|
1
|
- Using What You Already Have
|
|
2
|
- Critical Path Project Internet Services
McAfee Secure Content Management Appliance (SCM 3300)
- Using Spam Scoring for:
- Web-Based Email Filtering
- Microsoft Outlook Rules
- Your Brains!
|
|
3
|
- SCM 3300 is a device created by McAfee, a company that also makes
Anti-Virus software.
- SCM 3300 looks at every email and applies a series of rules to the
email.
- These rules give each email a score.
|
|
4
|
- From: American Life Direct
<insurance@feverpaceb.com>
- Subject: [possible spam] World's Fastest Life Insurance Policy - No
Medical Exams
- To: pierce@CritPath.Org
- Date: Wed, 29 Sep 2004 12:35:12 EST
- X-NAI-Spam-Score: 17.9
- X-NAI-Spam-Level: *****************
- X-NAI-Spam-Report: 12 Rules triggered
- * 4.8 -- NAI_BAD_URI -- URI:
NAI_BAD_URI
- * 4.1 -- BAYES_99 -- BODY:
Bayesian spam probability is 99 to 100% [scor
- * 3.7 -- SUBJ_LIFE_INSURANCE
-- Subject includes life insurance
- * 2.7 -- HTML_40_50 -- BODY:
Message is 40% to 50% HTML
- * 2.6 --
HTTP_WITH_EMAIL_IN_URL -- URI: remove' URL contains an email ad
- * -1.5 -- CLICK_BELOW -- Asks
you to click below
- * 1.1 -- HTML_MIME_NO_HTML_TAG
-- "HTML-only message, but there is no HT
- * 1.1 -- MIME_HTML_ONLY --
BODY: Message only has text/html MIME parts
- * -1.0 -- HTML_LINK_CLICK_HERE
-- BODY: HTML link text says click here
- * 0.3 -- HTML_FONT_INVISIBLE
-- BODY: HTML font color is same as backgro
- * 0.1 -- HTML_MESSAGE -- BODY:
HTML included in message
- * -0.0 -- HTML_WEB_BUGS --
BODY: Image tag intended to identify you
|
|
5
|
- From: American Life Direct
<insurance@feverpaceb.com>
- Subject: [possible spam] World's Fastest Life Insurance Policy - No
Medical Exams
- To: pierce@CritPath.Org
- Date: Wed, 29 Sep 2004 12:35:12 EST
- X-NAI-Spam-Score: 17.9
- X-NAI-Spam-Level: *****************
- X-NAI-Spam-Report: 12 Rules triggered
- * 4.8 -- NAI_BAD_URI -- URI:
NAI_BAD_URI
- * 4.1 -- BAYES_99 -- BODY:
Bayesian spam probability is 99 to 100% [scor
- * 3.7 -- SUBJ_LIFE_INSURANCE
-- Subject includes life insurance
- * 2.7 -- HTML_40_50 -- BODY:
Message is 40% to 50% HTML
- * 2.6 --
HTTP_WITH_EMAIL_IN_URL -- URI: remove' URL contains an email ad
- * -1.5 -- CLICK_BELOW -- Asks
you to click below
- * 1.1 -- HTML_MIME_NO_HTML_TAG
-- "HTML-only message, but there is no HT
- * 1.1 -- MIME_HTML_ONLY --
BODY: Message only has text/html MIME parts
- * -1.0 -- HTML_LINK_CLICK_HERE
-- BODY: HTML link text says click here
- * 0.3 -- HTML_FONT_INVISIBLE
-- BODY: HTML font color is same as backgro
- * 0.1 -- HTML_MESSAGE -- BODY:
HTML included in message
- * -0.0 -- HTML_WEB_BUGS --
BODY: Image tag intended to identify you
|
|
6
|
- If enough rules are ‘broken’ the email gets the phrase [possible spam]
added to the Subject line
|
|
7
|
- From: American Life Direct
<insurance@feverpaceb.com>
- Subject: [possible spam] World's Fastest Life Insurance Policy - No
Medical Exams
- To: pierce@CritPath.Org
- Date: Wed, 29 Sep 2004 12:35:12 EST
- X-NAI-Spam-Score: 17.9
- X-NAI-Spam-Level: *****************
- X-NAI-Spam-Report: 12 Rules triggered
- * 4.8 -- NAI_BAD_URI -- URI:
NAI_BAD_URI
- * 4.1 -- BAYES_99 -- BODY:
Bayesian spam probability is 99 to 100% [scor
- * 3.7 -- SUBJ_LIFE_INSURANCE
-- Subject includes life insurance
- * 2.7 -- HTML_40_50 -- BODY:
Message is 40% to 50% HTML
- * 2.6 --
HTTP_WITH_EMAIL_IN_URL -- URI: remove' URL contains an email ad
- * -1.5 -- CLICK_BELOW -- Asks
you to click below
- * 1.1 -- HTML_MIME_NO_HTML_TAG
-- "HTML-only message, but there is no HT
- * 1.1 -- MIME_HTML_ONLY --
BODY: Message only has text/html MIME parts
- * -1.0 -- HTML_LINK_CLICK_HERE
-- BODY: HTML link text says click here
- * 0.3 -- HTML_FONT_INVISIBLE
-- BODY: HTML font color is same as backgro
- * 0.1 -- HTML_MESSAGE -- BODY:
HTML included in message
- * -0.0 -- HTML_WEB_BUGS --
BODY: Image tag intended to identify you
|
|
8
|
|
|
9
|
|
|
10
|
|
|
11
|
|
|
12
|
|
|
13
|
|
|
14
|
- Creating a Rule based on
- Spam Score
|
|
15
|
|
|
16
|
|
|
17
|
|
|
18
|
- Other ways you can reduce Spam
|
|
19
|
- Avoid replying to the SPAM sender
- Make use of laws against Spam
- Review Web sites' privacy policies
- Don't list yourself in Internet directories
- Do not forward chain e-mail
- For Personal email addresses
- Alter your e-mail address when you post it
- Don't give out your primary e-mail address
- Don't post your address on your Web page
|
|
20
|
- Spam email can carry destructive programs, like viruses and worms, that
can damage your computer
- Not every spam is caught by the SCM 3300, so check your mailbox
regularly
- Delete spam every day! Don’t let it sit in your Deleted Items folder.
|
|
21
|
- Microsoft
- http://www.microsoft.com/athome/security/protect/default.mspx
- Critical Path Project Internet Services
- Critical Path Help Desk
- critpath@critpath.org
- 215-985-4851
|