IMF Mihály Andó IT-IS 6 November 2006
Mihály Andó 2 / 11 6 November 2006 What is IMF? Intelligent Message Filter provides server-side message filtering, Integrated with Exchange Server 2003 sp2, Based on SmartScreen technology from Ms Research, - SmartScreen tracks over 500,000 characteristics based on data from hundreds of thousands of MSN Hotmail subscribers who volunteered to classify millions of messages as legitimate or as spam. Per-message spam confidence level ratings, Updates are available every first and third Wednesday (Automatic Updates).
Mihály Andó 3 / 11 6 November 2006 How it works? Action: - archive - delete - reject - no action Action: move to junk
Mihály Andó 4 / 11 6 November 2006 What is the SCL? SCL: Spam Confidence Level The server calculate one number for every mail, this is the SCL. This is a number from 0 to indicates lowest probability whereas 9 indicates near certainty of the being spam - -1 = IMF is switch off.
Mihály Andó 5 / 11 6 November 2006 How to enable IMF for a user ? Activate the Junk folder. - Safe Senders / Safe Recipients / Blocked Senders Precondition: IMF activated on gateways
Mihály Andó 6 / 11 6 November 2006 Test A – 100% SPAM SCL ThresholdMove to junk % % % % Test: - - More then s extracted from mailboxes, all of them being spam - - Evaluation of spam detection rate using different threshold
Mihály Andó 7 / 11 6 November 2006 Test B – “good” mails SCL Threshold Move to Junk (false positive) 7 0.2% 6 2.1% 5 10% % Test: - - More then s extracted from mailboxes, all of them being legitimate s - - Evaluation of spam detection rate using different threshold
Mihály Andó 8 / 11 6 November 2006 Test A, B – summary SCL Spam detection rate False positive rate %0.2% %2.1% %10% %52.2%
Mihály Andó 9 / 11 6 November 2006 IMF / Cern spam tool IMF limitations - Gateway threshold or store threshold, but no per user threshold !!! - Global white-list: only based on IP address (but end-users can maintain their own white-list of senders or recipients) CERN Spam tool features not in IMF - No filtering based on character sets - End-users can not white-list s with a particular subject - No dynamic Bayesian filtering based on spams reported by end-users Limitation or … benefit ? IMF features not in CERN Spam tool - trust s from your contacts (automatically, no need to upload your contacts on a regular basis)
Mihály Andó 10 / 11 6 November 2006 Conclusion Rather efficient but lacking flexibility Great improvements expected with Exchange 2007 / Forefront Security - Per user configuration, Daily updates of spam signature,… In the meantime, we could - Continue evaluation by enabling IMF on gateways, Enabling “junk ” only for test users - Make Cern anti-spam solution compatible with the anti-spam framework of Exchange: Use “SCL” instead of custom “cern spam score” Introduce “junk ” Merge Cern with-list / Outlook with-list
Questions ? (25 CHF / question)