Home > Security News > Most antispam technologies get failing grade
Security News:
EMAIL THIS

Most antispam technologies get failing grade

By Robert Westervelt, News Editor
26 Jul 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Users of challenge-response technology reported the most satisfaction making it the most effective method to fight annoying spam, according to an independent study.

In fact most antispam technologies are getting a failing grade from some very frustrated users.

Business is ever more dependent on email and our anti-spam technologies are trying hard to fight the scourge that is spam, but they're not doing a very good job.
Peter Brockmann,
president and research director, Brockmann & Company

The study, by Northborough, Mass.-based IT consultants Brockmann & Company showed that challenge-response did better than appliances, hosted spam filters and commercial filters.

Brockmann surveyed more than 500 businesses, with 40% of the respondents having IT responsibilities. The independently funded study was conducted in June and resulted in the creation of a spam index to measure how satisfied workers were with their spam technologies.

The latest challenge-response technologies allow end users to send a "challenge" email to an unknown sender asking them to verify that the message is legitimate. The method is less sophisticated than filtering technology sold by antispam and antivirus vendors, but challenge-response was twice as effective as hosted services for spam prevention.

According to the survey, 67% of challenge-response users specified that they are very satisfied with their email experience as compared to next highest technology, hosted services, in which 42% reported that they were very satisfied.

Commercial software filters, such as those produced by McAfee, Symantec and Trend Micro, satisfied only 22% of respondents, the report found.

The author of the report, Peter Brockmann, president and research director of Brockmann & Company, said survey respondents were frustrated with their current technologies. The report found that 36% of organizations surveyed lost business because of legitimate emails getting caught in spam filters, Brockmann said.

"Business is ever more dependent on email and our antispam technologies are trying hard to fight the scourge that is spam, but they're not doing a very good job," he said.

Anti-spam:
Reputation systems gaining credibility in fight against spam: Now that nearly all organizations are employing some sort of anti-spam technology, spammers know their only hope for success lies with outwitting spam-detection strategies.

Is the CAN-SPAM Act a help or a hindrance? Security expert Joel Dubin examines the effectiveness of the regulation.

Brockmann said more businesses are beginning to investigate challenge-response technologies, such as those offered by Irvine, Calif-based Sendio and Seattle-based SpamArrest. But the industry was built on filtering technologies that take less aggressive approach by defending against spam rather than verifying message senders, he said.

"To a large respect the whole industry has harped around a performance metric of getting more of the nasty messages out of people's inboxes," Brockmann said. "To a large extent, unless we change something, it's not going to get any better."

Enterprises are finding challenge-response a viable option, Brockmann said. The latest challenge-response technologies use grey lists and other features to avoid sending a challenge email to unknown senders.

Brockmann's spam index is calculated based on the amount of spam emails they get, the number of trapped messages, the amount of time users had to deal with spam, and an estimated number of resend requests.

Brockmann said email hosting providers, from vendors such as AppRiver, MessageLabs and MXLogic also underperformed based on the index. Filtering appliances vendors, which integrate software with a hardware appliance, such as Barracuda, Borderware and McAfee performed poorly. And reputation-based systems known as "real-time black lists" that block out known spammer IP addresses from vendors such as Commtouch, IronPort and Spamhaus, also failed to satisfy users.

The worst performing technology was filter-based ISP solutions, which provides some form of antivirus and antispam filtering for hosted domains. The service is offered by most email hosting service providers.



Tags: Email Security Guidelines, Encryption and AppliancesEmail and Messaging Threats (spam, phishing, instant messaging)VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Email Security Guidelines, Encryption and Appliances
How to confirm the receipt of an email with security protocols
Best Email Security Products
Can an IP spoofing tool be used to spam SPF servers?
WatchGuard acquires email and Web security vendor BorderWare
McAfee to acquire email SaaS vendor MX Logic
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Cisco offers more email security choices, but lacks vision

Email and Messaging Threats (spam, phishing, instant messaging)
Messaging security risks have upper hand on solutions
Web-based attacks skyrocket, pirating sites surge, security firms say
Pushdo botnet uses Facebook to spread malicious email attachment
Scareware report highlights successful business model
How to prevent phishing attacks with social engineering tests
Phishing protection begins with training, antiphishing evangelist
Phishing attacks to remain a major problem, say security experts
Barracuda acquires Purewire expanding Web security reach
FBI raids phishing crime ring, nearly 100 arrested
Massive phishing scheme affects Microsoft Hotmail accounts
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
challenge-response system  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts