+ All Categories
Home > Documents > The Anti-SPAM service from Forskningsnettet - What is new about it?

The Anti-SPAM service from Forskningsnettet - What is new about it?

Date post: 09-Feb-2016
Category:
Upload: happy
View: 24 times
Download: 0 times
Share this document with a friend
Description:
The Anti-SPAM service from Forskningsnettet - What is new about it?. TF-MSP meeting 4/2-2010 Martin Bech, UNI-C [email protected]. Fighting SPAM. A well-known problem Well-known solutions We all deal with spam Lots of home-built solutions Even more commercial services - PowerPoint PPT Presentation
Popular Tags:
19
The Anti-SPAM service from Forskningsnettet - What is new about it? TF-MSP meeting 4/2-2010 Martin Bech, UNI-C [email protected]
Transcript
Page 1: The Anti-SPAM service from Forskningsnettet - What is new about it?

The Anti-SPAM service fromForskningsnettet- What is new about it?

TF-MSP meeting4/2-2010Martin Bech, [email protected]

Page 2: The Anti-SPAM service from Forskningsnettet - What is new about it?

Fighting SPAM

A well-known problemWell-known solutionsWe all deal with spamLots of home-built solutionsEven more commercial services

Is there anything more for us as an NREN to do in this field?

Page 3: The Anti-SPAM service from Forskningsnettet - What is new about it?

Motivation for a common Anti-spam service

All universities are centralizing mail handlingAll Universities are using considerable resources fighting spamMaybe some kind of economy of scale may be achievedAnd we may even have a few new ideas to make the whole service better and innovative…

Page 4: The Anti-SPAM service from Forskningsnettet - What is new about it?

The basic idea

Make the storage of spam mail the sender’s problemWhile still preserving the benefits of having received the mails

Page 5: The Anti-SPAM service from Forskningsnettet - What is new about it?

RFC 2821

SMTP client required to wait 10 minutes before timeout for DATA completionAfter we have received the final “.” in the mail we scan it while keeping the connection open.If scanning is succesful, we return the “250 OK” message otherwise the “550” message is issuedOur “550” message contains a URL that a “human” sender may use to push his email through

Page 6: The Anti-SPAM service from Forskningsnettet - What is new about it?

Standard reception flow

SenderMTA

HELO local.domainMAIL FROM: mail@sendRCPT TO: [email protected]: bla bla

More bla bla

Immediately reject mail:550 Mail delivery rejected

Open TCP connection

GreylistingIn a

blocking list?

Yes

Immediately accept mail:250 Message accepted for delivery

No

And give the mailthe standard filter treatment

Bayesianfiltering

…and whatever

Virus scan

Non-delivery mail to “sender”

Standard delivery

Page 7: The Anti-SPAM service from Forskningsnettet - What is new about it?

Our approach

SenderMTA

HELO local.domainMAIL FROM: mail@sendRCPT TO: [email protected]: bla bla

More bla bla

Reject mail:550 Mail delivery rejected

Open TCP connection

Greylisting

In a blocking list?

Yes

Immediately accept mail:250 Message accepted for delivery

No

Bayesianfiltering

…and whatever

Virus scan

Standard delivery

Apply filtering while TCP connection from MTA open

Page 8: The Anti-SPAM service from Forskningsnettet - What is new about it?

Advantages in our approach

It is the obligation of the sender to store the rejected mailWe don’t issue any non-delivery messages – they are the obligation of the sending MTABlocked and rejected mails may still be stored as desired by the user

Page 9: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 10: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 11: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 12: The Anti-SPAM service from Forskningsnettet - What is new about it?

Ability to rescue all important mails from deletion

Honest (or at least human) senders may push their mails through – provided they don’t contain virusUsers may rescue rejected mails because we can configure the system to keep a copy even when it is the responsibility of the sender to store the rejected mailFor instance: You want a mail from a robot whose MTA is on a blocking list

Page 13: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 14: The Anti-SPAM service from Forskningsnettet - What is new about it?

Several ways of recipient validation

LDAPRadiusAD“SMTP Interruptus”which means sending RCTP To: userto the mail-server and breaking the connection

Page 15: The Anti-SPAM service from Forskningsnettet - What is new about it?

Configurable on domain and user level

Page 16: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 17: The Anti-SPAM service from Forskningsnettet - What is new about it?
Page 18: The Anti-SPAM service from Forskningsnettet - What is new about it?

Anti-SPAM production configuration

This figure is not very fancy, but the aim is to transmit the message that wehave designed this with scalability in mind

Page 19: The Anti-SPAM service from Forskningsnettet - What is new about it?

Would a similar service be relevant in your NREN?

A tremendous interest from the usersAll built using open-source componentsNo licences – only costs are our developers and the operations of the serversWe could help you build a similar setup – call me!

[email protected]


Recommended