Home > Ask the Security Experts > Application Security Questions & Answers > Will only allowing whitelist email messages stop image spam?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Will only allowing whitelist email messages stop image spam?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 24 July 2007
In order to thwart image spam, our organization automatically deletes email messages containing images that are not from senders on our whitelists. Do you recommend this strategy, and is there a better one that we should consider?

>
EXPERT RESPONSE
Image spam has become a significant problem for both spam-filtering systems and system administrators. This unsolicited messaging technique presents the text of a spam email as a picture in an image file. Because spam-filtering programs are mainly built to detect patterns in an email message's ASCII text, image spam has been highly effective in circumventing filters. Detection applications that utilize optical character recognition do not fare much better; obfuscation techniques make it easy for spammers to hide the text from machine-based readers while still leaving the message legible. Ironically, while Web sites are using CAPTCHAs (an image of distorted text) to tell whether the user is human, spammers are using the same basic techniques to bypass spam filters. The result is a noticeable rise in the amount of spam arriving in users' inboxes.

Your approach of automatically deleting non-whitelist email messages will certainly keep image spam to a minimum -- in fact, close to 100%. When it comes to tackling spam, whitelists are certainly a better approach than blacklists. Spammers continually create new email addresses to send messages from, or new keywords to use in their email, so blacklists are nearly always out of date.

A major drawback of whitelists, however, is their inordinate number of false positives. With whitelists, it's easy for a number of genuine emails to be deleted. An email from a potential supplier, for example, may include a corporate logo. Unless the company is already on the whitelist, the email will be deleted.

Trying to avoid the number of false positives requires an up-to-date whitelist. Maintaining this catalog of trusted sources is another drawback. Whether you use specific email addresses, IP addresses or trusted domains, gathering the list can be a very time–consuming and labor-intensive task.

If most of your legitimate email comes from a relatively small and fixed set of senders, then I would stick with your current tactic. The effectiveness of the strategy justifies the work involved in maintaining the list. However, if your users are likely to register for online services or subscribe to online newsletters, you could run into problems. For example, if you don't immediately add a new email source to your whitelist, or if the domain or IP address is entered incorrectly, the communication will fail. In these circumstances, instead of deleting emails containing images, I would quarantine them. Then, the recipient can quickly review the "from" and "subject" fields before allowing them to be downloaded to his or her inbox. Most gateway spam filters provide this type of functionality.

You could also institute a challenge-response test. When an unknown sender writes an email to one of your users, the system can automatically send a challenge back to the sender. The sender has to respond to this email in order for the message to be delivered. Since spammers are unlikely to bother with a response, the approach can be an effective one. The technology can be irritating, however, for your genuine correspondents.

Unfortunately, there's no perfect antispam strategy, but you should definitely back up your technology-based defenses with security awareness training and a strong email policy. Many users are still unaware of the often malicious nature of spam.

More information:

  • Spammers that target enterprises are switching from image spam to emails containing PDF attachments.
  • Learn why simple antispam filters aren't enough to stop the image spam problem.


  • Sound Off! -   


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Has proof-of-concept mobile device malware translated into any meaningful attacks?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?
    Will firewall technology have to adapt to applications that use port 80?
    How secure is a mobile phone platform that has an open source framework?
    What ports should be opened and closed when IPsec filters are implemented?

    Spam and Antispam
    Spam Blockers Losing Ground on Sophisticated Attackers
    Companies still monitoring email manually, survey finds
    Google Docs used in latest spam run
    New phishing, Zeus Trojan technique spreads crimeware
    Kraken botnet balloons to dangerous levels
    New Storm attack exploits April Fool's Day
    Gmail CAPTCHA cracking leads to spam surge
    Clinton, Obama campaigns used in spam blasts
    Google-Postini email services deliver security market message
    Product review: Webroot's Webroot Antispyware Corporate Edition with AntiVirus
    Spam and Antispam Research

    Email Security Basics
    Secure messaging complications result in limited protection
    Podcast: Exchange security -- A quick primer
    Are Internet cafe users' email credentials at risk?
    Enigmail: Wrapping email in a digital security blanket
    Email authentication showdown: IP-based vs. signature-based
    Are challenge-response technologies the best way to stop spam?
    Researchers flag Symantec Mail Security flaws
    Serious Google Gmail flaw exposes sensitive user data
    How is internal mail channeled through an enterprise firewall?
    Most antispam technologies get failing grade

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CAPTCHA  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    content filtering  (SearchSecurity.com)
    DomainKeys  (SearchSecurity.com)
    Joe job  (SearchSecurity.com)
    munging  (SearchSecurity.com)
    Register of Known Spam Operations  (SearchSecurity.com)
    Sender Policy Framework  (SearchSecurity.com)
    spam cocktail  (SearchSecurity.com)
    spam filter  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts