Symantec Brightmail AntiSpam Overview
8
Symantec
Brightmail AntiSpam™
Symantec Brightmail AntiSpam Overview
Brightmail Filters
Symantec Brightmail AntiSpam employs the following four major types of filters:
•
AntiSpam Filters –
AntiSpam Filters are created by Symantec using our state-of-the-
art technologies and strategies to filter and classify email as it enters your site.
•
Content Filters –
Custom content filters are written by you, using the Brightmail
Control Center or the Sieve scripting language, to tailor filtering to the needs of your
organization.
•
Blocked and Allowed Senders Lists –
You can create lists of blocked senders and
allowed senders and you can use third party lists. The lists included in the Brightmail
Reputation Service are deployed by default.
•
AntiVirus Filters –
Antivirus definitions and engines provided by Symantec protect
your users from email-borne viruses.
AntiSpam Filters
The nature of spam—and the business implications of false positives—demands a careful
and flexible approach to filter creation. Accordingly, Symantec does not use a one-size-
fits-all approach to creating filters. Instead, it employs a combination of filtering
strategies, based on the specific type of spam. Some technologies perform sophisticated
comparisons with the latest spam received by the Probe Network, resulting in matches of
unparalleled accuracy. Others are more proactive, attacking future spam based on special
characteristics or origination information. Symantec filter types include:
•
Heuristic Filters
•
URL Filters
•
Signature Filters
•
Header Filters
Heuristic Filters –
Heuristic Filters scan the headers and the body of a message, applying
a variety of tests. These tests search for tell-tale characteristics that are usually inherent in
spam, such as opt-out links, specific phrases, and forged headers. Each characteristic is
assigned a spam probability, and the message is given a cumulative probability score
based on the overall test results. If a certain probability threshold is reached, Symantec
Brightmail AntiSpam determines the message to be spam. Using heuristics, Symantec
Brightmail AntiSpam software can make the determination that a message is spam, even if
it hasn’t passed through the Probe Network. The BLOC transmits updated Heuristic Filters
as it does other AntiSpam Filters.
URL Filters –
Symantec’s URL Filters catch messages based on specific URLs found in
spam. URL-based spam is increasingly pervasive because spammers want to direct
readers to a specific Web site for contact information or purchasing instructions. Although
the underlying URLs do not change frequently, spammers attempt to obfuscate and
disguise them. As a result, these URLs appear to be unique across similar spam messages.
Содержание BRIGHTMAIL - SYM ANTISPAM AND
Страница 1: ...Symantec Brightmail AntiSpam Version 6 0 Installation Guide ...
Страница 6: ...vi Symantec Brightmail AntiSpam Table of Contents ...
Страница 20: ...Symantec Brightmail AntiSpam Overview 14 Symantec Brightmail AntiSpam Symantec Brightmail AntiSpam Overview ...
Страница 112: ...Plug Ins and Foldering 106 Symantec Brightmail AntiSpam Plug Ins and Foldering ...
Страница 150: ...144 Symantec Brightmail AntiSpam Appendix A Symantec Brightmail AntiSpam Files ...