffic

Mail system components. Electronic Mail MRA MUA MSA MAA. David Byers

Do you need to... Do you need to...

MailFoundry User Manual. Page 1 of 86. Revision: MF Copyright 2007, Solinus Inc. All Rights Reserved. Page 1 of 86

Avira Managed Security (AMES) User Guide

GRAYWALL. Introduction. Installing Graywall. Graylist Mercury/32 daemon Version 1.0.0

Eiteasy s Enterprise Filter

XGENPLUS SECURITY FEATURES...

D3 TECHNOLOGIES SPAM FILTER

Securepoint Security Systems

Migration Manual (For Outlook Express 6)


Fighting Spam with open source software

MailFoundry Users Manual. MailFoundry User Manual Revision: MF Copyright 2005, Solinus Inc. All Rights Reserved

ADMINISTRATORS GUIDE v6.00 Page 1

Anti Spam Best Practices

Fighting Spam: Tools, Tips, and Techniques

Barracuda Security Service User Guide

Mail Service Reference

ORF ENTERPRISE EDITION 1. Getting the Most Out of ORF

From SPAMfighter SMTP Anti Spam Server to SPAMfighter Mail Gateway

Services Deployment. Administrator Guide

When Reputation is Not Enough: Barracuda Spam Firewall Predictive Sender Profiling. White Paper

FortiMail Filtering Course 221-v2.0. Course Overview. Course Objectives

Spam filtering. Peter Likarish Based on slides by EJ Jung 11/03/10

FILTERING FAQ

The Open Source Stack: One approach to spam filtering

Migration Manual (For Outlook 2010)

Barracuda Spam Firewall

Implementing MDaemon as an Security Gateway to Exchange Server

Symantec Hosted Mail Security Getting Started Guide

Administrator Manual v3.0

ADMINISTRATORS GUIDE v6.02 Page 1

FortiMail Filtering Course 221-v2.2 Course Overview

eprism Security Appliance 6.0 Release Notes What's New in 6.0

About this documentation

Collateral Damage. Consequences of Spam and Virus Filtering for the System. Peter Eisentraut 22C3. credativ GmbH.

How To Protect Your From Spam On A Barracuda Spam And Virus Firewall

Panda Cloud Protection

IMail Server. Twenty Ways to Stop Spam with IMail Server. Abstract

Technical Note. FORTIMAIL Configuration For Enterprise Deployment. Rev 2.1

anomaly, thus reported to our central servers.

Barracuda Spam Firewall User s Guide

Articles Fighting SPAM in Lotus Domino

Comprehensive Anti-Spam Service

IT Services page 1 of 10 Spam Filtering. Overview

Setting up Microsoft Outlook to reject unsolicited (UCE or Spam )

Quarantined Messages 5 What are quarantined messages? 5 What username and password do I use to access my quarantined messages? 5

Icebox - Sendio SPAM Filter

The Network Box Anti-Spam Solution

Transcription:

Eidgenössische Technische Hochschule Zürich Swiss Federal Institute of Technology Zurich Informatikdienste / IT-Services ETH Zürich - Mail Filtering Service (TERENA 2009) 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch)

Mail-Filtering Policy tagged message STOP exim clean message Accept or reject messages; do not accept & then silently delete them Provide users with a tag-only option for spam Allow personal black-listing & white-listing of sender addresses and domains Allow use of wildcards in black-listed / white-listed sender domains (*.ru) Reject spam messages, unless sender is white-listed or recipient is tag-only Reject malware & phishing messages without regard to user preferences 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 2

Mail Filtering Environment 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 3

Mail-Filtering Environment (1) DNS MX records direct a domain s mail to the filter nodes example: biol.ethz.ch mx 5 phil1.ethz.ch biol.ethz.ch mx 5 phil2.ethz.ch biol.ethz.ch mx 5 phil3.ethz.ch inbound filter nodes Filtering policy: reject spam & malware messages at SMTP-time User options: personal white-lists personal black-lists tag-only (accept spam & tag it) dept. servers departmental mail servers central mail server Exchange Server independent mail servers 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 4

Mail-Filtering Environment (2) filtering provided for 20,000 users we process 1.5 to 3.5 million messages per day 3 filtering nodes & 1 back-up receiver phil1 100 incoming SMTP sessions per node. phil2 phil3 SMTP-time message filtering: filtering is done while the SMTP connection is still open filtering requires several seconds unwanted messages are rejected during the SMTP session, or accepted & tagged 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 5

Open-Source Filtering Components EXIM mail gateway software ClamAV virus/phishing detection network + 3 rd -party signatures SpamAssassin spam content-filtering software + SARE & local rule-sets DCC mass-mailing detection network (called from SpamAssassin) Razor spam detection network (called from SpamAssassin) 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 6

Mail-Filtering Components DNS eth subnets ip white list scan domains server max evil ip list ip black list botnet host spam helo user black/ white lists tag only exim defer switch helo checks clamav virus sigs phishing sigs spam sigs Spam Assassin header body DCC Razor rule sets remote DCC remote Razor ETH mail servers 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 7

An SMTP Session (1) If connection comes from one of our hosts, then exempt it from spam checks If sender IP-address cannot be resolved to a host name, then mark it for rcpt-phase rejection TCP/IP Connection from 131.111.8.59 If sender IP is found in a local blacklist, then reject it now or mark it for rcpt-phase rejection If sender IP is found in a DNS IP blacklist or has a dynamic IP-address, then mark it for rcpt-phase tag/reject 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 8

An SMTP Session (2) If the HELO name does not have correct syntax or the sender said something stupid like HELO device.local, then mark it for rcpt-phase tag/reject If the sender said, HELO [IP-address] & the HELO IP differs from the connecting IP, or the HELO IP matches my IP-address, then mark it for rcpt-phase tag/reject TCP/IP Connection from 131.111.8.59 EHLO spamcentral.net If sender host has been identified as a member of a botnet, then reject it now or mark it for rcpt-phase rejection If the HELO name does not have corresponding DNS records, or if the HELO name matches one of my MX records, or if the HELO name matches my hostname, if the HELO name matches a spammer HELO, then mark it for rcpt-phase tag/reject 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 9

An SMTP Session (3) If the sender domain does not exist, then reject the connection now TCP/IP Connection EHLO MAIL FROM: from 131.111.8.59 spamcentral.net spammer@spam.net SIZE=381 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 10

An SMTP Session (4) If the recipient address does not exist, then reject the recipient address If the MAIL FROM SIZE parameter indicates that the message is too big for the recipient s mail server, then reject the recipient address If the recipient has blacklisted this sender then reject the recipient address TCP/IP Connection EHLO MAIL FROM: RCPT TO: from 131.111.8.59 spamcentral.net spammer@spam.net tom@ethz.ch SIZE=381 If the recipient has white-listed this sender, or has selected the tag-only option, then skip the spam checks If the recipient uses default spam-handling then reject the recipient address, if the message has been marked If this is a multi-recipient message, & the current recipient s spam preference differs from that of the 1st recipient, then temporarily reject this recipient address 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 11

An SMTP Session (5) If the message is bigger than 30 MB, then reject the message If the message content matches a ClamAV malware signature, then reject the message If the message content matches a ClamAV spam signature, then tag or reject the message TCP/IP Connection EHLO MAIL FROM: RCPT TO: DATA from 131.111.8.59 spamcentral.net spammer@spam.net SIZE=381 tom@ethz.ch Subject: A Hot deal! From: admin@ethz.ch Date: 08/30/2007 16:00 To: santaclaus@northpole.net Received: from mail1.pole.net [83.4.6.232] The PRGN stock price is about to soar! Buy it now to get in on the HOT DEAL!. If SpamAssassin thinks that the message is spam, then tag or reject the message 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 12

An SMTP Session (6) Accept & deliver tagged, clean & white-listed messages TCP/IP Connection EHLO MAIL FROM: RCPT TO: DATA QUIT from 131.111.8.59 spamcentral.net spammer@spam.net SIZE=381 tom@ethz.ch Subject: A Hot deal! From: admin@ethz.ch Date: 08/30/2007 16:00 To: santaclaus@northpole.net Received: from mail1.pole.net [83.4.6.232] accept & deliver The PRGN stock price is about to soar! Buy it now to get in on the HOT DEAL!. 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 13

End 09 Dec 2009 - D. McLaughlin (davidmcl@ethz.ch) 14