27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7-2<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 7 Reputation Filtering<br />

The SenderBase Reputation Service allows enterprises to identify known spam based on the connecting<br />

IP address, allowing organizations to block spam as soon as it reaches the gateway. This increases the<br />

effectiveness of the anti-spam scanning engine being used or any content-based filter.<br />

Protect against spam floods<br />

Viruses such as SoBig and “hit and run” spam attacks can create sudden and unexpected spikes in<br />

message volume. If a particular sender starts sending at high volumes, the SenderBase Reputation<br />

Service can detect this through its global affiliate network and assign a more negative score, which the<br />

Cisco <strong>IronPort</strong> appliance can use to immediately begin limiting the number of recipients per hour<br />

allowed from the sender. (See also Outbreak Filters, page 10-1.)<br />

Improve throughput<br />

The Cisco <strong>IronPort</strong> appliance can reduce system load and increase message throughput by immediately<br />

rejecting known spam and routing known good messages past content filters.<br />

Reputation Filtering: the Cisco <strong>IronPort</strong> SenderBase Reputation Service<br />

The Cisco <strong>IronPort</strong> SenderBase Reputation Service (available at http://www.senderbase.org) is a<br />

service designed to help email administrators better manage incoming email streams by providing<br />

objective data about the identity of senders. The SenderBase Reputation Service is similar to a credit<br />

reporting service for email; it provides data that enterprises can use to differentiate legitimate senders<br />

from spam sources. Integrated directly into the Cisco <strong>IronPort</strong> appliance GUI, the SenderBase<br />

Reputation Service provides objective data that allows you to identify reliably and block IP addresses<br />

originating unsolicited commercial email (UCE) or to verify the authenticity of legitimate incoming<br />

email from business partners, customers, or any other important source. The SenderBase Reputation<br />

Service is unique in that it provides a global view of email message volume and organizes the data in a<br />

way that makes it easy to identify and group related sources of email.<br />

Note If your Cisco <strong>IronPort</strong> appliance is set to receive mail from a local MX/MTA, you must identify upstream<br />

hosts that may mask the sender's IP address. See Incoming Relays, page 9-19 for more information.<br />

Several key elements of the SenderBase Reputation Service are that it is:<br />

Non-spoofable<br />

The email sender’s reputation is based on the IP addresses of the email sender. Because SMTP is a<br />

two-way conversation over TCP/IP, it is nearly impossible to “spoof” an IP address — the IP address<br />

presented must actually be controlled by the server sending the message.<br />

Comprehensive<br />

The SenderBase Reputation Service uses global data from the SenderBase Affiliate network such as<br />

complaint rates and message volume statistics as well as data from carefully selected public blacklists<br />

and open proxy lists to determine the probability that a message from a given source is spam.<br />

Configurable<br />

Unlike other “identity-based” anti-spam techniques like blacklists or whitelists that return a simple<br />

yes/no decision, the SenderBase Reputation Service returns a graduated response based on the<br />

probability that a message from that source is spam. This allows you to set your own threshold for where<br />

you choose to block spam and automatically assign senders to different groups based on their<br />

SenderBase Reputation Score.<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!