Architecture of Kaspersky Anti-Spam and principles of spam filtering
19
The UDS technology allows filtering of known spam before updates to
the content filtration databases become available.
A filtration server interacts with UDS servers of Kaspersky Lab via UDP using
port 7060 for communication. In order to use UDS, a filtration server must be
able to establish outgoing connections through that port.
Information about available UDS servers is added to the content filtration
databases. The choice of an individual UDS to be used for message analysis is
performed automatically on the basis of the response time of accessible UDS
servers.
2.3. Recognition results and actions
over messages
The analysis procedure results in assignment of one of the following statuses to
a message:
•
Spam
– message recognized as spam with a high degree of reliability.
•
Probable Spam
– message contains some spam signs; however, it
cannot be unambiguously identified as spam.
•
Formal
– message is formal. E.g., it is a mail server notification informing
about mail delivery or inability to deliver it or about message infection with
a virus. The category includes messages sent automatically by mail
clients. Such messages are usually not considered to be spam.
•
Trusted
– message received from trusted sources, for example, from
internal mail servers. The administrator must create a list of trusted
sources (a white list of senders).
Trusted
status is also assigned to
messages addressed to users whose mail the product does not scan in
accordance with the corresponding group policy settings.
•
Blacklisted
– message received from an address present in a black list.
The administrator must create the black list.
•
Not detected
– a message that has not been recognized as spam.
Each e-mail message can be assigned just one of the above statuses. The
application records the status assigned to a message after analysis to a special
X-Spamtest-Status-Extended
header. Please refer to section A.5 on page 112
for details about the headers added to mail messages after filtering.