BharatBhasha.com
 
Free Articles  >>  Email >>  Page 6  >> 

Does Your Email Reputation System Have a Bad Rep

Does Your Email Reputation System Have a Bad Rep?   by CipherTrust

The recent spike in the volume of spam traveling across the Internet, combined with the dangers of phishing and virus attacks that frequently accompany these messages, has forced enterprises to reconsider how they determine which messages will be allowed into their network. The latest advances in anti-spam technology have been enabled in part by the use of reputation services which determine the “good” and “bad” senders. There are several approaches to determining a sender’s reputation; some more effective than others.

In order to determine whether senders are “good” or “bad”, organizations must have the ability to accurately identify the sender of an email. Spammers and their ilk would prefer to hide their identities – especially for those that are engaged in open fraud such as phishing attacks. They modify email headers in an attempt to fool recipients into thinking the email is coming from a legitimate source. This practice, called “spoofing”, is a common tactic used by spammers to obfuscate their true identities.

To confront this issue, Microsoft, CipherTrust and other industry leaders have worked to create standards that allow organizations to determine whether an email is coming from a legitimate sender. To date, there continues to be debate as to which technology will prevail. Microsoft’s Caller ID (now dubbed the Sender ID Framework or SIDF) has emerged as a front-runner along with Meng Weng’s Sender Policy Framework (SPF) .

Unfortunately, merely knowing who is sending an email doesn’t necessarily stop spam. As it turns out, spammers have been early adopters of the new standards, they are better about applying for sender authentication technologies than normal corporations, and they are eager to participate!

Regardless of how many spammers adopt “honest” emailing practices, the technology to identify email senders is quickly being adopted by major ISPs and corporations. Armed with that knowledge, reputation-based filtering can have a significant impact on the level of spam in everyone’s inbox.

There are a number of methods companies use to determine whether a given email sender has a “good” reputation. Some of the most common tactics are:

By far the most costly method in terms of human resources, In-house lists require IT staff to maintain whitelists and blacklists in order to cut down on the spam problem. The difficulty with these programs is that they require that the IT staff become knowledgeable about a host of email security and spam issues, and the investment is rarely sufficient to overcome the thousands of variations of nuisances and threats posed by spammers, phishers, and other dubious email senders. By the time the administrator becomes aware of a new spam attack, the spam has already gotten onto the network, and into users inboxes.

These whitelists and blacklists are built and maintained by third party organizations for the benefit of subscribers. These lists are subject to many of the same problems faced by in-house administrators. In addition, some blacklists are maintained by vigilante groups that are quick to penalize an organization for spam; sometimes without due diligence and without giving that organization time to respond to spam charges. There is also a time-lag between when a spammer starts sending spam from a particular IP address and when the address gets added to the blacklist. By the time the services become aware of a spammers activities, the spammer has already sent millions of messages.

Two prominent examples of bonded programs are IronPort’s Bonded Sender Program and and Habeas’ Sender Warranted Email programs. These programs allow email marketers to secure bonds to certify that their email adheres to guidelines on the basis of privacy, mailing practices and issue resolution. ISPs and other mail servers can then query Bonded Sender when scanning incoming messages and handle them accordingly. However, this “pay-to-play” model is fundamentally flawed, as it gives spammers the ability to simply “buy” their way onto the list by securing a bond as a legitimate sender, regardless of whether they’re actually legitimate or not. While the cost of the bond may be prohibitive to some senders, the benefits far outweigh the costs to most spammers, as the only way the bond will be debited is if Bonded Sender receives complaints about a specific account sending spam. And really, when was the last time you or anyone you know reported receiving spam? Would you even know where to report it? In reality, spammers are paying IronPort for the right to clog your inbox.

TrustedSource is CipherTrust’s adaptive, real-time email reputation system that provides information on email sender behavior. Who sends spam? Who polices their outbound email well? TrustedSource knows. By constantly observing and analyzing email traffic across the Internet, CipherTrust identifies the "good guys.” TrustedSource provides constant updates on sender status to improve spam-fighting accuracy and allows IronMail, the secure email gateway, to achieve the highest level of accuracy in determining good email from bad.

TrustedSource servers provide data to IronMail by contributing negative values to IronMail’s Spam Profiler (SP) algorithm for messages sent from senders that are deemed reputable. Every message that passes through IronMail is checked against the TrustedSource list and based on the reply, IronMail will make a decision about whether to reduce the overall SP spam score for that message and improve its chances of not being classified as spam.

What constitutes “good behavior”
Spammer behavior changes constantly so no definitive answer is available. However, the following practices are considered “best practices” for email senders:


  • Comply with the proper RFC protocols for email.
  • Do not attempt to obscure content or messages in emails.
  • Do not send email to unverified or nonexistent email addresses.
  • Post privacy policies where they can be read and understood, prior to submission of a request.
  • Offer opportunities for users to opt-out of programs.

Adopting a reputation-based anti-spam system alone has not proven effective to stop spam. However, by combining reputation-based systems such as CipherTrust’s TrustedSource with other methods of spam control technologies such as SIDF, SPF, Bayesian Filters, Blacklists, Whitelists, Anomaly Detection, and Spam Signatures, IronMail has achieved industry-leading success.




Article Source: http://www.BharatBhasha.com
Article Url: http://www.bharatbhasha.com/email.php/18032

Other Articles related to "Does Your Email Reputation System Have a Bad Rep" by CipherTrust

Your Reputation Precedes You
by CipherTrust A Look at the Past, Present and Future of Email Reputation Systems “Reputation, reputation, reputation! Oh, I have lost my reputation! I have lost the immortal part of myself, and what remains is bestial.”--Spoken by Cassio, in Shakespeare’s Othello (circa 1602)Though written over four centuries ago, the sentiment behind these words still holds true – you’re nothing without your reputation. Every day, different reputation systems dictate who you are to those who don’t know you....

Maximizing Email Security ROI Stop Spam and Save
by CipherTrustThis is the first of a five-part series on Maximizing Email Security ROI In the realm of email security threats, the costs of spam are relatively easy to recognize. Although most organizations rarely, if ever, take the time to calculate their spam costs, they can easily account for the losses caused by spam with regards to employee productivity, consumption of IT resources and help desk costs. Harder to measure are the less obvious, and potentially catastrophic, costs incurred...

Maximizing Email Security ROI Part II Stop Viruses Before They Stop You
by CipherTrustThis is the second of a five-part series on Maximizing Email Security ROI. Across the spectrum of information security risks, most casual users understand the dangers posed by viruses and worms. Network administrators have even more reason to fear a virus attack, as a successful assault can cripple corporate networks for days. The lasting damage, however, is much more difficult to determine with precision, as the residual financial impact of a virus infection extends long after...

Increase Efficiency with Intelligent Email Traffic Control
by CipherTrustWork Smarter, Not HarderCipherTrust’s IronMail has helped some of the largest enterprises in the world stem the flood of spam to their end users, as well as address a host of other e-mail threats. IronMail’s unique Spam Profiler tool provides maximum effectiveness by scrutinizing thousands of characteristics of every message to determine a spam score. But the challenges for enterprises today do not stop at identifying and blocking spam. With spam volumes continuing to increase...

Maximizing E mail Security ROI Part V A New Twist to an Old Problem Email Encryption
by CipherTrust This is the last of a five-part series on Maximizing Email Security ROI. Throughout the ages, people have encrypted communications to suit their information security needs. In the 1st century B.C., Julius Caesar didn’t trust the couriers who carried his messages to trusted acquaintances. So, he replaced every A with a D, every B with an E, and so on, all the way through the alphabet. Only those who knew Caesar’s shift-by-three rule could decipher his messages. Over 2000 years...

Maximizing Email Security ROI Part III No More Mr Nice Guy Enforcing E Mail Policy
by CipherTrustThis is the third of a five-part series on Maximizing E-mail Security ROI.E-mail is an easy, cheap and readily available form of communication. It’s a great tool for businesses, but without proper safeguards in place to regulate the information transmitted it can also be a potential threat. An effective e-mail policy should be all-encompassing, helping organizations comply with federal regulations, protect intellectual property and prevent offensive materials from being...

Why Corporations Need to Worry About Phishing
by CipherTrustPhishing is a relatively new form of online fraud that focuses on fooling the victim into providing sensitive financial or personal information to a bogus website that bears a significant resemblance to a tried and true online brand. Typically, the victim provides information into a form on the imposter site, which then relays the information to the fraudster. Although this form of fraud is relatively new, its prevalence is exploding. From November 2003 to May 2004, Phishing...

3 Criteria for Controlling Enterprise Spam
by CipherTrustOr: T*ake Y O U R email ba & ack + From the Sp@mmers! 0400constrictor bubble snake informational If you have a business, then you have a spam problem. The efficiencies of communicating through e-mail not only benefit organizations like yours; they also benefit the spammers who profit off of sending pernicious e-mails to millions of people every day. In fact, spam is so cost-effective that it costs less than $0.0004 to send a single spam. That’s 25 emails for just one penny! The...

Maximizing E mail Security ROI Part IV The Digital Monsters under Your Bed E Mail Intruders
by CipherTrust This is the last of a five-part series on Maximizing Email Security ROI. Remember your kid fears? As soon as the lights went out, the monsters under your bed began plotting ways to get you. Somehow, though, you always managed to outsmart them and make it through the night. Then one night you grew up, and the monsters went away for good. Well, they're back. And they've unionized.International rings of hackers, many backed by funds from organized crime groups, are the new...

Detecting and Eliminating Computer Viruses at the Gateway
by CipherTrustTraditional anti-virus software only stops known computer viruses – stopping undefined computer viruses requires a different approach.In the past, network administrators scrambled to apply new virus signatures whenever new computer viruses were discovered. While these signatures will stop a known threat, it takes time for anti-virus vendors to develop them. Unfortunately, the newest and most damaging viruses are able to spread so quickly that the damage is done before a...

Click here to see More Articles by CipherTrust
Articles In LimeLight
  • Understanding Employee Motivation
    By Bertil Hjert Added on Friday, April 25, 2008
  • Bad Credit Car Loans - Things You Should Know Before You Apply
    By Carrie Reeder Added on Sunday, May 4, 2008
  • Affordable Health Insurance In Missouri
    By Elizabeth Newberry Added on Wednesday, April 16, 2008
  • The Advancement Of Security Technology With Network Security Cameras
    By Steve Strong Added on Sunday, April 27, 2008
  • Obtaining Your Texas Home Equity Loan
    By IPRWire Staff Writer Added on Sunday, May 4, 2008
  • Cheap Car Insurance For Young Drivers
    By Elizabeth Newberry Added on Sunday, April 27, 2008
  • Income Protection Insurance Or IPP
    By Simon Burgess Added on Saturday, April 19, 2008
  • Types Of Auto Insurance Policies
    By Mark Robinson Added on Saturday, April 26, 2008
  • Be Aware Of Ongoing Coastal Vacation Scams
    By Dustin Heath Cannon Added on Sunday, May 4, 2008
  • Finding The Best Auto Insurance Companies Is Not A Herculean Task
    By Mark Robinson Added on Monday, May 5, 2008
  • Wedding Occasion Gift Baskets
    By Joe Palladino Added on Monday, May 5, 2008
  • Taking Care Of Your Wooden Patio Furniture
    By Adam Peters Added on Friday, April 18, 2008
  • Loan Protection Insurance Cover For Debt Management
    By Simon Burgess Added on Saturday, April 19, 2008
  • Independent Horse Loving Women
    By Ron Petracek Added on Thursday, May 1, 2008
  • Adult Add: Making Time Your Time All Day
    By Tellman H. Knudson Added on Saturday, April 19, 2008
  • Tasks To Undertake Before Embarking On A Mountain Bike Trip
    By Mr.Andrew Caxton Added on Saturday, April 19, 2008
  • Finding A Marketing Network That Keeps Your Interest
    By Dustin Heath Cannon Added on Wednesday, April 30, 2008
  • How To Build A Squidoo Lens That Drives Traffic To Your Website
    By Alex Rich Added on Monday, April 28, 2008
  • Controlling Pests In Your Aquarium
    By Devin Gilliland Added on Monday, April 28, 2008
  • Destination Inverness? Get Around In A Car Hire
    By Lakshmi Reddy Added on Friday, April 18, 2008
  • About Author CipherTrust :

    CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, “No Phishing: Protecting Employees from E-mail Fraud” or by visiting www.ciphertrust.com.

    Publishers / Webmasters
    Tell A Friend
    Comments / Questions?
    Download this article in PDF
    Search through all the articles:


    318 Users Online!
    Related Articles:
    Latest Articles:
     
    Email >> Top 50 Articles on Email >> All Articles in this category
    Category - >
    Advertising Advice Affiliate Programs Automobiles
    Be Your Own Mentor Careers Communication Consumers
    CopyWriting Crime Domain Names DoT com Entrepreneur Corner
    Ebooks Ecommerce Education Email
    Entertainment Environment Family Finance And Business
    Food & Drink Gardening Health & Fitness Hobbies
    Home Business Home Improvement Humour House Holds
    Internet And Computers Kiddos and Teens Legal Matters Mail Order
    Management Marketing Marriage MetaPhysical
    Motivational MultiMedia Multi Level Marketing NewsLetters
    Pets Psychology Religion Parenting
    Politics Sales Science Search Engine Optimization
    Site Promotion Sports Technology Travel
    Web Development Web Hosting WeightLoss Women's Corner
    Writing Miscellaneous Articles Real Estate Arts And Crafts


    Disclaimer: The information presented and opinions expressed in the articles are those of the authors
    and do not necessarily represent the views of Bharatbhasha.com and/or its owners.


    Copyright © AwareINDIA. All rights reserved || Privacy Policy || Terms Of Use || Author Guidelines || Article Search
    FAQs Link To Us || Submit An Article || All Products || Free Downloads|| Contact Us || Site Map  || Advertise with Us ||
    Click here for Special webhosting packages for visitors of this website only!