Anti-Spam / Anti-Virus Solution
Warranty of SwissCenter
- 99.8% of spam detected
- 99.99% of viruses detected
- less than 0.001% false positive rate
- Immeiately reacts to new spam techniques
- Active protection within minutes of a new spam attack
Who could benefit from this solution?
All hosting clients on our standard Linux PHP / mySQL and Microsoft ASP / DotNet platforms can benefit from this revolutionary anti-virus/anti-spam solution. Hosting clients at the "Professional" level and above benefit from this solution at no extra cost. "Classic" and "Premium" clients can activate these services for a monthly fee of 2.00 CHF and 1.00 CHF respectively.
How does SwissCenter get these results?
SwissCenter's unique solution consists of a combination of the qualities of two families of software, anti-virus and anti-spam.
The multi-criteria detection method
The multi-criteria detection method, better known as "spamassassin" and its different plulgins, assigns each message that arrives in an inbox a score based on a number of criteria. If the message score is above a certain level, it is considered to be spam and is marked as such.
Examples of the criteria used by SwissCenter's multi-criteria module:
Message only has text/html MIME parts 1.5
Listed in both Razor and DCC databases 4.0
Listed in DCC (http://rhyolite.com/anti-spam/dcc/) 4.0
HTML included in message 0.0
Message hits more than one network digest check 0.0
Na li¶cie Razor2 (http://razor.sf.net/) 0.5
Razor2 gives engine 8 confidence level above 50% 1.5
Received: contains an IP address used for HELO 2.1
Message-ID is unusually short 1.0
Message-Id is not valid, according to RFC 2822 1.9
Razor2 stwierdził pewno¶ć pomiędzy 51 i 100 0.5
Domain Keys: policy says domain signs some mails 0.0
Received: HELO and IP do not match, but should 2.8
Razor2 gives engine 4 confidence level above 50% 1.5
Listed in Pyzor (http://pyzor.sf.net/) 3.7
Total 24.2
The advantages of this method are as follows:
a. On average, 90-99% of spams are detected.
b. The false-positive rate is generally less than 1%, but depends on software rules: the higher the spam detection rate is raised, the higher will be the false-positive rate.
This method only has a few drawbacks:
a. Adaptation of the detection software to new spam techniques (new types of files, or new types of message or sender obfuscation) may require a software update.
b. The chance of false positives cannot be totally eliminated.
The "Recurrent Pattern Detection" method
The "Recurrent Pattern Detection" method, proposed by the world leader in anti-spam technology, Commtouch®, consists of analyzing not only the contents, but also the method of message distribution on the Internet. When a message is distributed in mass using servers identified as suspect, it is almost certainly spam.
Specifically, the Commtouch system works as follows:
a. The nerve center of the system is a worldwide central collector, to which tens of thousands of emails are redirected each second.
b. Each individual email is identified by a "digital signature" over a few aspects of the file, and constitutes a sort of digital fingerprint that is stored in the central system.
c. When thousands of messages carrying exactly the same signature arrive at the collector in an interval of a few minutes, the central system determines that there is a strong probability that the message is spam, and distributes this information in realtime to the users of the system.
d. The mail servers at SwissCenter, on the basis of the information from the Commtouch central system, identifies a mass email as spam and marks it as such.
The advantages of solutions based on the Recurrent Pattern Detection method are as follows:
a. 90-99% of spam detected.
b. Handling of messages is extremely fast (the signature is very lightweight in comparison to the entire message).
c. After no more than 10 minutes after the mass distribution of an email, its signature is reported by the detection center at Commtouch, and the anti-spam system at SwissCenter stops the message.
d. The system adapts immediately to new spam techniques.
e. The false-positive rate is the lowest possible of any method.
The main weakness of systems using the Recurrent Pattern Detection system is during the first minutes during which a new spam is distributed. The first messages of a spam wave are not detected as such, because there aren't yet enough of them to be identified by the system as spam.
The combination of these two detection methods yields absolutely exceptional results:
- 99.8 % of spam detected
- less than 0.001 % false positive rate
- Immeiately reacts to new spam techniques
- Coverage during the first minutes of a new spam attack, principally due to the multi-criteria system, with coverage of subsequent waves handled by the two systems working together.
|