ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security management Toolkit

Using a five-layer filter to cut spam

Staff

Published: 15 Dec 2003 13:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

TechRepublic Member: Curtis Birnbach

Job: President, Hudson Research Inc., which runs an electro-optics foundry including an optical shop, an electronics lab, an electro-optics lab, and mechanical fabrication areas, and produces devices for the military and the telecommunications industry

Industry: Electro-optics

Problem: Reducing the amount of spam employees have to delete

Solution
We have a five-layer spam filtration process that eliminates much of the problem. We get between 400 and 800 pieces a day, of which about 85 percent comes from China. Our layers are:

  • Brightmail
  • Router/hardware firewall
  • McAfee Spam-Killer
  • Symantec Software Firewall/Anti-Virus
  • E-mail client
  • This combination eliminates all but 50 to 100 pieces. The biggest problem is that our two Web sites attract spiders through the info@xxx general addresses. We can eliminate the bulk of the remaining spam by adding JavaScripts to the site, but that would compromise the ability of our sites to go through firewalls without requiring entries into the firewall database. We have always tried to maintain the maximum level of availability on our sites by minimizing the number and types of JavaScripts and using code that is highly cross-platform compatible.

    Client does a lot of the work
    We have elected to put a substantial portion of our defenses on the client rather than the server as it makes our system less vulnerable. It is annoying to administer, but worth the effort as it has prevented virus- and worm-based attacks. Given the number of security holes in the Windows servers, the client-based approach has obvious benefits. It works. The spammers are not anticipating this, and they focus their attack on the server. While we take as much care as possible to protect our servers, they are but one layer and a deception as far as the spammers are concerned.

    At this point, we are faced with the choice of rewriting a substantial portion of two Web sites to mitigate the problem or continuing to spend about a half hour per day on directly spam-related screening.

    Blocking tactics
    We tune our various filters to block primarily by domain, secondarily on key words. Due to the highly specific and technical nature of our products and services, we block all mail from non-NATO countries. However, advanced spammers routinely send mail through third parties, particularly through free services such as Yahoo, MSN, Excite, Lycos, etc. These services represent one of the biggest problems facing us as we also get a portion of legitimate email through these ISPs and cannot afford to summarily block these services.

    I can tell you that the impact of spam on small businesses is proportionally greater than the impact on large businesses. We have less manpower, less money, sometimes no IT department at all, and to devote even a half an hour a day to this issue is a terrible burden.

    • Email
    • Trackback
    • Clip Link
    • Print friendly Print with HP

    Did you find this article useful?
    65 out of 126 people found this useful



    Company/Topic Alerts

    Create a new alert from the list below:






    Related Jobs

    C#, VB.Net Web sites / applications. ASP.Net, Flash, AJAX. to 34,000

    ASP.Net developer with Flash, Flex or Silverlight is required by niche software consultancy, that develop a unique web base software application ...

    FIREWALL ADMINISTRATOR - CISCO PIX/ASA / CHECKPOINT - BIRMINGHAM

    New opening for a Network Security Specialist to work for a leading IT consultancy in the Birmingham area. Focused on design, implementation and ...

    Juniper Sales Professional, JUNOS, NetScreen, Firewall, WX, London

    Juniper Sales Professional required for pivotal role within a global provider of security & network infrastructure services & products based in ...

    Sentry Posts Blog

    Mobile Linux Better For Mobile Busines...

    Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

    Post a comment

    DWP downplays security breach

    The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

    Post a comment

    How many headshots does one chairperso...

    We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

    Post a comment

    Featured Talkback

    It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

    By: RonaldWilkins

    Read full story:
    Deloitte: People are still weakest security link

    DOWNLOAD

    Security Essentials

    Security Downloads

    There are masses of security suites out there for small businesses. Here's a selection to get you started

    Editor’s Rating
    1 Norton 360™
    2 AVG Anti-Virus Free Edition Rating: 10
    3 PC Tools AntiVirus Free Edition
    4 Kaspersky Internet Security

    See All Software

    In association with Symantec