Sunday | 12 October, 2008
CIO
Why spammers are like dogs
IronPort founder discusses Cisco acquisition, e-mail security, and spam
Cara Garretson (Network World) 29 May, 2007 08:00:50

Related Features
  • +

    Ticked Off at Tick the Box Mentality 04 February, 2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Doing Your Sums on . . . Build, Buy or Rent 05 November, 2007 13:32:30

    You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?
    CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
Related Stories
  • +

    Can Macs conquer the enterprise? 11 January, 2008 10:55:53

    The field is wide open for a Macintosh insurrection on the business desktop. It could happen, but probably won't. Here's why.
    If Apple were a football team, the New England Patriots would have had some serious competition this year.
  • +

    10 things we hate about laptops 16 November, 2007 12:40:09

    Sure, laptops have revolutionized the way we compute. That doesn't mean they don't drive IT bonkers.
    Damaged. Lost. Stolen. Too big, too small. Insecure and unreliable. And just plain annoying. If you're in IT, there's just not much to like about laptops.
  • +

    IPv6 Will matter to the enterprise in five years 10 November, 2007 08:30:12

    Routing guru Jeff Doyle says there's no need to move to IPv6 now, offers design tips for OSPF nets, discusses Layer 2 vs. Layer 3 routing and shares more advice with attendees of his live Network World chat.
    Welcome to Network World Chats. Our guest today is Jeff Doyle, celebrity author, Cisco Subnet blogger and networking guru. He has come prepared to answer your questions on all things routing.
Additional Resources
Executive Guides
Whitepapers

Newsletter Subscription

Sign up for our CIO newsletters!
Weekly coverage of the issues that impact corporate and government information
RSS Feeds

We've been hearing a lot lately about the importance of data-leak prevention; do you view the internal threat to be more dangerous to an enterprise than the external threat?

It differs by industry, just how threatening it is. If an employee really wants to take data, they can print it out, they can do it in [different] ways, and there's just no way that you could stop them. To think you're going to come up with a foolproof solution to a [determined] employee who wants to get data out of your company, I think that's almost impossible.

But taking some prudent steps and looking at what's leaving via e-mail or the Web is important, and increasingly being demanded by customers, especially in various segments such as financial. I don't think it's an industry-toppling problem, I think it's more 'I'd like to check that box and say we're monitoring it.' Not to say there aren't instances . . . of intellectual property leaving the building.

After years of spam volumes declining, 2006 saw a significant increase in the amount of junk headed for in-boxes. What's going on?

The rise in volume . . . is because more people are getting into the business, and the people that are in the business realize spam's a money-maker. People have a profit motive to get into that business; it's not just for fun, now you can really make some money. It's a team-on-team sport, we [antispam vendors] try to field the best team and come up with defenses but . . . the reality is these guys have test accounts on every major ISP; they're like a dog with a zap collar, they keep trying the fence until they find a weakness and pound it unmercifully.

The weakness last year was image spam, which was really a difficult problem to solve. These guys figured out they could send an image and by randomizing a pixel they could make it through traditional spam filters. But it's like airport security -- we weren't having people take their shoes off until [Richard] Reid tried to blow one of his shoes up. We didn't have to check our water, then someone figures out you can combine two liquids and make a bomb out of that, too. [Spammers] are innovative, and we've got to stay on top of them. When we see something new or different, we've got to plug that hole immediately. Things like [when] spammers figured out this past year that many spam filters rely on humans to write rules, and humans have to sleep and don't typically work on Sunday nights, so they send all their spam between 2 and 4 AM, in a very short window, and it just zipped past all these folks. We see innovation [with the spammers] and we have to innovate as well.

What is the next set of features that communications-security vendors must add to their products to remain competitive and keep up with enterprises' needs?

We just bought PostX; encryption by and large hasn't been rolled out in e-mail, it seems absurd since for every important Web transaction we immediately go to a secure pipe, but everything in e-mail flies over the Internet in free text. I think authentication [for e-mail] is something people are starting to take seriously.

Image analysis is becoming increasingly interesting, watching what's coming in and going out via images, since most images now are sent via e-mail.

You've been tracking spam for a long time. What's your favorite spammer trick?

Every one is a little amusing. [For example] putting fake text in [a message] from books that might be Homer's Odyssey. Antispam engines put a score on how spammy each e-mail is, if it has capital letters, if it has a link, there are many different vectors when trying to determine [spam]. One of my favorites is when the spammers put things [into messages] to improve their scores . . . to hoodwink the filters. It's like dressing up in a disguise to get through airport security: 'If I'm dressed as a police officer, maybe they won't shake me down so much.'

Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
  • +

    Cambridge lab sets quantum key world record 09 October, 2008 07:51:00

    Researchers can now shift encryption keys around at speeds of 1Mbps.
    The hugely promising security technology of Quantum Key Distribution (QKD) has moved an important step closer to commercialization with the announcement by UK-based researchers that they can now shift encryption keys around at speeds of 1Mbps.
  • +

    Palin hacking charge flawed, lawyers say 09 October, 2008 07:28:00

    Case considered a misdemeanor offence not a felony.
    David Kernell is facing five years in prison for allegedly hacking into Alaska Governor Sarah Palin's Yahoo e-mail account, but lawyers watching the case say that the felony charge against him is a bit of a stretch.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Wireless LANs: Is my enterprise at risk?

Achieve an overall understanding of the risks associated with wireless LANs. Discover their inherent properties, as well as what makes them different from wired networks. Read on to uncover a list of recently published articles on real-life breaches and incidents illustrating the need for proactive measures to mitigate wireless security risks.