|

Barracuda Networks Product Overview
Spam & Virus Firewall
Web/URL Filter
Instant Messaging Firewall
Web Application Load Balancer
Email Archiver
Web Site Firewall
SSL VPN
Anti Spam
Anti Spyware
Anti Virus
Request 14 Day Evaluation
Request a Quotation

|
 |
Anti Spam Technology
Superior Spam Filtering Methods
The Barracuda Spam & Virus Firewall provides comprehensive spam blocking for your
organization. The algorithms and methods used by the Barracuda Spam & Virus Firewall are
the most comprehensive and most advanced in the industry.
The methods and techniques used by the Barracuda Spam & Virus Firewall are
continuously updated via the hourly Barracuda Energize Updates service to stay
ahead of spam trends as they emerge.
The Barracuda Spam & Virus Firewall provides a number of different parameters that
can be adjusted and tuned for your specific environment.
There are two main classes of techniques for blocking unwanted email:
- Connection Management techniques involve dropping
incoming mail connections before actually receiving the message
- Mail Scanning techniques involve analysis of messages
after they have been received.
Within each class are many possible defense tactics. The Barracuda Spam & Virus Firewall combines a multitude of these defense tactics to stop spam and other
unwanted email that violates policy.
Connection Management
The connection management techniques generally require less processing. For
typical small or medium businesses, more than half of the total email volume can
be blocked through connection management techniques. Very large Internet Service
Providers (ISPs) or even smaller Web hosts while under attack, may observe block
rates at connection management layers exceeding 99 percent of all email
volume.
| Technique |
Description |
| Network Denial of Service Protection |
Built on a hardened and secure operating system, the Barracuda Spam & Virus Firewall receives email on behalf of the organization insulating the
organization's email server from receiving direct Internet connections and
their associated threats. |
| Rate Controls |
Automated spam software can be used to send large amounts of email to a
single email server. To protect the email infrastructure from these
flood-based attacks, the Barracuda Spam & Virus Firewall counts the number of
incoming connections from a particular IP address and throttles the
connections once a particular threshold is exceeded.
Organizations who relay email through known servers before reaching the
Barracuda Spam & Virus Firewall or who communicate frequently with known partners
should add the IP addresses of those known relays and good email servers
to the Rate Control exemption list. |
| IP Analysis |
After applying rate controls based on IP address, the Barracuda Spam & Virus Firewall then performs analysis on the IP address.
- Customer-defined policy for allowed IP addresses.
The Barracuda Spam & Virus Firewall enables administrators to define a list of
trusted email servers by IP address. By adding IP addresses to this
list, administrators can avoid spam scanning of good email, both
reducing processing requirements and eliminating the chances of false
positives.
- Customer-defined policy for blocked IP addresses.
The Barracuda Spam & Virus Firewall also enables administrators to define a list
of known bad email senders. In general, administrators need not enter
blacklists of spam senders, as these are typically added by Barracuda
Central to the Barracuda Blacklist Service. In some cases,
administrators may choose to utilize the IP block lists to restrict
specific email servers as a matter of policy rather than as a matter of
spam protection.
- Barracuda Reputation. Barracuda Reputation is
maintained by Barracuda Central and includes a list of IP addresses of
known, good senders as well as known spammers. Updates to the Barracuda
Reputation database are delivered to the Barracuda Spam & Virus Firewall via
Barracuda Energize Updates.
- External block lists. The Barracuda Spam & Virus Firewall
enables administrators to take advantage of external block lists which
are also known as real-time block lists (RBLs) or DNS block lists
(DNSBLs). Several organizations maintain external block lists, such as
spamhaus.org.
In general, external blacklists take precedence over subsequent allow
lists (“whitelists”) on the sender email address or domain, recipient,
headers or message body. The Barracuda Spam & Virus Firewall does have an option
to delay RBL checks so that subsequent allow lists can take precedence
over external block lists. |
| Sender Authentication |
Declaring an invalid “from” address is a common practice by spammers.
The Barracuda Spam & Virus Firewall utilizes a number of techniques to both
validate the sender and to apply policy.
- Protocol compliance. Before even validating a
sender, the Barracuda Spam & Virus Firewall validates that the sender is
specified properly. Examples of enforcement policies include forcing RFC
821 compliance or requiring fully qualified domain names.
- DNS lookup. To prevent senders from faking a “from”
domain, the Barracuda Spam & Virus Firewall can perform a DNS lookup on the
sender domain to ensure that the domain exists.
- Sender spoof protection. Optionally, the Barracuda
Spam & Virus Firewall can prevent “spoofing” of their own domain by disallowing
emails from the outside using the customer's own domain name. Note that
sender spoof protection should not be enabled if the organizations send
messages from outside their internal email infrastructure (e.g., in the
case of marketing bulk-mail services).
- Custom policies. Organizations can define their own
allowed sender domains or email addresses. They can also define their
own block lists based on sender domains or email addresses. Note that
allow lists override block lists.
- Sender Policy Framework (SPF) . SPF is a proposed
standard with growing momentum designed to prevent spoofing of email
domains. SPF provides a means for organizations to declare their known
email servers in their DNS records so that email recipients can validate
the identity of the sender domain based on the IP address of the sending
email server. The Barracuda Spam & Virus Firewall enables email administrators
to block or tag messages on failed SPF checks.
|
| Recipient Verification |
Many spammers attack email infrastructures by harvesting email
addresses. The Barracuda Spam & Virus Firewall verifies the validity of recipient
email addresses through multiple techniques.
- Protocol compliance. Before even validating a
recipient, the Barracuda Spam & Virus Firewall validates that the recipient is
specified properly. An example of an enforcement policy includes forcing
RFC 821 compliance.
- Custom policies. Organizations can define their
policies based on allowed recipient email addresses for which spam
scanning should be disabled. They can also define their own block lists
based on email addresses. Note that allow lists override block lists.
- LDAP recipient verification. Customers of Barracuda
Spam & Virus Firewall models 300 and higher can choose to reject messages if the
recipient email addresses do not appear in the LDAP directory.
- SMTP recipient verification. By default, the
Barracuda Spam & Virus Firewall rejects messages if the downstream mail server
does not accept mail for that recipient.
|
Mail Scanning
As spammers become more sophisticated, mail scanning techniques grow in their
importance.
| Technique |
Description |
| Virus Scanning |
The most basic level of mail scanning is virus scanning. The Barracuda
Spam & Virus Firewall scans all email messages and all incoming files for viruses
using two layers of virus scanning technology and automatically
decompresses archives for comprehensive protection.
Virus scanning takes precedence over all other mail scanning
techniques, and it is applied even when mail passes through the connection
management layers. As such, even email coming from “whitelisted” IP
addresses, sender domains, sender email addresses or recipients are still
scanned for viruses and blocked if a virus is detected. |
| Custom Policy |
Administrators can choose to define their own policies, perhaps for
compliance or governance reasons, which take precedence over spam blocking
rules delivered to the system automatically through Barracuda Energize
Updates. The Barracuda Spam & Virus Firewall enables administrators to set custom
content filters based on the subject, message headers, message bodies and
attachment file type.
In general, administrators do not need to set their own filters for the
purposes of blocking spam, as these forms of rules are delivered to
Barracuda Spam & Virus Firewalls automatically through Barracuda Energize
Updates. |
| Fingerprint Analysis |
A message “fingerprint” is based on commonly used message components
(e.g., an image) across many instances of spam. Fingerprint analysis is
often a useful mechanism to block future instances of spam once an early
outbreak is identified.
Engineers at Barracuda Central work around the clock to identify new
spam fingerprints which are then updated on all Barracuda Spam & Virus Firewalls
through Barracuda Energize Updates. |
| Intent Analysis |
All spam messages have an “intent” – which is to get a user to reply to
an email, visit a Web site or call a phone number. Intent analysis
involves researching email addresses, Web links and phone numbers embedded
in email messages to determine whether they are associated with legitimate
entities. Frequently, intent analysis is the defense layer that catches
phishing attacks.
The Barracuda Spam & Virus Firewall features multiple forms of intent
analysis:
- Intent analysis. The Barracuda Spam & Virus Firewall
extracts markers of intent such as URLs and compares them against a
database maintained by Barracuda Central and delivered to the Barracuda
Spam & Virus Firewall via Barracuda Energize Updates.
- Realtime intent analysis. For new domain names that
may come into use, real-time intent analysis involves performing DNS
lookups against known URL block lists.
- Multilevel intent analysis. Use of free Web sites
to redirect to known spammer sites is a growing practice used by
spammers to hide or obfuscate their identity from mail scanning
techniques such as Intent Analysis. Multilevel intent analysis involves
inspecting the results of Web queries to URLs of well-known free Web
sites for redirections to known spammer sites.
|
| Image Analysis |
Today, image spam represents about one-third of all traffic on the
Internet. While fingerprint analysis captures a significant percentage of
images after they have been seen, the Barracuda Spam & Virus Firewall also uses
image analysis techniques which protect against new image variants. These
techniques include:
- Optical Character Recognition (OCR). Embedding text
in images is a popular spamming practice to avoid text processing in
anti-spam engines. OCR enables the Barracuda Spam & Virus Firewall to analyze
the text rendered inside the images.
- Image Processing. To mitigate attempts by spammers
to foil optical character recognition through speckling, shading, or
color manipulation, the Barracuda Spam & Virus Firewall also utilizes a number
of lightweight image processing technologies to normalize the images
prior to the OCR phase. More heavyweight image processing algorithms are
utilized at Barracuda Central to quickly generate fingerprints that can
be used by Barracuda Spam & Virus Firewalls to block messages.
- Animated GIF Analysis. In addition, the Barracuda
Spam & Virus Firewall contains specialized algorithms for analyzing animated
GIFs for suspect content.
|
| Bayesian Analysis |
Bayesian Analysis is a linguistic algorithm that profiles language used
in both spam messages and legitimate email for any particular user or
organization. To determine the likelihood that a new email is spam,
Bayesian Analysis compares the words and phrases used in the new email
against the corpus of previously received email.
The Barracuda Spam & Virus Firewall only uses Bayesian Analysis after
administrators or users profile a corpus of at least 200 legitimate
messages and 200 spam messages. |
| Spam Scoring |
Beyond absolute blocks that a single filter can apply, the Barracuda
Spam & Virus Firewall also includes a sophisticated scoring engine that weighs
multiple factors where a single filter may result into restrictive policy.
By combining multiple rules with known weightings, the Barracuda Spam & Virus Firewall can deliver a strong confidence interval for spam messages.
The Barracuda Spam & Virus Firewall enables administrators to set global spam
scores. Certain models of the Barracuda Spam & Virus Firewall also support per
domain and per user thresholds. |
|
 |


|