55
IronPort Messaging Security IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager Eastern Europe & Russia IronPort - A CISCO Systems Business Unit CISCO EXPO Croatia 2008

CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Messaging Security

IronPort Messaging Security

CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND

SPYWARE

Mirko Schneider

Territory Manager Eastern Europe & Russia

IronPort -A CISCO Systems Business Unit

CISCO EXPO Croatia 2008

Page 2: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The Power of SenderBase

®

First, Biggest, Best Reputation System

Over 100,000contributing networks

Over 20M IP addresses tracked globally

View into over 25%of email traffic

Over150parameters tracked

Global Email and Web Traffic Monitoring

Page 3: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Leading Edge Technology

Reputation Filtering Sets off Industry Scramble

July 21, 2003

IronPort Reputation

Filters™

February 16, 2003

IronPort SenderBase™

June 28, 2004

Symantec

Brightmail

Reputation

Service

June 4, 2004

CipherTrust

TrustedSource™

November 9, 2004

Proofpoint MLX Dynamic

Reputation™

June 14, 2005

Trend Micro

Acquires

Kelkea Reputation

Product

May 23, 2005

Tumbleweed Recurrent

Pattern Detection™

2004

2003

2005

Page 4: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Who is IronPort?

•Founded in 2000 by Email pioneers

from Hotmail, ListBot, Yahoo

•idea: building the fastest and

strongest gateway appliance

•HQ in California, Silicon Valley

•Worldwide 500+ employees

•Market growth rate = 50%

IronPort growth rate = 100%

revenue 2007: ~ 250m USD

•A Cisco Business Unit since mid

2007

Page 5: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort –A CISCO Business Unit

•Largest security acquistion

•5thlargest acquisition ever

•market consolidation:

Brightmail

-> Symantec: 370m $

Ciphertrust

-> SecureComputing: 273m $

Postini

-> Google: 625m $

SurfControl

-> Websense: 400m $

Page 6: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The Principles of Industry Leadership

•Analyst Leadership

–Gartner’s Magic Quadrants 2006: Leader

–IDC July 2007: market share leader

–Radicati Market Quadrants 2007: Leader

•Customer Leadership

–52 of the World’s Largest 100 Companies

–20+% of Global 2000

–12 of the 15 largest ISPs

•Success in Croatia

Austria d.d. Zagreb

Page 7: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Web Security

| Email Security

| Security Management|Encryption

IronPort

®

Gateway Security Products

EMAIL

Security Appliance

WEB

Security Appliance

Security

MANAGEMENT

Appliance

IronPort

SenderBase

APPLICATION-SPECIFIC

SECURITY GATEWAYS

CLIENTS

BLOCK Incoming Threats

PROTECT Corporate Assets

Data Leakage Prevention

Encryption

CENTRALIZE Administration

Internet

ENCRYPTION

Appliance

Page 8: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The IronPort SenderBase

®

Network

Glo

ba

l R

ea

ch Y

ield

s B

ench

mark

Accura

cy

•30B+ queries daily

•150+ Email and Web parameters

•25% of the World’s Traffic

•Cisco Network Devices

IronPort EMAIL

Security Appliances

IronPort WEB

Security

Appliances

IronPort

SenderBase

Com

bines Email & Web Traffic Analysis

�View into both email & Web

traffic dramatically improves

detection

�80% of spam contains URLs

�Email is a key distribution

vector for Web-based malware

�Malware is a key distribution

vector for Spam zombie

infections

Page 9: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The Leader in Email Security

IronPort C-Series Appliance

Page 10: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Consolidates the

Network Perimeter

For

Security

, R

elia

bili

ty a

nd L

ow

er

Main

ten

ance

After IronPort

Groupware

Firewall

IronPort Email Security Appliance

Internet

Before IronPort

Anti-Spam

Anti-Virus

Policy Enforcement

Mail Routing

Internet

Firewall

Groupware

Users

Encryption Platform

MTA

DLP

Scanner

DLP Policy

Manager

Users

Page 11: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Architecture for

Multi-Layered Email Security

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

DATA LOSS

PREVENTION

VIRUS

DEFENSE

EMAIL

ENCRYPTION &

AUTHENTICATION

Page 12: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Multi-layer Spam Defense

Best of Breed

•IronPort Reputation Filters–the outer layer defense

•IronPort Anti-Spam-stops the broadest array of threats –spam, phishing, fraud

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

DATA LOSS

PREVENTION

VIRUS

DEFENSE

EMAIL

ENCRYPTION &

AUTHENTICATION

Page 13: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

0

20

40

60

80

100

120

140

160

180

Oct-

05

Dec-

05

Feb-

06

Apr-

06

Jun-

06

Aug-

06

Oct-

06

Dec-

06

Feb-

07

Apr-

07

Jun-

07

Aug-

07

Oct-

07

Dec-

07

Feb-

08

Apr-

08

Jun-

08

Aug-

08

Oct-

08

Dec-

08

Date

Avg Daily Volume (billions)Spam Volumes

2005 -2008 Reality & Projections

Dec 05 –Dec 06: 100% year-over-year

increase, 38B additional messages

Dec 06 –Dec 07: 58% year-over-year

increase: 44B additional messages

Page 14: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Spam is changing rapidly

PDF, Excel,MP3 ...

Page 15: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Multi-Layered Security

Preventive + Reactive = Defense in Depth

Reactive

Layer

+

Immediate Reaction

to Threats

Extremely High

Performance

Coarse Outer Layer

Blocks or Rate Limits

Adapts Over Time

Computationally

Intensive

Fine-grained Inner Layer

Delete or Quarantine

Preventive

Layer

blocks

~ 80%

of spam

Page 16: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort SenderBase

®

Network

Global Reach Yields Benchmark Accuracy

•5B+queries daily

•150+Email and Web parameters

•25%of the World’s Email Traffic

The Dominant Force in Global

Email and Web Traffic Monitoring…

80%

50%

40%

IronPort

CipherTrust

BorderWare

Spam Caught by Reputation

Source: www.ciphertrust.com and www.borderware.com, August 6, 2006

…Results in Accuracy and

Advanced Protection

120,000

4,000

8,000

IronPort

CipherTrust

BorderWare

Network Reach (Contributing Networks)

13 hours*

McAfee, Trend, Symantec, Sophos, CA, F-Secure

IronPort

Virus Protection Lead

* 6

/20

05

–6

/20

06

. 1

75

ou

tbre

aks id

en

tifie

d.

Ca

lcu

late

d a

s p

ub

licly

pu

blis

he

d s

ign

atu

res f

rom

th

e lis

ted

ve

nd

ors

.

Page 17: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Global Volume

Data

Over 100,000

organizations,

email traffic,

web traffic

Message

Composition

Data

Message size,

attachment volume,

attachment types,

URLs, host names

Spam Traps

SpamCop, ISPs,

customer

contributions

IP Blacklists &

Whitelists

SpamCop, SpamHaus

(SBL), NJABL,

Bonded Sender

Compromised

Host Lists

Downloaded files,

linking URLs,

threat heuristics

Web site

Composition

Data

SORBS, OPM,

DSBL

Other Data

Fortune 1000, length

of sending history,

location, where the

domain is hosted,

how long has it been

registered, how long

has the site been up

Complaint

Reports

Spam, phishing,

virus reports

Spamvertized URLs,

phishing URLs,

spyware sites

Domain Blacklists

& Safelists

IronPort SenderBase™Reputation

150 parameters for each IP

www.senderbase.org

Senderbase Reputation Score -10 to +10

Page 18: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Reputation Filters Stop

80% of Hostile Mail at the Door….

•Known good

is delivered

•Suspicious

is rate limited

& spam filtered

•Known bad is

deleted/tagged

•Reputation Filters is a switch point

•IronPort uses identity & reputation to apply policy

•Sophisticated response to sophisticated

threats

Anti-Spam

Engine

(reactive)

Incoming Mail

Good, Bad, and “Grey”

or Unknown Email

Reputation

Filtering

(preventive)

Page 19: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Reputation Filters

Dell Case Study

•Dell’s challenge:

–Dell currently receives 26Mmessages per day

–Only 1.5Mare legitimate messages

–68 existing gatewaysrunning Spam Assassin

were not accurate

•IronPort solution:

–Reputation Filters block over 19Mmessages per day

–5.5Mmessages per day scanned by

anti-spam engine

–Replaced 68servers with 8IronPort C60s

•Accuracy of spam filtering increased10x

•Servers consolidated by70%

•Operating costs reduced by75%

“IronPort has

increased the

quality and

reliability of

our network

operations,

while

reducing our

costs.”

--Tim Helmsetetter

Manager, Global

Collaborative Systems

Engineering and

Service Management,

DELL CORPORATION

Page 20: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Self Defending Network 3.0

Extending Technology Leadership

•Wide Traffic Inspection

•Firewalls, routers, email

appliances, web

appliances, end point

security agents

•sharing data across

multiple protocols, across

multiple network egress

points, and across multiple

networks world wide

Accuracy (%)

100%

Technical Resources ($)

Staying Ahead Requires

Higher Investment in

Technical Resources

Page 21: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Multi-Layered Security

Preventive + Reactive = Defense in Depth

+

Immediate Reaction

to Threats

Extremely High

Performance

Coarse Outer Layer

Blocks or Rate Limits

Adapts Over Time

Computationally

Intensive

Fine-grained Inner Layer

Delete or Quarantine

Preventive

Layer

Reactive

Layer

Page 22: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort AntiSpam Broadens the

Context with Web Reputation

•Content filtering techniques alone are inadequate

•Email reputation systems improved protection

•Combating new attacks demands Web reputation

Tim

e

TODAY

Effectiveness

Where?Web Reputation

Where does the call to action take you?

Who?Email Reputation

Who is sending you this message?

How?Message Structure

How was this message constructed?

What?

Message Content

What content is included in this message?

Page 23: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

URLNo

attachment

-Payload

delivered

via web

Page 24: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort SenderBase

®

Network

First, Biggest, Best Reputation System

Over 100,000contributing networks

Over 20M IP addresses tracked globally

View into over 25%of email traffic

Over150parameters tracked

Global Email and Web Traffic Monitoring

Page 25: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Web Reputation

Data

Make

s the D

iffe

rence

•URL Blacklists

•URL Whitelists

•URL Categorization Data

•HTML Content Data

•URL Behavior

•Global Volume Data

•Domain Registrar Information

•Dynamic IP Addresses

•Compromised Host Lists

•Web Crawler Data

•Network Owners

•Known Threats URLs

•Offline data (F500, G2000…)

•Web Site History

SenderBase

Data

Data Analysis/

Security Modeling

Web Reputation

Scores (WBRS)

-10 to +10

Parameters

THREAT PREVENTION IN REALTIME

Page 26: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Anti-Spam

Press Reviews

2007 Technology of the Year:

Best Anti-Spam

Jan 2007

Competitors tested:

Symantec, Microsoft, Mirapoint, ProofPoint

“easy s

etu

p”

“excelle

nt

spa

m f

ilteri

ng

“no t

unin

g n

ecessary

“the f

ew

est

fals

e p

ositiv

es o

f

any s

olu

tion t

este

d”

Anti-Spam Bake-Off Winner

Dec 2006

Competitors tested:

CipherTrust, Borderware, Sophos,

SonicWall

“The s

uperi

ority

of

IronP

ort

. . .

see

ms a

bu

nda

ntly c

lear”

“We d

id n

ot

ha

ve t

o r

escue a

sin

gle

leg

itim

ate

message

“(Ir

onP

ort

) is

the a

bsolu

te m

ust

from

this

test”

Page 27: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Multi-layer Virus Defense

Best of Breed

•IronPort Virus Outbreak Filtersstop outbreaks 13 hours ahead of signatures

•Sophos Anti-Virussignature based solution with industry leading accuracy

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

POLICY

ENFORCEMENT

VIRUS

DEFENSE

EMAIL

AUTHENTICATION

Page 28: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Virus Outbreak Filters™

First Line of Defense

Early Protection

with

IronPort Virus

Outbreak Filters

Page 29: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Traditional AV Solutions Aren’t

Responding Quickly Enough . . .

4:00

9:00

14:00

19:00

0:00

5:00

10:00

15:00

Time (GMT)

Virus Volume

First AV

Signature

Available

Mytob-HJ: 4-19-06

9:30

10:20

11:10

12:00

12:50

13:40

14:30

15:20

Time (GMT)

Virus Volume

First AV

Signature

Available

Kukudro-A: 6-27-06

020

40

60

80

100

120

20:00

23:45

3:30

7:15

11:00

14:45

18:30

22:15

Time (GMT)

Virus Volume

First AV

Signature

Available

Bagle-GT: 4-21-06

Calc

ula

ted a

s p

ublic

ly p

ublis

hed s

ignatu

res f

rom

the f

ollo

win

g v

endo

rs: S

ophos,

Tre

nd M

icro

, C

om

pute

r A

ssocia

tes, F

-Secure

, S

ym

ante

c a

nd M

cA

fee.

If sig

natu

re t

ime is n

ot

availa

ble

, firs

t public

ly p

ublis

hed a

lert

tim

e is u

sed.

19:00

22:45

2:30

6:15

10:00

13:45

17:30

21:15

Time (GMT)

Virus Volume

First AV

Signature

Available

FeebsDI-Q: 6-07-06

Page 30: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort SenderBase

®

Network

First, Biggest, Best Reputation System

Over 100,000contributing networks

Over 20M IP addresses tracked globally

View into over 25%of email traffic

Over150parameters tracked

Global Email and Web Traffic Monitoring

What

is g

oin

g o

nRIGHT NOW?

Page 31: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Introducing Virus Outbreak Filters

4:00

9:00

14:00

19:00

0:00

5:00

10:00

15:00

Time (GMT)

Virus Volume

First AV

Signature

Available

Mytob-HJ: 32 hrs 57 mins Lead Time!

VOF

Protection

Starts

9:30

10:20

11:10

12:00

12:50

13:40

14:30

15:20

Time (GMT)

Virus Volume

First AV

Signature

Available

VOF

Protection

Starts

Kukudro-A: 3 hrs 38 mins Lead Time!

19:00

22:45

2:30

6:15

10:00

13:45

17:30

21:15

Time (GMT)

Virus Volume

First AV

Signature

Available

FeebsDI-Q: 21 hrs 59 mins Lead Time!

VOF

Protection

Starts

20:00

23:45

3:30

7:15

11:00

14:45

18:30

22:15

Time (GMT)

Virus Volume

First AV

Signature

Available

Bagle-GT: 18 hrs 28 mins Lead Time!

VOF

Protection

Starts

Calc

ula

ted a

s p

ublic

ly p

ublis

hed s

ignatu

res f

rom

the f

ollo

win

g v

endo

rs: S

ophos,

Tre

nd M

icro

, C

om

pute

r A

ssocia

tes, F

-Secure

, S

ym

ante

c a

nd M

cA

fee.

If sig

natu

re t

ime is n

ot

availa

ble

, firs

t public

ly p

ublis

hed a

lert

tim

e is u

sed.

Page 32: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Virus Outbreak Filters Advantage

Average lead time*…

………………………over 13 hours

Major Outbreaks blocked * ………………………175 outbreaks

Total incremental protection*…

………….over 94 days

* June 2

005 –

July

2006.

Calc

ula

ted a

s p

ublic

ly p

ublis

hed s

ignatu

res f

rom

the f

ollo

win

g v

endors

: S

oph

os, M

cA

fee ,

Tre

nd M

icro

, C

om

pute

r

Associa

tes, F

-Secure

, S

ym

ante

c a

nd M

cA

fee.

If sig

natu

re t

ime is n

ot

availa

ble

, firs

t public

ly p

ublis

hed a

lert

tim

e is u

sed.

Virus Name

Date

Virus Description

Lead Time

(hh:mm)

Troj/Dloadr-BCK

7/24/07

Installs spyware on infected PCs.

10:06

Troj/Yar-A

5/24/07

Widely-spammed out email teaser promising a trailer of the film

"Pirates of the Caribbean 3“. Downloads spyware onto infected

computers.

3:20

Trojan.Dropper

5/10/07

Trojan that attempts to download malicious code.

10:40

W32.Virut!dr

4/12/07

Spammed email that asks recipients to open spyware attachments

entitled “document.txt.exe”and “video.zip”.

31:12

Troj/DwnLdr-GFN

3/4/07

Installs backdoor and communicates via HTTP, thus bypassing

firewall filters.

17:31

W32/WowPWS-AU

3/3/07

Mass mailing worm that sends emails with the subject: "Chinese

test missile obliterates satellite!“. Asks users to open spyware

infected file.

6:51

Troj_Agent.JAW

1/14/07

Spammed email message that contains PDF attachment. Once

attachment is opened, backdoor is installed for remote hackers to

access the PC.

20:08

Page 33: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

MyDoom Variant—MyDoom.BB (February 15, 2005)

G2000 Company Protected By IronPort’s Virus Outbreak Filters

1:00

2:00

3:00

4:00

5:00

6:00

7:00

8:00

9:00

10:00

11:00

12:00

13:00

14:00

17:00

18:00

19:00

20:00

21:00

22:00

23:00

24:00

20:00

21:00

First Anti-virus

Signature Published

22:54 GMT (Next Day) 22:00

23:00

IronPort Threat Level

Raised to 3 And Protection

Starts

18:08 GMT

28 hours 46 minutes

Note: All times shown are in GMT

6503 files quarantined

24:00

February 15, 2005

February 16, 2005

IronPort Outbreak Filters Protect

G2000 C

om

pany F

rom

MyD

oom

.BB

$65K saved @ $200/desktop, 5% infected

Page 34: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Policy Enforcement

Inbound/Outbound Content Filtering for Compliance

•Flexible Policy Enginefrom Blocking Attachments to Enforcing Regulatory Compliance

•Compliance Solutions and Encryption keep communications private and secure

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

DATA LOSS

PREVENTION

VIRUS

DEFENSE

EMAIL

ENCRYPTION &

AUTHENTICATION

Page 35: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Email Encryption & Authentication

Superior Security and Identity Protection

•DomainKey Signing-establishes and protects your identity on the Internet

•IronPort Bounce Verification–protects from misdirected bounce attacks

•Directory Harvest Attack Prevention–blocks attempts to steal email directory information

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

DATA LOSS

PREVENTION

VIRUS

DEFENSE

EMAIL

ENCRYPTION &

AUTHENTICATION

Page 36: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Leader in Email Encryption!

Magic Quadrant

for E-Mail Encryption

Boundary 2007

Source: Gartner RAS Core Research

You need that competitive

analysis?

Mail me at

[email protected]!

Page 37: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The Challenger in Web Security

IronPort S-Series Appliance

Page 38: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort S-Series

•Control & secureWeb

traffic

•Comprehensive

management & visibility

•Industry-leading

accuracy against Web-

based threats

•Carrier-class

performance

IronPort Web Security Appliance

Next Generation Web Security Platform

Page 39: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Web Traffic: Clear & Present Risks

•Over 75% of all Enterprises

are infected with Spyware &

Malware

•35-40% of Web usage is

non-business related (IDC

Research)

•Malware threats & AUP

violations result in

compliance & legal

exposure

The Circle of Risk

Web

Traffic

Page 40: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Web Traffic

The L

on

g T

ail

Gets

Longer

Predictable traffic, well known domains

# of Sites

Traffic Volume

Growing fast, harbors suspect content & malware

“Big Head + Long Tail”

•~110 Million sites

•~10-12 Billion Web Pages

•Growing at 35-40% annually

“Big Head + Long Tail”

•~110 Million sites

•~10-12 Billion Web Pages

•Growing at 35-40% annually

Big

Head

Long Tail

Page 41: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort S-Series

Addre

ssin

g the E

ntire

Spectr

um

of W

eb T

raffic

Solution:URL Filtering

# of Sites

Traffic Volume

Solution:Web Reputation Filters +

Signature-based Anti-M

alware Defense

•Protects against known & unknown sites

•Best of breed signature scanning

Big

Head

Long Tail

IronPort Web Security Appliance

Page 42: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Current Systems Not

Designed for Today’s Problems

•Low accuracy

•High latency /

throughput

•Limited visibility to

security threats

“Not th

e r

ight to

ol

for

the job.”

Page 43: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort SenderBase Network

Larg

est

Em

ail

& W

eb T

raffic

Monitorin

g N

etw

ork

Largest: over 25% of traffic from 120,000+ sources

Broadest: 150 cross-protocol param

eters

Best: Two year “head start”vs. alternative system

s

Largest: over 25% of traffic from 120,000+ sources

Broadest: 150 cross-protocol param

eters

Best: Two year “head start”vs. alternative system

s

Page 44: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Integrated L4 Traffic Monitor

Wire S

pee

d N

etw

ork

Layer

Scan

nin

g f

or

Malw

are

•Scans all 65,535

ports at wire speed

•Detects rogue

phone home activity

•Catches malware

that attempts to

bypass Port 80

Users Network Layer

Analysis

AsyncOS for Web

AsyncOS for Web

L4 Traffic Monitor

L4 Traffic Monitor

110111

110011

100100

10010

111001

100101

011101

10010

000110

100110

011100

10000

110111

110011

100100

10010

111001

100101

011101

10010

000110

100110

011100

10000

TCP Headers

& Packets

TCP Headers

& Packets

Internet

Page 45: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Web Reputation Filters

Data

Make

s the D

iffe

rence

•URL Blacklists

•URL Whitelists

•URL Categorization Data

•HTML Content Data

•URL Behavior

•Global Volume Data

•Domain Registrar Information

•Dynamic IP Addresses

•Compromised Host Lists

•Web Crawler Data

•Network Owners

•Known Threats URLs

•Offline data (F500, G2000…)

•Web Site History

SenderBase

Data

Data Analysis/

Security Modeling

Web Reputation

Scores (WBRS)

-10 to +10

Parameters

THREAT PREVENTION IN REALTIME

Page 46: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Dynamic Application of Policies

•IronPort Web Reputation Filtersis a powerful firs

tlayer

of defense

•IronPort Anti-Malware Systemprovides a sophisticated s

econdlayer

of defense

Requested

URLs

Known good sites

aren’t scanned

Unknown sites are

scanned

Known bad sites are

blocked

IRONPORT

WEB REPUTATION

FILTERS

IRONPORT

WEB REPUTATION

FILTERS

IRONPORT

ANTI-MALWARE

SYSTEM

IRONPORT

ANTI-MALWARE

SYSTEM

Page 47: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

The Platform

IronPort AsyncOS

Page 48: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort AsyncOS™

Unmatched Scalability and Security

•AsyncOSscalable and secure OS optimized for messaging

•Advanced Email Controlsprotect reputation and downstream systems

•Standards-based Integrationreplaces legacy systems with ease

MANAGEMENT TOOLS

THE IRONPORT ASYNCOS™EMAIL PLATFORM

SPAM

DEFENSE

DATA LOSS

PREVENTION

VIRUS

DEFENSE

EMAIL

ENCRYPTION &

AUTHENTICATION

Page 49: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Scalable and Extensible Platform

Meeting S

ecurity

Need

s –

Today a

nd T

om

orr

ow

2004

2007

2010

Computational power

required for accurate

scanning

Number of functions

that must be supported

Average volume and

size of messages

Page 50: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort AsyncOS

Revolu

tio

nary

Em

ail

De

livery

Pla

tform

Traditional Email Gateways

And Other Appliances

IronPort Email Security Appliances

200

Concurrent

Connections

Low Performance/

Peak Delivery Issue

Disk I/O

Bottlenecks

Unable To Leverage

Full Capability

Components

CPU

Limited Solely

By CPU Capacity

10.000

Concurrent

Connections

High Performance/

Sure Delivery

Single Queue

for all destinations

Queue backup

delays all email

Per-Destination

Queue

Fault-Tolerance

and Custom

Control

Page 51: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Email Security Manager™

Single view of policies for the entire organization

•Mark and Deliver Spam

•Delete Executables

•Archive all mail

•Virus Outbreak Filters

disabled for .doc files

•Allow all media files

•Quarantine executables

“Email Security Manager serves as a single,

versatile dashboard to manage all the

services on the appliance.”

--P

C M

aga

zin

e 2

/22

/05

Categories: by Domain,

Username, or LDAP

IT

SALES

LEGAL

Page 52: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort Centralized Management

•Log in anywhere, control everywhere

•Interface assures configuration consistency

•Apply changes to a machine, group, or cluster

•Test on single system, “promote”to cluster

IRONPORT CLUSTER

Zagreb Group

SJ1 Machine

SJ2 Machine

SJ3 Machine

Dubrovnik Group

D1 Machine

D2 Machine

D3 Machine

Rijeka Group

T1 Machine

T2 Machine

T3 Machine

Page 53: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

IronPort M-Series™

Security Management Appliances

•Centralized, self-managing

quarantine appliance

•Provides complete end-

user self-service, drives

down administrator load

•Centralized Reporting and

Message Tracking Console

Page 54: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Sounds good? Test it!

•Free evaluation for 30 days

–starts with activation of keys on unit

–can be extended on request

•any size and any way

–you get the right units for your needs

–different ways of testing (life/ stealth, parallel, offline)

–full support, full functionality

•About 85% of users who evaluate become happy

customers!

Page 55: CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE · IronPort Messaging Security CISCO’S NEW STRATEGY AGAINST SPAM, VIRUSES AND SPYWARE Mirko Schneider Territory Manager

Get In Contact

IronPort, A Cisco Business Unit

Mirko Schneider

Hrvoje Dogan

Territory Manager

Systems Engineer

Eastern Europe & Russia

Eastern Europe & Russia

Mobile: +49 172 83 96 04 7

Mobile: +385 917655625

[email protected]

[email protected]

Distributor:

MACK IT

www.mack.hr

-partner contacts, evaluation

equipment, technical specialists