Spamfilter Relay Mailserver



Similar documents
Anti Spam Best Practices

Ficha técnica de curso Código: IFCAD241

Exim4U. Server Solution For Unix And Linux Systems

Filtering with Open Source Software. OLUG June 7, 2005

Spam blocking methods and experiences

Configuring Your Gateman Server

BitDefender Client Security Workstation Security and Management

"Charting the Course... Enterprise Linux Networking Services Course Summary

ENTERPRISE LINUX NETWORKING SERVICES

AXIGEN Mail Server. Quick Installation and Configuration Guide. Product version: 6.1 Document version: 1.0

About this documentation

Analysis of Spam Filter Methods on SMTP Servers Category: Trends in Anti-Spam Development

Do you need to... Do you need to...

GL275 - ENTERPRISE LINUX NETWORKING SERVICES

Fighting Spam with open source software

Information Security Measures and Monitoring System at BARC. - R.S.Mundada Computer Division B.A.R.C., Mumbai-85

TRUSTWAVE SEG SPAMCENSOR EXPLAINED

Effective Open-Source Spam Filtering

ESET Mail Security 4. User Guide. for Microsoft Exchange Server. Microsoft Windows 2000 / 2003 / 2008

Lab Tasks 1. Configuring a Slave Name Server 2. Configure rndc for Secure named Control

Empirical Analysis of Denial of Service Attack Against SMTP Servers 2 RELATED WORK

THE DEFINITIVE GUIDE TO SETTING UP A LINUX RELAY SERVER FOR MICROSOFT EXCHANGE SERVER

At Course Completion After completing this course, students will be able to: Take This Training. On This Page Introduction.

A Modular Architecture Using Open Source Components

EMB. Basics. Goals of this lab: Prerequisites: LXB, NET, DNS

The Open Source Stack: One approach to spam filtering

An Overview of Spam Blocking Techniques

GL-275: Red Hat Linux Network Services. Course Outline. Course Length: 5 days

Introduction Open Source Security Tools for Information Technology Professionals

Migration Project Plan for Cisco Cloud Security

Spam Filtering at CERN Emmanuel Ormancey - 23 October 2002

Mauro Andreolini University of Modena Michele Colajanni. unimore.

Government of Canada Managed Security Service (GCMSS) Annex A-5: Statement of Work - Antispam

SuSE Solutions Based on

one million mails a day: open source software to deal with it Charly Kühnast Municipal Datacenter for the Lower Rhine Area Moers, Germany

Spam filtering. Peter Likarish Based on slides by EJ Jung 11/03/10

Tools. David Hilley. David Hilley, March 5, 2008 L A T E X - p. 1

eprism Security Appliance 6.0 Intercept Anti-Spam Quick Start Guide

The Network Box Anti-Spam Solution

debops.postfix documentation

Postfix. by Rod Roark

Updating Your Skills from Microsoft Exchange 2000 Server or Microsoft Exchange Server 2003 to Microsoft

ENTERPRISE LINUX NETWORKING SERVICES

Technical Note. ISP Protection against BlackListing. FORTIMAIL Deployment for Outbound Spam Filtering. Rev 2.2

Anti-SPAM Solutions as a Component of Digital Communications Management

MDaemon configuration recommendations for dealing with spam related issues

Foreword Credits Preface Part I. Legal and Ethics 1. Legal and Ethics Issues 1.1 Core Issues 1.2 Computer Trespass Laws: No "Hacking" Allowed 1.

Release Notes. for Kerio Connect 8.0.0

MDaemon Vs. Microsoft Exchange Server 2013 Standard

Microsoft Exchange Server 2007, Upgrade from Exchange 2000/2003 ( /5049/5050) Course KC Days OVERVIEW COURSE OBJECTIVES AUDIENCE

Software Engineering 4C03 SPAM

PROTECTING YOUR MAILBOXES. Features SECURITY OF INFORMATION TECHNOLOGIES

A D M I N I S T R A T O R V 1. 0

How to Install SMTPSwith Mailer on Centos Server/VPS

MailFoundry Users Manual. MailFoundry User Manual Revision: MF Copyright 2005, Solinus Inc. All Rights Reserved

Anti-Spam Service User s Guide Advanced Internet Technologies, Inc. December 3, 2004

KASPERSKY LAB. Kaspersky SMTP-Gateway 5.5 for Linux/Unix ADMINISTRATOR S GUIDE

A Beginner's Guide to Setting Up A Web Hosting System (Or, the design and implementation of a system for the worldwide distribution of pictures of

Thanks for choosing sentora-paranoid for your sentora hosting environment security solution

By Jascha Wanger

COURCE TITLE DURATION LPI-202 Advanced Linux Professional Institute 40 H.

Mail NIKHEF

SuSE 9.3 Professional. Anti-Spam & Anti-Virus. Gateway Build. Guide For Beginners

MailMarshal SMTP 2006 Anti-Spam Technology

Training Guide eprism Security Appliance 4.0

suitability for groupware, and performance on powerful hardware. Axigen Mail Server

ECE Mail System Overview. Pablo J. Rebollo ECE Network Operations Center

English Translation of SecurityGateway for Exchange/SMTP Servers

How To Configure Forefront Threat Management Gateway (Forefront) For An Server

Security. Help Documentation

GFI Product Comparison. GFI MailEssentials vs Barracuda Spam Firewall

Mail Services. Easy-to-manage Internet mail solutions featuring best-in-class open source technologies. Features

Configure a Mail Server

Content of comparison

Quarantined Messages 5 What are quarantined messages? 5 What username and password do I use to access my quarantined messages? 5

noway.toonux.com 09 January 2014

SPAMfighter Exchange Module

Web. Anti- Spam. Disk. Mail DNS. Server. Backup

ETH Zürich - Mail Filtering Service

Services Deployment. Administrator Guide

Barracuda Spam Firewall User s Guide

Administering Microsoft Exchange Server ; 5 Days, Instructor-led

Contents Introduction xxvi Chapter 1: Understanding the Threats: Viruses, Trojans, Mail Bombers, Worms, and Illicit Servers

ADMINISTERING MICROSOFT EXCHANGE SERVER 2016

Mailborder. User Manual. Advanced Protection. Version Build 2. Copyright Mailborder Systems

KASPERSKY LAB. Kaspersky Anti-Virus 5.5 for Linux and FreeBSD Mail Servers ADMINISTRATOR S GUIDE

Articles Fighting SPAM in Lotus Domino

Implementing MDaemon as an Security Gateway to Exchange Server

Technical Note. FORTIMAIL Configuration For Enterprise Deployment. Rev 2.1

Fighting Spam: Tools, Tips, and Techniques

FILTERING FAQ

Spam, Spam and More Spam. Spammers: Cost to send

services. Anders Wiehe IT department Gjøvik University College

OIS. Update on the anti spam system at CERN. Pawel Grzywaczewski, CERN IT/OIS HEPIX fall 2010

ESET Mail Security & Zarafa 7 infrastructure Integration

Lesson Plans Configuring Exchange Server 2007

Updates from France. Migration of the CRU federation Setting up a national anti-spam service. 4 th December

KASPERSKY LAB. Kaspersky Mail Gateway 5.6 ADMINISTRATOR S GUIDE

Comprehensive Filtering. Whitepaper

How to Configure edgebox as an Server

Transcription:

Spamfilter Relay Mailserver Mark McSweeney CentraLUG, February 1, 2010

Overview Scope Little bit about me Why I built the spamfilter Deployment environment Spamfilter details Tuning and maintainance Other resources

Scope Explanation of how and why I did this Show all software packages used Point towards resources to learn more

A little about me Compliance Test engineer @ Compliance Worldwide 9 ½ years USAF installing CO and microwave relay stations Started tinkering w/ Linux ~ 2001 Not a professional Linux engineer No formal CS background/education

Why I built spamfilter I personally was getting > 500 spam mails /day Probably > 2000 to entire company Tried anti-spam plugins not very effective Commercial solutions very expensive Couldn't find anything viable for our Exchange Server

Deployment environment Initially 100% MS in back office Windows NT Server MS Exchange Clients MS Outlook Suggested minimum Pentium II 450 MHz w/ 512 Mbit RAM My setup Pentium II 350 w/ 256 Mbit RAM

Overview of spamfilter Found it initially through site written by Scott Henderson Built on RH 9.0 Scott stopped maintaining document ~ 2008 freespamfilter.org started to continue project Contains initial RH build as well as Debian, FreeBSD, OpenBSD, Gentoo, Fedora builds I use the Debian build

Overview of spamfilter

Software Packages Postfix Amavisd-new SpamAssassin Razor DCC Pyzor ClamAV

Postfix Mailer written by Wietse Venema that started life at IBM research as an alternative to the widely-used but difficult to configure Sendmail program. Key files are master.cf and main.cf A lot of values stored in lookup tables that are turned into hash tables using command: postmap foo Many settings stop mail from being accepted at the front door

Amavisd-new amavisd-new is a high-performance interface between mailer and content checkers: virus scanners, and/or SpamAssassin. Settings used in online document are what might be used at small business (perfect for me). Many more settings that scale highly for larger deployments

SpamAssassin Apache project Assigns a score to each email depending on how spammy it calculates it to be. Called by amavisd-new Querys DCC, Pyzor, Razor servers to score mail Also queries real time blacklists (RBLs)

Pyzor Collaborative, networked system to detect and block spam using digests of messages. Pyzor queries similar to DNS requests - uses UDP port 24441

Razor Distributed, collaborative, spam detection and filtering network. Through user contribution, Razor establishes a distributed and constantly updating catalogue of spam in propagation that is consulted by email clients to filter out known spam. Detection is done with statistical and randomized signatures User input is validated through reputation assignments based on consensus on report and revoke assertions which in turn is used for computing confidence values associated with individual signatures.

DCC Distributed Checksum Clearinghouse The basic logic in DCC is that most spam mails are sent to many recipients. The same message body appearing many times is therefore bulk email. DCC identifies bulk email by taking a checksum and sending that checksum to a Clearinghouse (server). Server responds with the number of times it has received that checksum. An individual email will create a score of 1 each time it is processed. Bulk mail can be identified because the response number is high. Content is not examined. Uses UDP protocol and uses little bandwidth.

ClamAV Cross-platform antivirus software tool-kit capable of detecting many types of malicious software, including viruses. Used as a server-side email virus scanner. Owned by Sourcefire, maker of Snort

Maintainance and Tuning ClamAV lets you know when new versions are available in /var/log/clamav/freshclam.log Since Postfix is run in a chroot jail it will complain about files differing. When this happens, we need to run a script that is supplied with the Postfix source code (called LINUX2) that will once again copy all the files that Postfix needs to where it needs them.

Maintainance and Tuning (more) Postfix has sections dealing with whitelisting and blacklisting. Amavisd also has sections dealing with whitelisting and blacklisting. Several scripts for updating, log checking, intrusion detection, etc.

Resources www.freespamfilter.org www.postfix.org http://razor.sourceforge.net/ http://www.ijs.si/software/amavisd/ http://spamassassin.apache.org http://sourceforge.net/apps/trac/pyzor/ http://www.clamav.net/