Home > Security Tips > Threat Monitor > 100% virus-free e-mail?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

100% virus-free e-mail?


James Michael Stewart
06.25.2002
Rating: -3.67- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




E-mail has become the most common distribution or carrier medium for viruses. The rate at which e-mail-borne viruses are detected or intercepted is increasing at an exponential rate. In 1999, only one virus was intercepted via e-mail per hour. In 2000, this rate increased to one virus every three minutes. By 2001, this rate jumped to one virus every thirty seconds. Now in 2002, the rate is approaching one virus every 10 seconds. Thus, the percentage of virus-infected e-mails is increasing faster than the rate of total number of e-mail messages transmitted. This is an alarming fact.

In addition, a virus scanner is only as useful as its definition lists are accurate and up-to-date. But even with a fully updated virus scanner, an average of 3% of known viruses still get past these protective barriers.

As the value of corporate data increases, the threat of a virus infection that either destroys data or distributed confidential data becomes more severe. The only solution is to prevent any and all viruses from entering your network. But traditional antivirus products are unable to provide such a solution.

Fortunately, there are companies that offer e-mail filtering and even one that offers guaranteed 100% virus-free e-mail delivery. This company is Message Labs, based in the UK. Using a combination of artificial intelligent search agents, heuristic investigation, signature matching and pattern analysis, Message Labs is able to detect and quarantine known and unknown viruses.

The basics of the Message Labs solution involve routing e-mail using DNS MX records to one of their high-speed high-volume control towers. There, each e-mail is scanned before being sent back to your e-mail server. Any infected e-mails are moved to a quarantine area. Quarantined e-mail can be accessed for up to 30 days to extract any valuable content, but precautions must be taken to prevent infection from accessing known virus carriers. In most cases, e-mail is delayed by less than two seconds, but that is a small price to pay for virus-free security. The Message Labs virus-free e-mail service requires that you maintain your own e-mail server and have at least 25 e-mail recipients.

Other companies are either less boastful or less confident with their claims. Postini, of Redwood City, Calif., is a company offering an e-mail gateway solution that companies deploy on their networks. This company's solution relies exclusively on McAfee's virus software. It does not include heuristic or AI scanning.

BigFish, of Marina del Rey, Calif., offers a solution that routes in-bound mail to their central processing systems where AV is used to scan for viruses and an optional attachment blocking capability can strip all attachments before sending the message on to the SMTP server of the customer company. It seems to use a single antivirus product and also does not include heuristic or AI scanning.

A company called Brightmail, of San Francisco, Calif., calls itself the "undisputed anti-spam leader." Using a process similar to MessageLabs, Brightmail filters spam, viruses and other undesirable messages at the Internet gateway. Brightmail seems to focus on spam though, with virus protection as an afterthought. They use Symantec for antivirus.


About the author
James Michael Stewart is a researcher and writer for Lanwrights, Inc.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




BROWSE BY TAG
Common Vulnerabilities and Prevention Tips,   Threat Monitor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Common Vulnerabilities and Prevention Tips
What's your infosec IQ?
IE update clears up spoofing issue
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
Mydoom variant targets security features, Microsoft
IE flaw could fool users in illicit downloads
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
Worm opens two backdoors, logs keystrokes

Threat Monitor
How to detect software tampering
How to prevent phishing attacks with social engineering tests
An enterprise strategy for Web application security threats
How SSL-encrypted Web connections are intercepted
How a corporate Twitter policy can combat social network threats
Cyberwarfare and the enterprise: Is the threat real?
Software security threats and employee awareness training
Newest malware threats
How to defend against rogue DHCP server malware
When BIOS updates become malware attacks

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts