Keeping Spam Out of Your E-Mail
|
Spam is a major issue at every large organization. The university is no exception. UC has a solution in place to protect us all from the majority of spam messages, but for the solution to be most effective, you need do something on your side as well.
UC's spam filter scans all incoming e-mail messages and tags each with a score from 0 to 300, indicating how likely it is that the message is spam. The system removes items with score of 300; that mail never reaches your e-mail inbox. Items that score in an intermediate range, between 50 and 299, are "most likely" spam, but are not removed as there is a chance they are legitimate.
You can set up a filter in your local e-mail client send the "probably spam, but maybe not" messages to a junk mail folder. Having spent about five minutes to set up a filter, you should notice an immediate reduction in the amount of arriving spam. Periodically, go through your junk mail folder to move any legitimate messages to your inbox, and empty out the junk mail folder.
Our good friends in the Information Security department have created step-by-step instructions for setting up spam filters.
For more technical details on the spam-blocking technologies we employ, here, please read on. |
What is Spam?Spam is unsolicited commercial e-mail or unsolicited bulk e-mail. Typically, a spammer buys or steals lists of e-mail addresses, or harvests the addresses from the Internet. If your e-mail address appears in a newsgroup, a Web site, a chat room, or in an online membership directory, it may find its way onto these lists. The spammer then uses software to send thousands or millions of messages. Gartner Inc., a consulting and research firm, has identified four types of spam, with the first two accounting for 25% of the e-mail messages on the Internet through 2002:
- Pure-trash spam (e.g., fraudulent schemes, invalid senders, ads from porn Web sites, etc.)
- Chain letters, urban legends, and hoaxes
- Honest individuals or businesses trying to make a living ("junk mail")
- Occupational spam from colleagues (e.g., from Listservs)
What is E-Mail Spoofing?E-Mail spoofing is the deliberate forging of a sender's e-mail address. The culprit pretends to be another person you may know or uses a name you may trust, for example: @UC.Edu.
What are Phishing and Pharming?
Phishing attacks use spoofed e-mails and fraudulent Web sites designed to fool recipients into divulging personal financial data such as credit card numbers, account usernames and passwords, and social security numbers.
Pharming uses the same kind of spoofed sites, but uses spyware to redirect users from real Web sites to the fraudulent sites, typically DNS-hijacking. By hijacking the trusted brands of well-known banks, online retailers, and credit card companies, phishers are able to convince unwary recipients to respond to them.
What Should I Do When I Receive Spam E-mail?
- Delete the spam e-mail.
- Do not send an unsubscribe message to the e-mail sender. Pure-trash spammers use this to confirm the validity of an e-mail address.
- Refrain from clicking on any links. Clicking on web links may expose your computer to a virus.
What Can I Do to Avoid Receiving Spam E-mail?
- Never reply to spam.
- Often, spam will have a "remove me" link. Complying with this action may confirm that yours is an active address.
- The "From:" address may be spoofed or forged so replying to the originator will not work.
- Be very cautious about displaying your e-mail address in newsgroups, chat rooms, Web sites or online directories. Think carefully before you post to a Usenet newsgroup. Subscribe only to essential discussion lists, and ensure that they are moderated.
- If you are thinking of filling out a form on a Web site, check the site's privacy policy first to be sure it uses secure technology and the company does not share your e-mail address with others. If the site doesn't have a privacy policy that describes this to your satisfaction, consider not using that service.
- Learn how to filter junk and adult content e-mail. Each e-mail client has its own filtering processes. These processes usually include an automated filtering process maintained by the client itself or a user-specified filtering process where the user defines the filtering rules. Also, most e-mail clients have options for creating lists of blocked senders and safe senders to control messages at a very personal level. Check Help for your e-mail client or contact the UCit Help Desk at 556-HELP for instructions on setting up filters or tips on managing junkmail with your e-mail client.
Laws Governing Spam
The US Federal Government and the State of Ohio have introduced laws to regulate the transmission of e-mail advertisements.
What Is UCit Doing To Protect Users From Spam E-mail?95% of all spam coming into the university is being detected by some aspect of UCit's anti-spam monitoring.
If you use the Internet, you will get some unsolicited e-mail. Users have asked UCit to do something to control spam. We have introduced spam control on several fronts. The story of the Virus and Spam Detection devices that are used to combat spam at the University is told through the University Incoming Email Messages Virus and Spam Detection chart. Which spam detection devices block the most spam? What percentage of incoming messages are dropped? What percentage of incoming messages are delivered to your e-mail box? You can find the answers to these questions in the information presented here.
42% of all university e-mail messages are detected as spam by rapid anti-spam and as a result are dropped.
In August 2005, UCit E-mail Services contracted with the vendor of the Bearcat Online system for a state-of-the-art, spam control system known as Rapid Anti-Spam. This system monitors all e-mail coming into the University, and based on a sophisticated analytical method, tags message headers with scores from 0 to 300, indicating the probability of the message being spam. Any e-mail message scored at 300 is decidedly spam. All messages with this score are dropped, preventing a large percentage of spam from reaching the mailboxes of University e-mail users.
- Spam Alert Services (RBL Drops)
5% of all university e-mail messages are detected as spam by these spam alert services and as a result are dropped.
UCit has subscribed to two spam alert services known as Spamhaus and SpamCop. Both services track the Internet's Spammers, Spam Gangs, and Spam Services, providing dependable real-time anti-spam protection for Internet networks. They both work with Law Enforcement to identify and pursue spammers worldwide. Specifically, these services identify and tag any e-mail that comes from an IP address listed on an RBL, a Realtime Blackhole List. Spamhaus and SpamCop maintain these lists of IP addresses whose owners refuse to stop the proliferation of spam.
UCit deployed the Spamhaus spam management solution in September 2004. At that time, we intended for each user to filter the RBL-tagged e-mail using published filtering instructions. However, in December 2004, it became necessary for UCit to block RBL-tagged messages deemed as spam from entering the university e-mail system. This move prevents spam from reaching university e-mail boxes for all users.
UCit decided to block RBL-tagged messages because of escalating numbers of spam messages, which ranged from 30,000 to 500,000 per day. Users saw the effects of this in network slowdowns and even brief stoppages. UCit took this action to address these attacks and prevent the crippling of our e-mail systems.
In an effort to block even more spam, UCit E-mail Services implemented a second spam alert service, SpamCop, in early Summer 2005.
2% of the university's e-mail messages are detected as spam by UCit-maintained lists of reported spam and are dropped from the delivery queues.
Over time, as University faculty, staff, and students have reported spam, UCit has maintained lists of servers that are responsible for sending spam and subject lines for messages that are known spam. UCit blocks any IP where spamming has been reported if there have been at least twenty complaints about a particular spammer and if we are provided with the original Internet Headers. Specifically, UCit can do the following:
- Contact the ISP hosting the account and lodge a formal complaint.
- Initiate a block on the spammer's "From:" address. (Usually the header is forged and will change.)
- Initiate a block on the corresponding IP address of the system from which the spam originated.
- Initiate a block on the domain (multiple IPs) from which the spam originated. Please Note: The blocking of IP addresses and domains can result in the blocking of legitimate mail and is used only in extreme circumstances.
Now, with the improvements made by the implementation of other spam control devices, these lists are becoming less and less important, but they are still effective in catching some level of spam at the university. Because the reports came from university constituents, these messages have always been dropped. This practice continues, although it is hoped that other spam control efforts will eventually replace this level of service.
Another 15-20% of your spam can be controlled through the use of filters set up in your e-mail client.
The Rapid Anti-Spam product provides another spam control device in addition to indicating what spam can be dropped. Because this product scores any message that has the potential of being spam, any message with a score from 50-299 is also tagged with a UCE (Unsolicited Commercial E-mail) score. This tag gives an individual e-mail user the option of managing spam by setting up a filter in his or her e-mail client. After defining a folder for spam, the user can have messages moved to the spam folder by setting up a simple filter. The user can then review messages that were moved to the spam folder, verifying that all of them are spam and none of the messages are needed.
Instructions on how to set up these filters are included in Setting up Filters for Spam Tagged by Rapid Anti-Spam.
- Controls University Spammers
UCit disconnects service to any computer on the UC network that sends out spam.
- Protects UC LISTSERV from Spam
When the LISTSERV determines that a message is spam, it locks out the sender for 48 hours, during which the user is still able to use the LISTSERV normally and to post to mailing lists, but all messages are forwarded to the list owners for human verification. UCit informs the user that this has occurred.
- Investigates Spam Services
UCit works with software vendors and explores any new services that could help manage spam for university e-mail users. As new solutions are available, they will be researched and, where appropriate, implemented.
Spam Control
Do not expect that even the combination of all these anti-spam services will catch all spam. The nature of spam makes it impossible for any anti-spam engine to be current all the time. Three circumstances where spam can get past the spam detection devices are when:
- a spammer constantly moves operations from one server to another
- for short periods of time, the spammer uses "legitimate" services servers for spam mailings, and
- a spammer sends spam in small batches (disguising bulk mailing)
Spam control is ever-changing. Spammers are always trying to slip under the anti-spam devices by changing their operations. Spam slips through the spam control products, vendors investigate, change their product or service, and the services catch it the next time. Conversely, spam that was caught one time might not be caught the next. UCit is confident that legitimate e-mail is not being blocked as a result of any of the above-described actions.
False Positives
Because some spammers send spam by using legitimate services servers for short periods of time, there is a chance that you will have e-mail falsely detected as spam. This results in what is known as a false positive. If you elect to set up additional spam filters within your mail client, you are advised to review your junk-mail folder periodically to assure that legitimate e-mail has not been filtered.
Questions about Spam
If you have questions, please send e-mail to the UCit Help Desk or call the Help Desk at 556-HELP. Here are some additional links to more information on fighting spam:
SpamCon Foundation
Spamhaus
SpamCop
Anti-Phishing Work Group
US Department of Justice report on Phishing
Network Abuse Clearinghouse
Public Access Network Communications
Reporting Spam "Boilerplate" Memos
Where to Send your Spam Complaints
How to Complain to the Spammer's Provider
How to Find Internet Headers to Include with a Spam Complaint
Some of the information in this communication is adapted from information provided by colleagues at Indiana University and is used here with their permission.
|