Home > Security News > Authentication takes a bite out of spam
Security News:
EMAIL THIS

Authentication takes a bite out of spam

By Amy Storer, News Writer
27 Jul 2005 | SearchNetworking.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

SAN DIEGO -- Disguised as innocent offers to save 80% on discreet prescription shipments and opportunities to earn a genuine college diploma in two weeks, spam e-mails are generating a widespread technology arms war.

However, speakers at the recent 2005 Burton Group Catalyst Conference said thwarting spam isn't a lost cause.

Trent Henry and Daniel Golding, senior analysts with the Midvale, Utah-based research firm, suggested antispam strategies for both inbound and outbound e-mail.

Golding said enterprises should vigilantly work to control spam because it's ultimately a drain on company resources and a negative reflection on corporate reputations.

To better control inbound spam, the analysts suggested combining malware protection and spam prevention, enforcing policies such as keyword and content outbound filtering, as well as adding confidentiality and encryption.

While an absolute resolution to all unsolicited e-mail issues isn't possible, according to the analysts, Sender Policy Framework (SPF) is the most effective solution for controlling inbound and outbound fraudulent spam.

SPF is an extension to Domain Name System in which the Internet domain of an e-mail sender can be authenticated for that sender. It can help spot an inbound e-mail claiming to be from a particular organization but originating elsewhere, reject it or queue it for closer inspection.

"Nothing we're talking about is perfect, but spam is about percentages," Golding said. "SPF takes one hour [to implement], it's reasonably effective and not terribly complex."

The analysts said SPF and other e-mail authentication initiatives -- such as Sender ID and Domain Keys, Yahoo's authentication specification that was recently merged with Cisco Systems Inc.'s Identified Internet Mail spec -- work together to better determine if a message originated from a domain other than the one claimed.

Attendee Bob Hart, manager of network services with Kent, Ohio-based Kent State University, said this conference was the first time he'd heard of sender-based authentication, but he now plans to discuss it with his DNS engineer to see if it's necessary.

"I've always wondered how someone can send e-mails without the server knowing who you are," Hart added. "If I get regular mail without a return address, I'm suspect. So why wouldn't I want the same kind of security for our e-mail systems?"

Golding and Henry listed the following as immediate action items for attendees: utilize sender-based e-mail authentication, update e-mail servers or antispam firewall services to support inbound SPF checks and publish SPF records.

But even with these precautions in place, Henry warned, spam will continue to grow both in volume and delivery paths. He said enterprises should prepare for SPIM and SPIT -- spam over instant messaging and IP telephony, respectively -- as emerging battlegrounds.

This news story originally appeared on SearchNetworking.com.

Tags: Email and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Email and Messaging Threats (spam, phishing, instant messaging)
The world's top 5 riskiest domains
How to secure a .pdf file
Top spammer gets four years in jail for stock fraud scheme
New Zeus spam poses as Social Security statements
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Phishing protection begins with training, antiphishing evangelist
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CAPTCHA  (SearchSecurity.com)
crimeware  (SearchSecurity.com)
Operation Phish Phry  (SearchSecurity.com)
pharming  (SearchSecurity.com)
phishing  (SearchSecurity.com)
Register of Known Spam Operations  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Sender Policy Framework  (SearchSecurity.com)
spam cocktail  (SearchSecurity.com)
spear phishing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts