Advertisement
Promo

Security threats Toolkit

Sophos: Protecting the world from The Pentagon

Tom Espiner ZDNet.co.uk

Published: 28 Nov 2005 16:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...normally has bugs, and writers hope that any warnings by the security firms could actually help them complete their work.

Not technically malware, spam is still an important part of the work done at The Pentagon. The Sophos spam operations group of 11 people analyse and look at spam trends full-time. The unsolicited mail is taken from spam traps that work on a similar principle to the antivirus honeypots — anything that comes into them is by definition spam.


For photos of The Pentagon, click here.


"Any mail we receive from the honeypots is not legitimate. Anything with a large attachment will also be analysed by the antivirus guys, because more often than not malware is being spammed out," says Paul Baccas, spam research analyst. The honeypots Sophos uses are all ex-legitimate IP addresses that have been reassigned through agreements with ISP.

Spam blocking
Anti-spam software automatically filters 95 percent of the spam Sophos receives. The remaining 5 percent is automatically channelled through various rules, which look at whether the spam has come from a known spam relay, whether it has a high percentage of HTML and whether there are recognised text strings.

Approximately 0.05 percent of the spam is left after automatic filtering. This is when the analysts step-in to determine its characteristics and hopefully come up with a way of blocking it. One characteristic Sophos looks for is paragraph prints. Each spam has a certain distribution of paragraph breaks that characterises that particular spam and enables Sophos to recognise it and write a rule to block it. Rules are updated all the time and gradually get a lower score depending on their prevalence.

Next

Previous

1 2 3 4


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
236 out of 566 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters