Home > Ask the Security Experts > Application Security Questions & Answers > Are challenge-response technologies the best way to stop spam?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Are challenge-response technologies the best way to stop spam?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 10 September 2007
Challenge-response spam technologies seem to be very popular. Do they provide the best antispam protection?

>
EXPERT RESPONSE
Spam is hard to define; what one person considers spam could be an important message to someone else. Also, electronic message protocols do not require any prior contact between the sender and the recipient. Consequently, it's not possible to rely on automated authentication. Preventing spam, therefore, requires a multi-layered approach that includes technology, policy, practice and education.

Challenge-response spam technology intercepts incoming emails and sends a challenge to the sender, such as a request to click on a link or answer a simple question. If the sender correctly responds to the challenge message, then the original email is forwarded on; otherwise it is discarded. The process authenticates the sender by confirming that he or she sent the message.

Requiring human verification may seem like quite an effective approach to stopping spam, but there are various drawbacks that you need to consider. The challenge-response process effectively shifts the work of filtering email from the recipient to the sender, legitimate or otherwise. Publishers, however, may not complete the challenge-response when they have thousands of messages to send. Many people don't reply to challenge emails either because they don't know what they are, don't trust them or simply refuse. There are, therefore, many false positives. Other less knowledgeable users often complete the response even when they didn't actually send the original email, producing a false negative.

There is another problem, too. What if the challenge message doesn't reach the sender? The challenge itself could be blocked by the sender's antispam filter! If antispam filters are set to always allow challenges through, then spammers will create spam that looks like a challenge message. Also if the challenges become too predictable, then the spammers will be able to develop computer programs that spot the challenges and auto-send the required responses.

My personal preference is to deploy antispam tools that use a variety of filtering techniques. Bayesian filtering techniques, for example, compare the contents of incoming messages to those of previous legitimate mail. Heuristic filters look for patterns in the content of an email and match them against a database of known spam characteristics. Whitelists and blacklists are time-consuming to keep up to date, but they do provide flexibility so that users can decide which messages should be treated as spam.

Thankfully, server authentication initiatives can control spam at the mail server. Two of the most popular tools are the Sender Policy Framework (SPF) and Sender ID. These authentication mechanisms can verify whether a mail server is authorized to send on behalf of a given domain. Records are published in the domain name system (DNS), which lists the authorized email servers for a domain. If we are ever going to beat spam, it is this type of control that will help in its defeat -- not challenge and response.

More information:

  • Is Sender ID effective? Michael Cobb examines the authentication mechanism.
  • Challenge-response tools received high marks, according to a recent independent survey. Find out which antispam technologies didn't make the grade.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    What risks do application virtualization products pose to enterprise security?
    Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
    How can quality assurance tools aid software development?
    Should UTM and Web security filtering software be used together?
    Is the iPhone amenable to any method of email encryption?
    What are effective ways to stop instant messaging (IM) spam?
    Is it impossible to successfully remove a rootkit?
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?

    Email Security Appliances
    Trend Micro joins growing email encryption market
    Code Green enters consolidated DLP Market
    Small email security vendors thrive in saturated market
    Tumbleweed merger seen as a negative for email security customers
    Companies still monitoring email manually, survey finds
    Trend Micro aims Message Archiver at midmarket
    Most antispam technologies get failing grade
    Security vendor Postini acquired by Google
    How vulnerable are document scanners and other 'scan to email' appliances?
    ClamAV clamps down on e-mail security

    Spam and Antispam
    Facebook wins spam lawsuit
    Quiz: Email security essentials
    Phishing, malware laden USB sticks stoke holiday attacks
    McColo shutdown won't stop spam, malware, warn security experts
    Phishing, identity theft keeps law enforcement, researchers occupied
    Sophos sees increase in malicious email attachments
    What are effective ways to stop instant messaging (IM) spam?
    Malicious program poses as Windows Security Center
    Spam network halted by U.S., New Zealand officials
    McAfee to acquire Secure Computing
    Spam and Antispam Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Defense Message System  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts