351
Preventing attacks
Increasing productivity by identifying spam email
These scanning processes are described in the following:
■
“Reducing false positives by bypassing the real-time blacklists”
■
“Blocking spam using real-time blacklists”
■
“Reducing false positives using a custom allow list”
■
“Identifying spam using a custom known spammers list”
■
“Identifying spam using subject pattern matching”
■
“Identifying spam using heuristic antispam scanning”
■
“Adding antispam protection to a rule”
Identifying spam email
The security gateway lets you configure the following options to optimize spam detection:
In addition, you can specify limits for handling container files to protect against denial-of-service
attacks. These attacks can occur with container files that are large, that contain large numbers of
embedded compressed files, or that have been designed to maliciously use resources and degrade
performance. You set these limits using the Antivirus Configuration tab. They are applied when you
enable antispam checking on a rule.
“Preventing denial of service attacks”
The following describe how to configure the security gateway to identify spam email:
■
“Blocking spam using real-time blacklists”
■
“Identifying spam using heuristic antispam scanning”
■
“Identifying spam using a custom known spammers list”
5
Subject patterns identified
as spam
The subject line content is matched against the Subject patterns
identified as spam list. If there is a match or no subject line content,
the email is handled based on the settings that you configure. If there
is no match, the email proceeds to the next process.
6
Heuristic scanning
The email message is scanned by the heuristic scanner using the
specified sensitivity value. If the email message is identified as spam,
the email is handled based on the settings that you configure. If the
email is not identified as spam, the email is delivered to the recipient’s
inbox.
The POP3 protocol only uses the heuristic scanning process.
Table 9-4
Antispam scanning sequence (Continued)
Order
Scanning process
Description
Real-time blacklist server
Blocks mail that comes from mail servers known or believed
to send spam.
Heuristic sensitivity
Sets the sensitivity level of the heuristic antispam scanner.
Email senders identified as spam
Identifies spam based on addresses or domains that you
specify.
Subject patterns identified as spam
Identifies spam based on subject line content that you
specify.
Identify messages with no subject line as spam Identifies spam based on subject lines that do not contain
content.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...