A apresentação está carregando. Por favor, espere

A apresentação está carregando. Por favor, espere

Filtragem Email Filtragem de Email com RedHat Linux Ruben Oliveira RHCE RHCX MCSE MCITP.

Apresentações semelhantes

Apresentação em tema: "Filtragem Email Filtragem de Email com RedHat Linux Ruben Oliveira RHCE RHCX MCSE MCITP."— Transcrição da apresentação:

1 Filtragem Filtragem de com RedHat Linux Ruben Oliveira RHCE RHCX MCSE MCITP

2 Filtragem Conteúdos RedHat Linux SMTP - Simple Mail Transfer Protocol A evolução do SPAM Spam Bad Guys DNS Block Lists SPF Sender ID DomainKeys Greylisting Pattern Rules Bayes DCC Pyzor Razor OCR AV Soluções de Segurança

3 Filtragem Linux Origins 1984: The GNU Project and the Free Software Foundation Creates open source version of UNIX utilities Creates the General Public License (GPL) 1991: Linus Torvalds Creates open source, UNIX-like kernel, released under the GPL Today: Linux kernel + GNU utilities = complete, open source, UNIX- like operating system Packaged for targeted audiences as distributions

4 Filtragem Red Hat Enterprise Linux Enterprise-targeted operating system Focused on mature open source technology month release cycle Certified with leading OEM and ISV products Purchased with one year Red Hat Network subscription and support contract Support available for seven years after release Up to 24x7 coverage plans available

5 Filtragem The Fedora Project Red Hat sponsored open source project Focused on latest open source technology Rapid four to six month release cycle Available as free download from the Internet CentOS Created from the RedHat Linux OpenSource Software No Support from RedHat Community Supported Rebranded RHEL Clone without the trademarks or RHN

6 Filtragem SMTP (Simple Mail Transfer Protocol) protocolo baseado em texto Protocolo funciona na porta 25 numa rede TCP. Simples : telnet servidor 25

7 Filtragem Exemplo de uma sessão SMTP telnet smpt.dominio.pt 25 S: 220 smtp.dominio.pt ESMTP Postfix C: HELO dominio2.pt S: 250 Hello dominio2.pt C: MAIL FROM: S: 250 Ok C: RCPT TO: S: 250 Ok C: DATA S: 354 End data with. C: Subject: Mensagem de Teste C: C: Olá. C:. S: 250 Ok: queued as C: quit S: 221 Bye

8 Filtragem

9 Qual a razão do comercial não solicitado ser conhecido como SPAM ?

10 Filtragem SPAM spiced ham famoso na 2ª guerra mundial Monty Python sketch 1970 menu

11 Filtragem The Evolution of Spam The development of spammer techniques Direct mailing –Spammers Ingénuos –Fácil de Filtrar Open Relay –Erro de configuração Zombie or bot networks - Internet popular - Updates ou Anti Virus deficientes - Utilizadores ingénuos

12 Filtragem The Evolution of Spam The development of spam content Simple text and HTML Personalised mail Random text strings Graphics or PDF

13 Filtragem Empresas de Marketing Directo Afirmam que só enviam s com o consentimento do destinatário. Como exemplo, Target, Virid, VirtualTarget, BrasilBiz, Spinletter.net

14 Filtragem Marketers Jeanne Jennings is a leading authority and independent consultant with over 15 years of experience in the and online realm. She specializes in all aspects of marketing and publishing, from strategy through design and metrics analysis. Jeanne works with medium- to enterprise- sized organizations and is expert at helping her clients become more effective and more profitable online. She is the author of "The Marketing Kit: The Ultimate Marketers Bible" (SitePoint, 2007) and publisher of "The Jennings Report," a free newsletter for online marketing professionals. Visit her online at JeanneJennings.com.

15 Filtragem march folded the wavy chestnut lock, andnot buy it back; and faith in one another madethe students pay some money for the dance? cloud of pink and white lace that lay upon have stared straight before you, utterly right, for i'm all in a tangle now with doubts then the mournful

16 Filtragem

17 The 41-count indictment, unsealed in a Detroit federal court, claims Ralsky, 52, and his fellow defendants operated a wide-ranging international fraud scheme involving millions of illegal s touting thinly-traded Chinese penny stocks. Ralsky profited by selling the stock at artificially inflated prices. Only two of the defendants appeared in court Jan. 3 for arraignment. Ralsky is reportedly at large in Europe. According to the indictment, Ralsky and his group earned approximately $3 million on the scheme during the summer of Ralsky faces charges including conspiracy, fraud in connection with electronic mail, computer fraud, mail fraud, wire fraud and money laundering. The illegal practices cited in the indictment include evading spam- blocking devices, falsifying headers and domain names, using proxy computers to distribute the spam and misrepresenting the advertising content in the actual .

18 Filtragem Inside the "Ron Paul" Spam Botnet SecureWorks would like to thank our colleagues at myNetWatchman, IronPort and Spamhaus for their invaluable assistance in the investigation of this botnet. Tracking the Spam headers vary but some static elements The Reactor Core written in the Python language. Examining these showed that the Srizbi botnet is actually a working component of a piece of spamware known as Reactor Mailer. Reactor Mailer has been around at least since 2004, and is in its third major version. It was created along with Srizbi, the bot that actually does the mailing. Reactor Mailer is the brainchild of a spammer who goes by the pseudonym spm. He calls his company Elphisoft, and has even been interviewed about his operation by the Russian hacker website xakep.ru.

19 Filtragem

20 Spamit is the alternate name for the Glavmed sponsorship, responsible for lots of illegal spamming of Canadian Pharmacy and US Pharmacy websites.Glavmed Canadian PharmacyUS Pharmacy Following the same example as SanCash and GenBucks, this follows the pattern of having a public- facing, wide-open entity (ie: GenBucks / Glavmed) which makes no mention of spamming, or hijacking of servers, coupled with a very secretive, underground Affiliate program (ie: SanCash / Spamit) which is invitation only, password protected, and never mentioned anywhere in public, via any means.SanCashGenBucks

21 Filtragem


23 Dark Mailer 84 What is ROKSO? The Register of Known Spam Operations (ROKSO) is a register of spam senders and spam services that have been thrown off Internet Service Providers 3 times or more in connection with spamming or providing spam services, and are therefore repeat offenders. Spamhaus believes that these known determined professional spam operations are responsible for approximately 80% of spam on the Internet.

24 Filtragem Planeamento e Gestão da Filtragem de –Filtragem de conexões –Filtragem por análise de conteúdo

25 Filtragem DNSBL DNS Block List Spamhaus Zen SBL XBL PBL identificam IPs que foram usados para envio de SPAM alvo de tentativas de DoS

26 Filtragem

27 * PSBL (psbl.surriel.com) * FIVETEN (blackholes.five-ten-sg.com) * ZEN (zen.spamhaus.org) * APEWS (www.apews.org) * SORBS (dnsbl.sorbs.net) * Spamcop (bl.spamcop.net) * CBL (cbl.abuseat.org) * korea.services.net * UBL (ubl.unsubscore.com)

28 Filtragem Sender Policy Framework ou "Estrutura de Politicas de Remetente" Para que Serve ? Identificar os servidores legítimos que podem enviar de um domínio. Como se configura ? No servidor de DNS num record TXT Ex: IN TXT "v=spf1 mx -all" todos os MX do dominio são os únicos que devem enviar Cabe ao servidor receptor a recusa ou não de processar o

29 Filtragem Sender ID Patrocinado pela Microsoft semelhante ao Sender Policy Framework Purported Responsible Address

30 Filtragem DomainKeys Yahoo When the recipient gets the message, they'll be able to: verify the domain name of the sender. confirm the message content hasn't been altered. match the "from" address to the sender's domain name to prevent forgeries. trace the message back to the sender's domain name.

31 Filtragem Greylisting Temporáriamente rejeita mensagem Vantagens Fácil implementar Pouco CPU comparado com outras técnicas Desvantagens O primeiro pode demorar SMTP, Instant Messaging, Push Mail

32 Filtragem Regras Spamassassin body LOCAL_DEMONSTRATION_RULE /test/ score LOCAL_DEMONSTRATION_RULE 0.1 describe LOCAL_DEMONSTRATION_RULE This is a simple test rule header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i score LOCAL_DEMONSTRATION_SUBJECT 0.1

33 Filtragem Bayesian classifier analisa conteúdos que lhe indicam como legitimo ou spam e aprende

34 Filtragem Distributed signature systems Pyzor Razor DCC

35 Filtragem OCR Fácil Instalar Motores OCR gratuitos: gocr,ocrad CPU intensive HTML table slice

36 Filtragem AntiVirus Free Clamav BitDefender MailScanner Supported # sophos from or # mcafee from or # command from or # bitdefender from or # drweb from or # kaspersky from or # etrust from or # inoculate from or # inoculan from ftp.ca.com/pub/getbbs/linux.eng/inoctar.LINUX.Z, or # nod32 for No32 before version 1.99 from or # f-secure from or # f-prot from or # panda from or # rav from or # antivir from or # clamav from or # trend from or # norman from or # css from or # avg from or # vexira from or # symscanengine from (Symantec Scan Engine, not CSS)

37 Filtragem Exchange Anti-Spam : Sender ID IMF Inteligent Message Filtering * Content Filtering * IP Allow and Block List Provider * Sender Filtering * Sender Reputation * SMTP Tarpiting

38 Filtragem Forefront Security

39 Filtragem Soluções Anti Spam Comerciais Sonicwall grupo Rumos GFI MailEssential Barracuda IPBrick EdgeBox AnubisNetwork

40 Filtragem Spam will be a thing of the past in two years' time, Microsoft boss Bill Gates has promised. January 2004

41 Filtragem Organizações que combatem o spam Cauce (coallition against unsolicited commercial )

42 Filtragem Concluindo, NENHUMA técnica anti-spam funciona bem sozinha. Os spammers estão sempre a inovar as suas técnicas, e precisamos modernizar as nossas proprias técnicas de bloqueio. Serviço tem importância vital na maioria das empresas. O Spam pode ser reduzido a um mínimo aceitável. Actualização Constante ! No software já usado e com implementação de novas tecnologias.

43 Filtragem Cursos: RH033 Red Hat Linux Essentials RH133 Red Hat Linux System Administration RH253 Red Hat Linux Network Services and Security Administration

44 Filtragem Obrigado Coffee Break Case Study I - PT Inovação Case Study II - Divultec

Carregar ppt "Filtragem Email Filtragem de Email com RedHat Linux Ruben Oliveira RHCE RHCX MCSE MCITP."

Apresentações semelhantes

Anúncios Google