Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Anti-spam standard catches on - with spammers

Published: 09 Sep 2004 09:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

With few junk email filters supporting a protocol for verifying the source address of digital messages, spammers have adopted it themselves as a way to appear more legitimate, according to a report released on Wednesday.

The author of the study, email services provider MX Logic, analysed nearly 10 million bulk email messages that it had filtered on behalf of its clients in late August. The company found that nearly a sixth of the sources of the junk messages used a protocol known as Sender Policy Framework (SPF) to certify that the email addresses used in the messages were real.

While SPF has been touted as a way to stop spam, the data has shown that the true value of the protocol is more about preventing fraud, said Scott Chasin, chief technology officer of the Denver company.

"Authentication (with SPF) by itself is not a spam cure-all," Chasin said. "SPF -- as it relates to having an impact on spam -- will hurt only those who spoof domains. You are still going to need content filtering to see if the message was unsolicited."

SPF is one of two technologies currently being considered as part of a hybrid method, dubbed Sender ID, for certifying the source of email messages. Another technology, Microsoft's Caller ID for E-mail, makes up the other half of the proposed standard. Because it used technology that Microsoft is attempting to patent, Sender ID may require that users sign a licence from the software giant, which has angered many project groups in the open-source world.

That debate has caused many Internet engineers and mail administrators to take another look at SPF, created by Meng Wong, the founder of email service firm Pobox.com.

The Internet Engineering Task Force, the technical committee creating the standard, debated the issues extensively over its e-mail list during the last two weeks.

MX Logic's Chasin argues that SPF does not really solve the problem of spam -- at least not until there are supporting services to provide a measure of the reputation of the various email senders.

"SPF is great at combating fraud such as phishing," he said. Phishing is the Internet scam that usually uses email designed to look as if it came from an official organisation, such as a bank or government agency, to elicit personal data. "Phishing attacks are all about spoofing someone's domain name."

The majority of the SPF users found that spam was coming from "gobbledygook" domain names, not from legitimate companies, he said.

Chasin argues that new services are needed to give email recipients a measure of the reputation of the sender. Such services would basically certify that certain servers belong to "good" email senders, allowing message-filtering software to classify such email as legitimate.

"The email filters could then let through legitimate email," he said. "It would be 'guilty until proven innocent.'"

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
91 out of 199 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters