Exchange deployment at CERN and new ideas for SPAM fighting Michel Christaller, Emmanuel Ormancey, Alberto Pace.

Slides:



Advertisements
Similar presentations
K12 WebMail
Advertisements

Anti-SPAM experience at LAL Michel Jouvin LAL / IN2P3
Working with Outlook 2007 at CERN Outlook Main window Customize views Send s Organize s: Category, Follow-up flag, To-Do Bar Create signatures.
How to Use Stowe School District
A new Mailing List infrastructure at CERN Ruben Gaspar Aparicio Michel Christaller & Ruben Leivas Ledo IT - Internet Services Group CERN.
Basic Communication on the Internet:
Outlook 2010 Quick Guide Table of Contents: Overview of client, Sending/Receiving , Using the address book………..……… Sent Items……………………………………………………………………………………………..…..8.
Module 6 Implementing Messaging Security. Module Overview Deploying Edge Transport Servers Deploying an Antivirus Solution Configuring an Anti-Spam Solution.
CERN - European Organization for Nuclear Research Exchange 2000 Pilot at CERN HEPiX-HEPNT Fermilab, October 2002 Frédéric Hemmer Frédéric Hemmer – CERN.
Page 1 of 29 Net-Scale Technologies, Inc. Network Based Personal Information and Messaging Services Urs Muller Beat Flepp
IMF Mihály Andó IT-IS 6 November Mihály Andó 2 / 11 6 November 2006 What is IMF? ­ Intelligent Message Filter ­ provides server-side message filtering,
Exchange 2003 and SPAM Fighting Emmanuel Ormancey, Rafal Otto Internet Services Group Department of Information Technology CERN 3 June 2015.
Lesson 7: Business, , & Personal Information Management
XP Browser and Basics1. XP Browser and Basics2 Learn about Web browser software and Web pages The Web is a collection of files that reside.
Staff Computer Training Exchange 2003: More User Friendly Vicki Hecht Cherry Delaney ITaP Luncheon October 14, 2003.
Collaborative tools in NICE Alex Lossent - CERN IT/IS Hepix Fall 2005.
Exchange server Mail system Four components Mail user agent (MUA) to read and compose mail Mail transport agent (MTA) route messages Delivery agent.
Introduction to UTORexchange For IT support providers.
Guide to Operating System Security Chapter 10 Security.
POP Configuration Microsoft Outlook Express 6.x.
Exchange 2010 Overview Name Title Group. What You Tell Us Communication overload Globally distributed customers and partners High cost of communications.
Pro Exchange SPAM Filter An Exchange 2000 based spam filtering solution.
23 October 2002Emmanuel Ormancey1 Spam Filtering at CERN Emmanuel Ormancey - 23 October 2002.
How to Get The Most Out of Outlook 2003 Michele Schwartzman Division of Customer Support Summer 2006.
POP Configuration Microsoft Outlook What is POP? Short for Post Office Protocol, a protocol used to retrieve from a mail server. Most.
Outlook Web Access (OWA) is a web mail service of Microsoft Exchange; allow users to connect remotely via a Web browser OWA is used to access ,
CT NIKHEF Nov Mail NIKHEF CT system support.
Remote Assistance  Using this program you can allow someone to work on your computer, chat with you and view your screen with your permission  The other.
» Explain the way that electronic mail ( ) works » Configure an client » Identify message components » Create and send messages.
1 Outlook Live Live Messenger SkyDrive Office Live Live Spaces Live Groups.
Securing Exchange Server Session Goals: Introduce you to the concepts and mechanisms for securing Exchange Examine the techniques and tools.
CensorNet Ltd An introduction to CensorNet Mailsafe Presented by: XXXXXXXX Product Manager Tel: XXXXXXXXXXXXX.
Chapter 7: Using Windows Servers to Share Information.
SCO Insight Connector Training. The SCO Insight Connector  Product Overview  Technical Specifications  Installation  Using the Components  Target.
Backup Local Online For secure offsite storage of your , and making it available from any computer or smart phone. Backup accessed with.
Module 8: Managing Client Configuration and Connectivity.
Masud Hasan Secue VS Hushmail Project 2.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Module 6: Manage and Configure Messaging. Configuring Internet Mail Using Small Business Server (SBS) 2008 Console Configuring Protection Configuring.
-III Outlook How To Topics CS-3505 Outlook form Office 2003 Wb_ -II.ppt.
Microsoft Outlook 2007 Basics Distance Learning (860) 343 – 5756 Chapman 633/632 Middlesex Community College Visit
(or ?) Short for Electronic Mail The transmission of messages over networks.
By: Bill Stevenson Jose Plancarte Erik Magsino. Overview Messaging and collaboration server Send and Receive electronic mail and other forms of interactive.
The Internet 8th Edition Tutorial 2 Basic Communication on the Internet: .
Module 6 Planning and Deploying Messaging Security.
1 SCOoffice Server for OpenServer Technical Overview.
advantages The system is nearly universal because anyone who can access the Internet has an address. is fast because messages.
Microsoft Office Outlook 2013 Microsoft Office Outlook 2013 Courseware # 3252 Lesson 6: Organizing Information.
1 Adding Secure and Collaboration to Your Business with SCOoffice Server 4.1.
Update on  Mail Gateways  Servers  Spam Tagging  Anti-Virus  IMAP  Web Mail  LISTSERV  POP.
Outlook 2003 Quick Guide Table of Contents: Overview of client, Sending/Receiving , Using the address book………..……… Sent Items………………………………………………………………………………………………..4-5.
Status of Exchange deployment Alberto Pace for the IT/IS group Desktop Forum, April 3 rd 2003.
«Fly Carrier» agent software Optimization of data transmission over IP satellite networks.
NetTech Solutions Troubleshooting Office Applications Lesson Seven.
Outlook Web Access (OWA) is a web mail service of Microsoft Exchange; allow users to connect remotely via a Web browser OWA is used to access ,
A Quick Look At How Works Understanding the basics of how works can make life a lot easier for any user. Especially those who are interested.
XP New Perspectives on Microsoft Windows XP Tutorial 5 1 Microsoft Windows XP Bringing the World Wide Web to the Desktop Tutorial 5.
Plan for the Exchange 2000 Deployment Proposal Desktop Forum IT/IS 30/10/02.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
11 MICROSOFT OFFICE OUTLOOK 2003 AND MICROSOFT OUTLOOK EXPRESS Chapter 4.
CERN - IT Department CH-1211 Genève 23 Switzerland t OIS Update on the anti spam system at CERN Pawel Grzywaczewski, CERN IT/OIS HEPIX fall.
The New CERN Mail Services Information for group Administrators Alberto Pace for the Internet Service Group and the Mail Migration Task Force.
A leap ahead... Darren Kearney Don Miller Ilya Pinchuk.
[1] Control Spam by the Use of Greylisting Torgny Hallenmark LDC - Computing Center Lund University, Sweden TERENA Networking.
Outlook / Exchange Training. Outlook / Exchange: Agenda What Can Microsoft Exchange Do / How works at UST? and Inbox Mailbox Quota Archiving.
TMG Client Protection 6NPS – Session 7.
Internet Business Associate v2.0
Emmanuel Ormancey - Michel Christaller
HEPiX-HEPNT Fermilab, October 2002
Spam Fighting at CERN 12 January 2019 Emmanuel Ormancey.
Presentation transcript:

Exchange deployment at CERN and new ideas for SPAM fighting Michel Christaller, Emmanuel Ormancey, Alberto Pace

CERN Mail infrastructure  14 Servers  8 “Mailbox” stores, 2 Public Folder Stores, 2 Front-end servers, 2 Spare  IMAP (secure), POP (secure), MAPI and secure HTTP  MAPI with Outlook on Windows/Mac  MAPI open (in theory) outside CERN using Microsoft ISA Server  IMAP and POP work with almost any client  HTTP works with any Web browser  Collaborative tools available with MAPI and HTTP  Office XP recommended for collaborative features  Not possible to switch Outlook 2000 from IMO to CW  Allows multi protocol (pop, imap, mapi, webdav)  All information stored at server level, no more PST file problems  Office 2003 being evaluated  MAPI over HTTP  Seamless connected/disconnected/online/offline feature  Optimized for slow network connections

Migration overview  Nothing changes for the user Legacy Server New Server user.mailbox.cern.ch Mail Server Mail Client Mail User The server is replaced, Nothing changes for the client Additional interfaces available imap mapi http imaps pops webdav

Migration: what is done  User are invited to migrate by filling a migration form  The password is kept on the new service and synchronized with the windows password  Unresponsive users are forced to migrate and the password is reset  All folders and mails are copied from the old servers to Exchange  Mail Forwarding configuration is kept if any  Mailbox is not functional during at most 10 minutes, while rebuilding configuration files

Migration Workflow Migration Form Mailbox migrated Keep password typed in migration form Nice and Mail password synchronized Mailbox migrated Password reset Nice and Mail password synchronized “Ask for migration” mail Accept / Delay Form Reminder Mail (3) Accept After n reminders Force migration No answer Click on link

Migration Status  Exchange Users, Total  Only inactive and a few “non cooperative” users remaining  Cleanup: More than 700 Mail accounts deleted following user approval

Current status  1 year of production  Exchange software stable and scalable  No major disaster, only normal hardware failures, solved in operational delays  Usage: 50 % Outlook XP, other 50 % with IMAP, POP and HTTP access  1’000’000 Incoming mails per week, 30% is Spam

Next step, currently in test  Move SMTP Gateways to Exchange  Implement automatic anti flood system  Any server, sender or recipient sending or receiving more than 500 mails in 5 minutes will be banned (numbers to define)  Only solution to improve quality of service, and reduce impact of loops on “regular” mails  Migrate Mailing lists system from majordomo to Exchange  You will hear about this next year

Spam Fighting at Cern Evolution

Legacy system  Sendmail checks:  Lists of banned IP addresses, domains, subject, senders or recipients, and words  Header “consistency” tests (i.e. message id format)  Mail rejected if identified as Spam  Heavy manual work:  Update local banned lists from abuse reports  Remove entries when users report false positive rejections

Current service  Existing market products were reviewed:  Technology too young  Results are not accurate  Missing a per user basis configuration  While the market consolidates …  CERN developed his own Anti-Spam filter  Based on SpamAssassin  Less effort than running after immature commercial technology  Now in production for 1 year  Easy to modify and update detection techniques

How it works  The anti-spam filter calculates the probability for a message to be spam  Regular expressions  “Intelligent” content parsing  Statistical heuristics (Bayesian Filters)  The user sets the threshold at which he wants spam to be rejected  Rejected message can be seen by the user (CERN Spam folder)  Per user configuration (!)  Allows rejection of foreign languages mail (Chinese, Korean, Russian, Japanese, Arabic, etc …)

User configuration Filtering level Language-based rejection

Efficiency  Roughly Incoming mails per day  Spam filter detects from 25% to 35% as spam

Efficiency  False positives are very low  Except for commercial lists (spam that you want)  White lists at user level can be configured to prevent this  Good spam detection  Statistics are hard to build  Standard mailbox filtering statistics:  30 to 40 Spams filtered per day  1 or 2 Spams still go to the INBOX per week  Could still be improved with some optimization  Not enough for some users with “public” address  Old address or published address are more targeted for Spam

Current evolution  Spammer techniques always follow anti-spam techniques  New detection mechanisms work only for a few months  Needs a full time work to have a constantly “up- to-date” filter  Only viable long term solution is to accept only mails from people you know:  ICQ (and other messenger systems) already have this feature  Accept only messages from people in my contact list  Adding someone to the contact list requires validation

New feature (in test)  Good Mails not matching the user’s white list are quarantined  Mail is sent to sender requiring action to validate himself  Once validated, sender is added to white list, mails are moved back to Inbox Move to Inbox.Quarantine Quarantine level Inbox Move to Cern Spam Delete Spam Filter level Delete if evident spam level Mail to sender for validation

What’s next ?  Join forces against Spam  Share rules, regular expressions patterns and Bayesian statistics dictionary with other organizations  Central antispam configuration with Live Update like antivirus definitions is the solution. Therefore …  Long term goal: use a commercial product  Like for antivirus products, only a full time working team will provide up-to-date filters

In addition …  Within Exchange, mail is authenticated  Not possible to forge To: or From: fields  Delivery and Read receipts are reliable  A platform for workflow application  Extend this towards the internet  Mail messages digitally signed with guaranteed origin and dates  (See my presentation on PKI this Thursday)

Conclusion  Users are profiting from the new collaborative services  Shared calendar (already used by 1500 accounts)  Tasks, workflow  Web and webdav interfaces  Spam is a serious issue  Towards accepting only authenticated/verified mail  There is a future for commercial products in this area