Title: RedIRIS Reputation Block List
1RedIRIS Reputation Block List
2RedIRIS and mail services
- At the beginning, RedIRIS was directly involved
in the direct provision of e-mail services to
affiliated institutions - However, several years ago it stopped providing
those services (including webmail) - End of life cycle within NREN commodity
services provided by the institutions and the
market - RedIRIS has kept working on issues related to
e-mail, but mostly trying to improve its quality
and to fight against spam - RACE (audit of University mail configuration,
coordinated by RedIRIS and done by peers) - Promotion of security policies (e.g.,
SPF,DKIM,BATV) - Whitelists, spamtraps
- These initiatives were well received, but it was
necessary to bring them further to have a real
impact - Ideas obtained from TF-LCPM (spam filtering
services offered by SURFnet and UNINETT, and
presented at TF-LCPM meetings)
3Spam evolution
4Zombies
Data Email Threats Trend Report October
2007. Commtouch
Zombies are main origin of spam
Block SMTP zombies
Less spam
Identification of zombies
Warnings about IP zombies
5Criteria for a reputation system
6Reputation scheme
?
University
Sends spam to University
IP
DNS query Is IP in the zone?
Sends spam to spamtraps
exclusion
RedIRIS whitelist
Updates in real time
rsync
IRISRBL Servicio AntiSpam Red Académica
RedIRIS spamtraps
External sources CBL, SORBS, Spamhaus,Sophos
7Service Model
- Need to integrate several sources
- RedIRIS internal sources such as spamtraps are
statistically very effective, but they cover a
very limited part of the zone - It is necessary to add external databases
8Trial
9Survey (1)
We did a survey to collect information about
use of RBL in RedIRIS institution
10Survey (2)
Answers from 65 Institutions
82 willing to use RedIRISRBL 84 use
Whitelist 78 has SPF record
74 use RBLs 80 block
11What next
- Service on trial using RKS developed with
Sandvine - 50 institutions trying it
- 15 millions queries per day
- Positive feedback
- Need to increase information in the system
collective purchase of licence of commercial
providers? - First stage to gain confidence from users and
then upgrade the service? - Evaluation towards new model of service similar
to those of Surfnet and Nordunet
12Thanks for your attention!