RedIRIS Reputation Block List - PowerPoint PPT Presentation

About This Presentation
Title:

RedIRIS Reputation Block List

Description:

RedIRIS Reputation Block List – PowerPoint PPT presentation

Number of Views:22
Avg rating:3.0/5.0
Slides: 13
Provided by: josmanuelp
Category:

less

Transcript and Presenter's Notes

Title: RedIRIS Reputation Block List


1
RedIRIS Reputation Block List
  • September 2008

2
RedIRIS and mail services
  • At the beginning, RedIRIS was directly involved
    in the direct provision of e-mail services to
    affiliated institutions
  • However, several years ago it stopped providing
    those services (including webmail)
  • End of life cycle within NREN commodity
    services provided by the institutions and the
    market
  • RedIRIS has kept working on issues related to
    e-mail, but mostly trying to improve its quality
    and to fight against spam
  • RACE (audit of University mail configuration,
    coordinated by RedIRIS and done by peers)
  • Promotion of security policies (e.g.,
    SPF,DKIM,BATV)
  • Whitelists, spamtraps
  • These initiatives were well received, but it was
    necessary to bring them further to have a real
    impact
  • Ideas obtained from TF-LCPM (spam filtering
    services offered by SURFnet and UNINETT, and
    presented at TF-LCPM meetings)

3
Spam evolution
4
Zombies
Data Email Threats Trend Report October
2007. Commtouch
Zombies are main origin of spam
Block SMTP zombies
Less spam
Identification of zombies
Warnings about IP zombies
5
Criteria for a reputation system
6
Reputation scheme
?
University
Sends spam to University
IP
DNS query Is IP in the zone?
Sends spam to spamtraps
exclusion
RedIRIS whitelist
Updates in real time
rsync
IRISRBL Servicio AntiSpam Red Académica
RedIRIS spamtraps
External sources CBL, SORBS, Spamhaus,Sophos
7
Service Model
  • Need to integrate several sources
  • RedIRIS internal sources such as spamtraps are
    statistically very effective, but they cover a
    very limited part of the zone
  • It is necessary to add external databases

8
Trial
  • University of Zaragoza

9
Survey (1)
We did a survey to collect information about
use of RBL in RedIRIS institution
10
Survey (2)
Answers from 65 Institutions
82 willing to use RedIRISRBL 84 use
Whitelist 78 has SPF record
74 use RBLs 80 block
11
What next
  • Service on trial using RKS developed with
    Sandvine
  • 50 institutions trying it
  • 15 millions queries per day
  • Positive feedback
  • Need to increase information in the system
    collective purchase of licence of commercial
    providers?
  • First stage to gain confidence from users and
    then upgrade the service?
  • Evaluation towards new model of service similar
    to those of Surfnet and Nordunet

12
Thanks for your attention!
Write a Comment
User Comments (0)
About PowerShow.com