Cisco Email Security Flashcards
Learn primary technologies.
SenderBase Reputation Filters
SenderBase scores are assigned to IP addresses based on a combination of factors, including email volume and reputation.
Reputation scores in SenderBase may range from -10 to +10, reflecting the likelihood that a sending IP address is trying to send spam. Highly negative scores indicate senders who are very likely to be sending spam; highly positive scores indicate senders who are unlikely to be sending spam.
SenderBase is designed to help email administrators better manage incoming email streams by providing objective data about the identity of senders. SenderBase is akin to a credit reporting service for email, providing data that ISPs and companies can use to differentiate legitimate senders from spam sources. SenderBase provides objective data that allows email administrators to reliably identify and block IP addresses originating unsolicited commercial email (UCE) or to verify the authenticity of legitimate incoming email from business partners, customers or any other important source. What makes SenderBase unique is that it provides a global view of email message volume and organizes the data in a way that it is easy to identify and group related sources of email. SenderBase combines multiple sources of information to determine a “reputation score” for any IP address. This information includes:
Email volume information provided by tens of thousands of organizations that regularly receive Internet email
Spam complaints received by the SpamCop service
Information on other DNS-based blacklists
ESA
Email Security Appliance
CSM
Cisco Security Manager.
Anti-Spam
- False Positive rate of less than 1 in 1,000,000.
- Uses CASE.
- Industry Leading Accuracy.
CASE
Context Adaptive Scanning Engine.
Uses Complete Context of the Message.
1. Message content.
2. Message construction.
3. Sender
4. Where does the call to action take you.
This adds up to industry-leading accuracy.
Forged Email Detection
Protects against BEC attacks focused on executives. Provides detailed logs of all attempts and actions taken.
BEC
Business Email Compromise
Benefits of Global Threat Intelligence (TALOS)
Uses TALOS that combines data from below sources and changes the rules in CES every 3 to 5 minutes.
- 600 billion emails per day.
- 16 billion web requests per day.
- 1.5 million malware samples.
CDP
Cisco Domain Protection
1. Automates the process of implementing DMARC.
Graymail Detection and Safe Unsubscribe
- Precisely classifies and monitors graymail coming in.
- Safe Unsubscribe protects from threats masquerading as unsubscribe links.
- Uniform interface for managing all subscriptions.
Graymail
Marketing
Social Networking
Bulk Messages
AMP
Advanced Malware Protection.
AMP and Cisco Threat Grid
- File reputation scoring and blocking.
- Sandboxing
- File Retrospection
- Mailbox auto-remediation
- Integrates with AMP for endpoints to correlate files, telemetry data, behavior and activity to proactively defend against advanced threats from all possible vectors.
File retrospection
Being able to see what has happened with a file and
SPF
Sender Policy Framework