Cisco Cisco Email Security Appliance C160 Mode D'Emploi
Chapter 8 Anti-Spam
8-8
Cisco IronPort AsyncOS 7.5 for Email Configuration Guide
OL-25136-01
Analyzing multi-dimensional relationships allows CASE to catch a broad range
of threats while maintaining exceptional accuracy. For example, a message that
has content claiming to be from a legitimate financial institution but that is sent
from an IP address on a consumer broadband network or that contains a URL
hosted on a “zombie” PC will be viewed as suspicious. In contrast, a message
coming from a pharmaceutical company with a positive reputation will not be
tagged as spam even if the message contains words closely correlated with spam.
of threats while maintaining exceptional accuracy. For example, a message that
has content claiming to be from a legitimate financial institution but that is sent
from an IP address on a consumer broadband network or that contains a URL
hosted on a “zombie” PC will be viewed as suspicious. In contrast, a message
coming from a pharmaceutical company with a positive reputation will not be
tagged as spam even if the message contains words closely correlated with spam.
Industry-Leading Performance
CASE combines the following features to deliver accurate verdicts quickly:
•
Multiple threats are scanned for in a single pass
•
Dynamic “early exit” system
System performance is optimized using Cisco IronPort's unique “early exit”
system. Cisco IronPort developed a proprietary algorithm to determine the
order in which rules are applied based on rule accuracy and computational
expense. Lighter and more accurate rules are run first, and if a verdict is
reached, additional rules are not required. This improves system throughput,
allowing our products to meet the needs of large-scale enterprises.
Conversely, the efficiency of the engine allows for implementation on
low-cost hardware, making Cisco IronPort’s security services attractive for
low-end customers.
system. Cisco IronPort developed a proprietary algorithm to determine the
order in which rules are applied based on rule accuracy and computational
expense. Lighter and more accurate rules are run first, and if a verdict is
reached, additional rules are not required. This improves system throughput,
allowing our products to meet the needs of large-scale enterprises.
Conversely, the efficiency of the engine allows for implementation on
low-cost hardware, making Cisco IronPort’s security services attractive for
low-end customers.
•
Off-box network calculations
International Users
IronPort Anti-Spam is tuned to deliver industry-leading efficacy world-wide. In
addition to locale-specific content-aware threat detection techniques, you can
further optimize anti-spam scanning for specific regions using regional rules
profiles. The anti-spam engine includes a regional rules profile. The regional rules
profile targets spam on a regional basis. For example, China and Taiwan receive
a high percentage of spam in traditional or modern Chinese. The Chinese regional
rules are optimized for this type of spam. Cisco strongly recommends you use the
Chinese regional rules profile if you receive mail primarily for mainland China,
Taiwan, and Hong Kong. You can enable the regional rules profile from Security
Services > IronPort Anti-Spam.
addition to locale-specific content-aware threat detection techniques, you can
further optimize anti-spam scanning for specific regions using regional rules
profiles. The anti-spam engine includes a regional rules profile. The regional rules
profile targets spam on a regional basis. For example, China and Taiwan receive
a high percentage of spam in traditional or modern Chinese. The Chinese regional
rules are optimized for this type of spam. Cisco strongly recommends you use the
Chinese regional rules profile if you receive mail primarily for mainland China,
Taiwan, and Hong Kong. You can enable the regional rules profile from Security
Services > IronPort Anti-Spam.