Home

Akibia Spotlight

Check Point's Powerful SSL-VPN Capabilities Enhanced

Nokia Enhances Security Portfolio with IP390

Secure & Accelerate Your Business with Blue Coat

Your Reputation Precedes You: The Future of E-Mail Reputation Systems

Scaling Protection: The Network Now Plays a Roll in LAN Security

Compliance, NAC, VoIP & Others Require Next-Generation Network Infrastructure

The RSA Security PCI Solution

Solving the Entitlement Reporting Challenge

Case Study: Paragon Biomedical Secures Clinical Data via TippingPoint IPS

Achieving Compliance Nirvana

Voice on the Mobile Edge

Better Visibility for More Efficient Compliance

Best in Class HIPS Solutions for Best Practice Endpoint Security

Akibia News

Akibia Partners

Contact Akibia

 

 

Your Reputation Precedes You
A Look at the Future of E-mail Reputation Systems
By Dr. Paul Q. Judge, CHIEF TECHNOLOGY OFFICER - CIPHERTRUST, INC.

 

"Reputation, reputation, reputation! Oh, I have lost my reputation! I have lost the immortal part of myself, and what remains is bestial." Spoken by Cassio, in Shakespeare's Othello (circa 1602)

Though written more than four centuries ago, the sentiment behind these words still holds true - you're nothing without your reputation. Every day, different reputation systems dictate who you are to those who don't know you. To lenders, you're a credit score. To insurance companies, you're an actuarial risk. And now, thanks to the next generation of reputation systems, you're an IP score.

For obvious reasons, spammers, phishers and virus writers would prefer to hide their identities. They use countless techniques to disguise themselves with the intent of sneaking into your enterprise inboxes, robbing you blind or hijacking your network - or both.

On the other hand, those who would fight these senders are well served to know who the senders are and what they've been up to. To that end, e-mail reputation systems are used to figure out what sort of behavior senders have demonstrated in the past and make educated predictions of their future behavior, for better or for worse.

E-mail Security with Reputation

Unfortunately, many enterprises rely on an e-mail security solution based solely on message content; understanding the source of a particular message never enters the equation. While this approach is moderately effective when dealing with messages that contain specific spam identifiers, it is completely ineffective at stopping spam that employs techniques not yet seen.

A comprehensive approach to e-mail security involves examining both message content and sender history. By evaluating senders based on their past behavior, a more accurate picture of their intentions and legitimacy can be discerned. Has the sender engaged in spamming, virus distribution or phishing attacks? If they have, an effective reputation system knows and flags the message. Has the sender even been seen before? If not, a reputation system should pay close attention to ensure that the sender is not a "zombie" machine being controlled remotely by a hacker.

Trusted Source: The Next Generation

Today's spammers are more clever than ever, so today's reputation systems must be equally sophisticated. An effective reputation system must be dynamic, comprehensive and precise, and based on actual enterprise e-mail traffic in order to keep the spammers from gaining any advantage. That's why CipherTrust developed TrustedSource, the most precise and comprehensive reputation system available. TrustedSource keeps enterprises ahead of the spammers by leveraging research generated by CipherTrust's industry-leading network of customers. In developing TrustedSource, CipherTrust has succeeded in defining a reputation for every IP address in use across the Internet, not just those that have been encountered in the past.

By combining years of industry-leading research with the unmatched capabilities of IronMail's Message Profiler, CipherTrust has made some ground-breaking discoveries about the e-mail sending behavior of IP addresses. TrustedSource merges CipherTrust's unmatched knowledge base and global customer network of over 2000 blue-chip companies with generally available data such as traffic patterns, white/blacklists and network characteristics. This powerful combination allows TrustedSource to assign accurate scores to any IP address encountered by IronMail, considering both sender history and message characteristics.

Want more information about CipherTrust's TrustedSource reputation system? Contact CipherTrust at 1-866-448-8625 or visit www.ciphertrust.com.

 

About the Author

Dr. Paul Q. Judge currently serves as Chief Technology Officer for CipherTrust, Inc. Dr. Judge is a recognized authority on messaging security issues, having authored numerous papers that have been published in leading academic journals, presented at multiple industry and academic conferences including COMDEX, Interop, INBOX, RSA, MIT Spam Conference and InfoSecurity. Dr. Judge has also been featured in hundreds of national media outlets including CNN, Forbes, Business Week, People Magazine and the LA Times.