Spamblocker; Understanding How Spamblocker Works - Watchguard Firebox X20E User Manual

Firmware version 8.6 all firebox x edge e-series standard and wireless models
Hide thumbs Also See for Firebox X20E:
Table of Contents

Advertisement

14

spamBlocker

Unwanted email, also known as spam, fills the average inbox at an astonishing rate. A large volume of
spam decreases bandwidth, degrades employee productivity, and wastes network resources. Watch-
Guard® spamBlocker™ uses industry-leading pattern detection technology from Commtouch to block
spam at your Internet gateway and keep it from getting to your email server.
You must purchase the spamBlocker upgrade to use this feature. For more information, visit the
WatchGuard LiveSecurity™ web site at
reseller.

Understanding How spamBlocker Works

There are many procedures that email filters use to find spam. Blacklists keep a list of domains that are
used by known spam sources or are open relays for spam. Content filters search for key words in the
header and body of the email. URL detection compares a list of domains used by known spam sources
to the advertised link in the body of the email. But, all of these procedures scan each individual email
message. It is easy to bypass those fixed algorithms. You can mask the sender address to bypass a
blacklist. You can change key words, embed words in an image, or use multiple languages to bypass
content filters. You can create a chain of proxies to disguise the advertised URL.
spamBlocker™ uses the Recurrent-Pattern Detection (RPD™) solution created by Commtouch®. RPD is
an innovative method that searches the Internet for spam outbreaks in real time. To see an example of
real-time spam outbreak analysis, visit the Commtouch Outbreak Monitor at
http://www.commtouch.com/Site/ResearchLab/map.asp.
RPD finds the patterns of the outbreak, not only the pattern of individual spam messages. Because it
does not use the content or header of a message, it can identify spam in any language, format, or
encoding. When RPD identifies the threat, it is classified in the Commtouch Anti-Spam Detection Cen-
ter database by the severity of the attack. spamBlocker queries this database and assigns a category to
each email message. Then it applies the action that you have configured for that category.
User Guide
http://www.watchguard.com/store
or contact your WatchGuard
185

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents