16
Kaspersky Anti-Spam 3.0
Kaspersky Anti-Spam 3.0 processes e-mail traffic using the following algorithm:
1. Client plug-in module integrates with an installed mail server.
2. Mail server transfers to the client module messages for analysis by the
filtration server.
3. Filtration server checks messages scanning them for signs of spam
and, depending upon the result, modifies them in accordance with the
existing rules.
4. Client plug-in module returns processed messages to the mail server for
delivery.
2.2. Recognition technology
Kaspersky Anti-Spam offers powerful tools for spam detection in e-mail traffic.
This section contains a brief overview of spam recognition technologies
implemented in the product.
2.2.1. Analysis of formal signs
The method uses a set of rules based on examination of certain message
headers and their comparison with sets of headers typical of spam messages. In
addition to header analysis, the application takes into account message
structure, size, presence of attachments and other similar signs.
The method also provides for analysis of data transmitted by the sender during
an SMTP session. In particular, the following information is estimated:
•
IP address of the server that has sent the message, and whether it is
included into white or black lists of recipients;
•
IP addresses of intermediate relay servers obtained from the
Received
headers;
•
e-mail address of message sender and recipients transmitted in SMTP
session commands;
•
presence of the sender's and recipients' addresses in white or black lists;
•
conformity of the addresses transmitted during SMTP session to the set
of addresses specified in message headers and a number of other
checks.