27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OL-25136-01<br />

Outbreak Filters<br />

CHAPTER<br />

10<br />

Low-volume, targeted email attacks such as phishing messages, scams, and malware links are on the rise<br />

while viruses spread through attachments are on the decline. The messages used for these non-viral<br />

attacks are complex and evolving; they are professional-looking messages that use social engineering<br />

tricks, including using the recipient’s information, in an attempt to trick the recipient into clicking<br />

custom URLs that point to phishing and malware websites. These URLs can be unique for each recipient<br />

or a small group of recipients and these websites are online only for a short period of time and are<br />

unknown to web security services. All of these factors make these small scale, non-viral outbreaks more<br />

difficult to detect than widespread virus outbreaks and spam campaigns. Cisco <strong>IronPort</strong>’s Outbreak<br />

Filters feature protects your users from this growing trend of targeted attacks in addition to new virus<br />

outbreaks.<br />

Outbreak Filters Overview, page 10-1<br />

Outbreak Filters - Multi-Layered Targeted Protection, page 10-3<br />

How the Outbreak Filters Feature Works, page 10-8<br />

Managing Outbreak Filters (GUI), page 10-11<br />

Monitoring Outbreak Filters, page 10-19<br />

Outbreak Filters Overview<br />

Troubleshooting The Outbreak Filters Feature, page 10-20<br />

Messages designed to steal sensitive information from users or deliver malware to their computers<br />

continue to evolve and can slip by traditional anti-virus and anti-spam scanning software. Outbreak<br />

Filters act proactively to provide a critical first layer of defense against these new outbreaks. By<br />

detecting new outbreaks in real-time and dynamically responding to prevent suspicious traffic from<br />

entering the network, Cisco <strong>IronPort</strong>’s Outbreak Filters feature offers protection until new anti-virus and<br />

anti-spam updates are deployed. The Outbreak Filters use Cisco <strong>IronPort</strong>’s outbreak detection<br />

technology and intelligent quarantine system to protect your users.<br />

The Outbreak Filters feature protects your users and your network by gathering information about<br />

outbreaks as they occur and using this data to prevent the spread of these outbreaks to your users.<br />

Outbreak Filters compares incoming messages with published Outbreak Rules from Cisco Security<br />

Intelligence Operations (SIO) to determine if the message is a part of a large-scale virus outbreak or a<br />

smaller, non-viral attack. <strong>AsyncOS</strong> assigns messages that match the Outbreak Rules a threat level that<br />

indicates the severity of the message’s threat and compares that threat level to the quarantine and<br />

message modfication thresholds you set for your mail policy. Messages that meet or exceed one of those<br />

thresholds are quarantined or modified to protect the recipient.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

10-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!