27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9 Anti-Spam<br />

Broadest Threat Prevention<br />

OL-25136-01<br />

CASE combines content analysis, email reputation, and web reputation to deliver the broadest set of<br />

threat prevention factors.<br />

Cisco designed Cisco <strong>IronPort</strong> Anti-Spam from the ground up to detect the broadest range of email<br />

threats. Cisco <strong>IronPort</strong> Anti-Spam addresses a full range of known threats including spam, phishing and<br />

zombie attacks, as well as hard-to-detect low volume, short-lived email threats such as “419” scams. In<br />

addition, Cisco <strong>IronPort</strong> Anti-Spam identifies new and evolving blended threats such as spam attacks<br />

distributing malicious content through a download URL or an executable.<br />

To identify these threats, Cisco <strong>IronPort</strong> Anti-Spam uses the industry's most complete approach to threat<br />

detection, examining the full context of a message-its content, methods of message construction, the<br />

reputation of the sender, and the reputation of web sites advertised in the message and more. Only Cisco<br />

<strong>IronPort</strong> Anti-Spam combines the power of email and web reputation data, leveraging the full power of<br />

the world's largest email and web traffic monitoring network — SenderBase — to detect new attacks as<br />

soon as they begin.<br />

Note If your Cisco <strong>IronPort</strong> appliance is set to receive mail from a local MX/MTA, you must identify upstream<br />

hosts that may mask the sender’s IP address. See Incoming Relays, page 9-19 for more information.<br />

Lowest False Positive Rate<br />

Cisco <strong>IronPort</strong> Anti-Spam and Cisco <strong>IronPort</strong> Outbreak Filters are powered by Cisco <strong>IronPort</strong>’s<br />

patent-pending Context Adaptive Scanning Engine (CASE) . CASE provides breakthrough accuracy<br />

and performance by analyzing over 100,000 message attributes across four dimensions:<br />

Step 1 Email reputation — who is sending you this message?<br />

Step 2 Message content — what content is included in this message?<br />

Step 3 Message structure — how was this message constructed?<br />

Step 4 Web reputation — where does the call to action take you?<br />

Industry-Leading Performance<br />

Analyzing multi-dimensional relationships allows CASE to catch a broad range of threats while<br />

maintaining exceptional accuracy. For example, a message that has content claiming to be from a<br />

legitimate financial institution but that is sent from an IP address on a consumer broadband network or<br />

that contains a URL hosted on a “zombie” PC will be viewed as suspicious. In contrast, a message<br />

coming from a pharmaceutical company with a positive reputation will not be tagged as spam even if the<br />

message contains words closely correlated with spam.<br />

CASE combines the following features to deliver accurate verdicts quickly:<br />

Multiple threats are scanned for in a single pass<br />

Dynamic “early exit” system<br />

System performance is optimized using Cisco <strong>IronPort</strong>'s unique “early exit” system. Cisco <strong>IronPort</strong><br />

developed a proprietary algorithm to determine the order in which rules are applied based on rule<br />

accuracy and computational expense. Lighter and more accurate rules are run first, and if a verdict<br />

is reached, additional rules are not required. This improves system throughput, allowing our<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

9-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!