+ All Categories
Home > Documents > Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Date post: 30-Mar-2015
Category:
Upload: leticia-bickley
View: 223 times
Download: 3 times
Share this document with a friend
Popular Tags:
28
Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam
Transcript
Page 1: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Blacklist, Whitelist & spamtrap

Terena EQUAL WorkshopDec 9th 2009 amsterdam

Page 2: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Index

• SMTP Blacklist

• SMTP WhiteList

• Spamtraps

Page 3: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

IRISRBL: RedIRIS blacklist system

Page 4: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

IRISRBL motivations

• Which/How many Blacklist to use ? SMTP traffic can be slowed with too much

DNS checks But better results (more spam blocked)

• What can we do with the false positives ? How fast can a IP address be removed from

a Blacklist system ?

• How can the NREN provide an additional service to their members ?

Page 5: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

IRISRLB: Motivations II

• Commercial Blacklist problems: For the SMTP provider (listed in it):

Sometimes outgoing SMTP servers are listed Bounce messages Infected users sending spam …. Politics issues

How to be removed from the list ? Need to pay money ? 48 hours delay

To the user of the Black list: Messages not received Manual removing of black list / white list No information about why this IP address is listed

Page 6: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Blacklist implementation I

• Based on part of a bigger product, Rks from Sandvine, http://www.sandvine.com

• Service only for own constituency http://www.rediris.es/servicios/irisrbl/

• Integrate different sources: Several blacklist White List & exceptions Events (Spamtraps)

• Only one query to DNS check the blacklist• Small web interface to remove IP in the blacklists• Only postmaster of the Blacklists (not IP owner)

can remove IP addresses // false positives

Page 7: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Blacklist implementation: RKS

• Custom DNS server based with a database backend.

• Incremental feed of informationServer don’t need to restart to add new IP

addresses.

• Flexible policy to define which feeds to add and when a IP is listed.

• Support for different sources.• Different operating system support.

Page 8: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

IRISRBL Stats

• More than 60% of RedIRIS constituency is using IRISBL.

• About 350 DNS queries/second

Page 9: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Whitelist

Page 10: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

White List

2004/2005.• Lot of black listing problems between

Universities & ISP in Spain.• SPF was not widely implemented

• Most of the mail providers, were using some kind of manual white list .

• No coordination .

Page 11: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Other White listprojects

• Some discussion in the E-COAT meetings, provide the initial jumpstart information.

• Dutch ISP WL. http://noc.bit.nl/dnsbl/nlwhitelist/

• DNSWL.org , http://www.dnswl.org

Page 12: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

WhiteList motivations

• Our main motivation is to avoid problems with blacklisting of SMTP server.

• We only tried a minimum quality requirement for being listed in the whitelist.

• It’s more important to receive the legal email from a blacklisted smtp server than don’t receive any email at all You can use other filters (content filters, etc)

after the blacklist to avoid this spam

Page 13: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

WhiteList Vision: button up

• Organizations usually exchange emails locally (country wide) SME partners and big local ISP are the main

problem

• Including big ISP in the whitelist provide visibilit.

• Focus locally and exchange information with other similar initiatives.

Page 14: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

White List format & usage:

• Two white list zones defined: ESWL: outgoing SMTP server of Abuses

members. MTAWL: White list with big international email

providers, other organizations and similar initiatives.

• White list is provided in different formats: DNS based (like blacklist) Configuration files for different SMTP servers.

• The files can be downloaded from the white list page.

• All the IP listed has a abuse/technical contact public address for troubleshooting

Page 15: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

RedIRIS white list: Eswl y MTAwl

RedIRIS

TelefónicaEuskaltel

ESwl

ONO

MTAwl

• Goverment

• Yahoo,Gmail, Hotmail

• Agencias, …

• zone high DNSwl.org• Others

RedIRISwitoutSPF

Telecable

Sarenet

Hostalia

Ya.com

TusProfesionales

• Pymes

Hostalia

RedIRIS White List

Page 16: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

WL policy:

Don’t spend too much time thinking how to implement it. Simple policy: you are in the list

Because you asked for this Someone added (mtawl )

People using the WL, want to have you in the WL.

WL , don’t provide any kind of reputation “good SMTP behaviour”, only states that this is the address of an SMTP server that “usually” don’t send too much spam. But also you provide contact information for abuse

reporting. And our spamtrap system allow us to monitor IP

address behaviour

Page 17: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Version 1.

• Simple Perl scripts . Manual processing of the information Ad-hoc scripts to add information from other

White List

• Success: Used by Universities & Spanish ISPs Great interest from other groups:

Bank, local government …

Fix most of the black listing problems between ISP & Universities.

Page 18: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Version 2.

• Web interface • Registry of changes• Most of the task can be done by the

domain owners.• Protocol to import information from other

White List systems.

Page 19: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

WhiteList soruces

• Spanish Universities & ISP

• SME

• Big SMTP providers

• Feeds from other sources DNSWL trustedsource

Page 20: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Conclusions

• Use a white list to avoid problems caused by blacklist, not to provide any kind of email assurance.

• Whitelist are useful if people knows and use it, (and usually they want also to be there).

• Having different level of quality promotes postmaster to reach the “high” level , improving the email quality overall.

Page 21: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

SPAMTRAP system

Page 22: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Spamtrap

• Fake emails accounts to receive spam.

• Provide information for: Bad IP addresses that are sending

spam(feed blacklist system) WL SMTP servers sending spam

(compromise system, detection of bad usage or compromise)

Early detect system of phising attacks.

Page 23: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Spamtrap features:

• Use domains & subdomains never used before. (ej, usr.rediris.es) Avoid collisions with real domains &

addresses.

• Redirect domains to a central machine to avoid parsing receive headers. Source IP address is always in the first

received line.

• Publish email addresses in web pages for crawlers.

Page 24: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Spamtrap : implementation

• Unix server + SMTP server (postfix)• Subdomains provided by universities.• Simple script to generate fake email

addresses for the domains• Publish the information in a web page

with a warning message.• Parsing of the incoming emails to remove

bounces from smtp servers.

Page 25: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Spamttrap implementation (II)

• Batch system to avoid system overload

• Real time check against different DNSzones Detection of Whitelisted servers sending

spam

• URL & binary extraction Extract malware from the files

• Store evidence for later use

Page 26: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Results of Spamtrap

• Blacklist: IP addresses that sent spam are used to feed the blacklist reputation system in real time (~5 minutes delay)

• WhiteList: IP addresses are verified against whitelist to detect infected machine and SMTP problems in the whitelist member.

• Phising/trend reporting: check some patterns to detect phising trends against some organizations in Spain.

• Provide information for security groups.

Page 27: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

Expectations:

• Blacklist: Sharing of blacklist between NRENS Commercial agreement (SCS like) for Terena

members ? Improve the tool

• WhiteList: Sharing of information between different

NRENs

• Spamtrap: Improve the tool More robust sensor network.

Page 28: Blacklist, Whitelist & spamtrap Terena EQUAL Workshop Dec 9 th 2009 amsterdam.

28

Edificio Bronce

Plaza Manuel Gómez Moreno s/n

28020 Madrid. España

Tel.: 91 212 76 20 / 25

Fax: 91 212 76 35

www.red.es – www.rediris.es


Recommended