Americas

  • United States

Asia

Oceania

Heuristic Analysis: E-Mail Filtering the Garden of Good and Evil

News
Mar 01, 20032 mins
Data and Information SecurityEmail ClientsMalware

Heuristic analysis, an e-mail scanning technique that sifts through e-mail messages for the characteristics and behaviors that are unique to spam messages, may help.

Dandelions might look pretty, but they can kill an otherwise healthy lawn. The same is true of the spam that plants itself in your inbox. But heuristic analysis, an e-mail scanning technique that sifts through e-mail messages for the characteristics and behaviors that are unique to spam messages, may help.

Doug McLean, vice president of marketing at Postini, a spam filtering service, describes the spam characteristics as the “fingerprints” of spammers. They include information buried in the e-mail message header that is invisible to most e-mail recipientsinformation such as the path the e-mail took to reach its destination and the content of the message. Picking out spamlike qualities in e-mail messages is not hard to do, according to Dave Strickler, CEO of antispam service provider MailWise. “The biggest thing that people don’t realize is the amount of mistakes spammers make in the header of an e-mail message,” he says. Multiple sender addresses, grossly inaccurate time stamps and nonexistent time zone settings are just a few of the aberrations that are common in spam messages, Strickler says.

Spam signatures work the same way virus signatures do, according to McLean. Researchers look at individual e-mail messages and determine whether they are spam. Once a legitimate spam message is identified, the antispam vendor uses an algorithm to calculate a unique string of bits, or “signature,” for the spam message. The antispam software uses that signature to scan incoming messages and identify spam.

Blacklists and keywords, the other common methods of screening e-mail for spam, only give administrators the ability to block messages coming from specific addresses or domains, or containing certain words. As a result, they are less deft at picking out spam messages from legitimate e-mail traffic.

So, how can a CSO know which product and approach is best? CSOs who are looking into antispam products and services would be well served by conferring with companies that are already using the technology. For managed service providers, McLean says, the account renewal rate will tell CSOs a lot about how happy the company’s current customers are.