Home > Ask the Security Experts > Application Security Questions & Answers > Will using whitelists and blacklists effectively stop spam?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Will using whitelists and blacklists effectively stop spam?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 17 November 2006
We use an IronPort device on our perimeter, and we check email content for viruses and spam. A part of our organization insists on using global whitelisting to bypass quarantine procedures. This, however, seems like a security risk, since it will expose IP addresses and lead to IP spoofing. Are we correct in our assumptions?

>
EXPERT RESPONSE
Blacklists and whitelists are very blunt instruments with which to combat spam or malicious emails. Creating either list is time-consuming, but a white-listed sender's system, in particular, can easily be compromised. Should this happen, your email system would allow spam from the mail server until the sender from the whitelist is removed. Does the department in your organization know for sure that the newsletters would actually be stopped by IronPort? It would be worth testing. Also, if the messages are quarantined, it is just a matter of approving any newsletters that are genuine and allowing them to be forwarded to the intended recipient, a minor inconvenience if compared to allowing exceptions to your mail security policy. If one department can force an exception, others are bound to try and follow suit.

IronPort is certainly a leading email security device. I like IronPort's C-Series mail gateways, which use Bounce Address Tag Validation (BATV). One spam attack that IronPort prevents is known as "joe-job," or a misdirected bounce attack. To execute this attack, a spammer sends emails with the intended recipient's address spoofed as the return address. This causes mail systems to inadvertently bounce the spam to the real victim. Bounce Address Tag Validation safeguards outgoing mail, adding an encrypted verification check to the SMTP FROM: field that makes it easier to distinguish between real addresses and fake bounced ones. What's great about this type of verification is that, unlike other email authentication technologies, it can be effective, even if other mail servers are not required to adopt it.

While I can't speak to your concerns about exposing IP addresses, it may help to know that each mail server that processes a message inserts a Received: header at the top of its list. The header includes the sender's IP address and provides a continuous track of a message's route. So, even if the sender uses a false email address when contacting the receiving server, modern mail transfer programs record the correct IP address of the sender. Thus an email message's "Received:" headers show how it has been routed to its destination. The IP address of the sender is more or less the only part of an email message that cannot be faked. It is next to impossible to spoof the IP address for the duration of the SMTP conversation. This is why IP addresses are a key component in combating antispam efforts and identifying known bad or good senders.

More information:

  • Learn how to stop spam from ruining your mailing lists.
  • Read about spammers' latest technique: image spam.

  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    What risks do application virtualization products pose to enterprise security?
    Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
    How can quality assurance tools aid software development?
    Should UTM and Web security filtering software be used together?
    Is the iPhone amenable to any method of email encryption?
    What are effective ways to stop instant messaging (IM) spam?
    Is it impossible to successfully remove a rootkit?
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?

    Spam and Antispam
    Video: The foundation of an email security strategy
    Facebook wins spam lawsuit
    Quiz: Email security essentials
    Phishing, malware laden USB sticks stoke holiday attacks
    McColo shutdown won't stop spam, malware, warn security experts
    Phishing, identity theft keeps law enforcement, researchers occupied
    Sophos sees increase in malicious email attachments
    What are effective ways to stop instant messaging (IM) spam?
    Malicious program poses as Windows Security Center
    Spam network halted by U.S., New Zealand officials
    Spam and Antispam Research

    Email Encryption (SMIME & PGP)
    Trend Micro joins growing email encryption market
    Code Green enters consolidated DLP Market
    Is the iPhone amenable to any method of email encryption?
    Tumbleweed merger seen as a negative for email security customers
    Secure messaging complications result in limited protection
    Information security book excerpts and reviews
    ING hopes to cut phishing attacks with encryption software
    Companies still monitoring email manually, survey finds
    Should iPhone email be sent without SSL encryption?
    Can the symmetric encryption algorithm for S/MIME messages be changed?
    Email Encryption (SMIME & PGP) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CAPTCHA  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    content filtering  (SearchSecurity.com)
    DomainKeys  (SearchSecurity.com)
    Joe job  (SearchSecurity.com)
    munging  (SearchSecurity.com)
    Register of Known Spam Operations  (SearchSecurity.com)
    Sender Policy Framework  (SearchSecurity.com)
    spam cocktail  (SearchSecurity.com)
    spam filter  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts