Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


May 12, 2000

Content Scanning and User Education Help Reduce Virus Risks

RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I’ll make sure I don't sign this week’s column with "I Love You." I'm amazed how something so simple can cause such destruction and inconvenience. How many of you were drastically affected by last week’s events with the ILOVEYOU worm? How many gateways shut down and Message Transfer Agents (MTAs) stopped? My company's information management folks did a stellar job of proactively preparing and reacting to this real-world problem. I can’t emphasize enough how important content scanning at your gateways and a little user education are in these instances.

Scanning content on your incoming SMTP gateway is an excellent way to protect your organization from viruses such as Melissa, WormExplore, and ILOVEYOU. Content scanners that are available from vendors such as Content Technologies let you scan incoming SMTP traffic for MIME attachments similar to those we saw last week. My company implemented content scanning, and by the time most ILOVEYOU messages reached recipients, they contained nothing more than sterile attachments that informed the user that the file contained a virus and had been cleaned. We configured our antivirus and scanning software to look for anything named LOVE-LETTERS-FOR-YOU.TXT.VBS, LOVE-LETTERS-FOR-YOU.TXT.TXT, VERY FUNNY.VBS, or VERY FUNNY.TXT to avoid last week’s outbreak and copycat outbreaks. We also used third-party add-ons to configure our Exchange Internet Mail Services (IMS) to block anything with a .vbs (VBScript) extension.

Although scanning for attachment content on your SMTP gateway is the best way to protect your organization, it can’t stop everything. That's why user education is the other pillar that good protection must stand on. It seems rather simple: If you don’t know the person who is sending you an attachment with an .exe, .com, .vbs, or other extension, DON’T OPEN IT! However, not all users know that every VBS file is a potential bomb. We must educate Exchange users about these points and encourage them to practice the default rule of not opening any attachment they aren’t sure about. In last week’s outbreak, the users who were savvy enough to not open the suspect messages and instead hit the delete key went about their business as usual. This is a key point: Antivirus software by itself can't protect you from these attacks. It's a combination of a well-implemented gateway and server-based scanning process combined with some solid user education practices. Microsoft Outlook is a rich and powerful client tool. With this richness and power come some vulnerabilities that attacks such as Melissa and ILOVEYOU have exploited. Only through this two-pronged approach can you ensure your organization is protected.

End of Article



Reader Comments
To note a contradiction in this article.. not to open attachments from people that you don't know, is exactly what viruses, trojans, worms, etc.. feed on, that is routing the script to people that are on your mailing list. This is how the "LOVE-bug" and dozens of other malicious scripts penetrate corporate networks so fast.

So, opening attachment from people you don't know is not always the best advice. The best thing to do to protect yourself is to validate via voice that the attachment came from that individual. It's time-consuming but that's the best method of protection. That is unless everyone has forgotten how to use a telephone

anon May 15, 2000


This article doesn't give me any specifics. For example... Mentioning Trend Micro's ScanMail for Exchange allows you to filter out by extension and subject. Or... an indepth comparison between Trend and NAI's Groupware and NAV for Exchange. The article seems watered down with generalities. The only specific info was "Content scanners that are available from vendors such as Content Technologies ". The rest of the info , while good general info, is already known by every LAN administrator who has gone through a virus outbreak.

Moral: More MEAT, Less round about blather.

Peter Richardson May 17, 2000


Duh. What kind of pablum is this? If you're a messaging systems manager or administrator, and you don't know this, you shouldn't have a job. When are you going to give me some information I can use?

Fred July 07, 2000


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Microsoft Warns of Windows Version Expirations

Microsoft warned that this year will see three out-of-date Windows versions slip into retirement. ...

Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...


Related Articles New Love Packs a Wallop

Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Top 5 Key Technologies Changing The Face of Exchange and Data Protection

Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement