Previous Topic

Next Topic

Book Contents

Book Index

IceWarp Anti-Spam LIVE

IceWarp Server can use IceWarp Anti-Spam LIVE, an example of RPD (Recurring Pattern Detection) Technology, as part of its fight against spam.

A Real-Time Detection Center analyzes large volumes of Internet traffic in real time, identifying new Spam, Virus and Phishing outbreaks based on characteristic mass distribution patterns. Emerging outbreaks are usually identified moments after they are introduced onto the Internet.

This can significantly help in protecting your Users from bulk and spam emails.

As with other IceWarp Anti-Spam technologies, IceWarp Anti-Spam LIVE is used to adjust the Spam score of a message rather than to give a final judgment on the message:

ASL_general

Field

Description

Active

Enables CommTouch checking.

(Commtouch technology automatically analyzes billions of Internet transactions in real-time in its global data centers to identify new threats as they are initiated, protecting email infrastructures and enabling safe, compliant browsing.)

Engine is applied only if score bellow

This field indicates a spam score that is a limit for running IceWarp Anti-Spam LIVE.

A message comes to IceWarp Anti-Spam LIVE with some spam score. In the Score non-spam messages, you set a score for messages that IceWarp Anti-Spam LIVE recognizes as OK. This score is added (it is a negative number) to the score that a message has when coming to IceWarp Anti-Spam LIVE. If the result is higher than the spam score set in the Anti/Spam – Action – Score required to classify message as spam field, it is useless to apply IceWarp Anti-Spam LIVE because the message will still be a spam.

E. g.:

You have the Score required to classify ... value set to 4.

The message comes to IceWarp Anti-Spam LIVE with the score of 7.

7 - 2.4 = 4.6

This message will always have its score higher than 4 – it is useless to run IceWarp Anti-Spam LIVE.

Another example:

The message comes to IceWarp Anti-Spam LIVE with the score of 5.

5 - 2.4 = 2.6

IceWarp Anti-Spam LIVE is run.

Score bulk and highly suspected virus messages

Set the slider to an amount that will be added to the Spam score if IceWarp Anti-Spam LIVE reports the message as bulk.

Score confirmed spam messages and virus messages

Set the slider to an amount that will be added to the Spam score if IceWarp Anti-Spam LIVE reports the message is Spam.

Given the proven reliability of IceWarp Anti-Spam LIVE it is recommended that this be set at 9 or more.

Score non-spam messages

Set the slider to an amount that the Spam score will be reduced by if IceWarp Anti-Spam LIVE reports the message as not Spam.

The default value is 0 because reducing the score too much can result in False Positives – remember that LIVE is one of several technologies adding up to the overall score.

note_small

NOTE: The IceWarp Anti-Spam LIVE engine is only called for messages which are not classified as Spam by IceWarp Server's other AntiSpam engines, according to the Score required to classify a message as spam setting in AS Action - General.

IceWarp Anti-Spam LIVE Reasons - identified as LIVE=

Code Issued

Reason

Y

This message is flagged as highly likely Spam by the IceWarp Anti-Spam LIVE Servers.

H

This message is flagged as highly likely to be a Bulk Mail.

N

This message is considered genuine.

 

note_small

NOTE: Some servers block external access to port 80, thus they need to know what address is for AntiSpam LIVE to free it up in their FireWalls. This information is in the ctasd.conf file (<InstallDirectory>/spam/commtouch):

Server_address = Resolver%d.icew.ctmail.com

Where %d is some dynamic number.

In This Chapter

IceWarp Anti-Spam LIVE Classifications