
  1. 1、本文档共45页,可阅读全部内容。
  2. 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
  3. 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载
  4. 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Cloud Pre-Filter and IP Filtering When IMSVA receives mail from the Cloud Pre-Filter, the SMTP client address is the IP-address of the Cloud Pre-Filter. All IP Filtering features (IP Profiler and Email Reputation) become unusable when using the Cloud Pre-Filter for incoming mail. The Cloud Pre-Filter has its own Email Reputation Service. IP Filtering can be disabled if IP Profiler is not used to detect violations in outgoing mail. Classification * * Pre-Filter Quarantine Classification * * All messages that must be quarantined get the following header: When IMSVA detects the presence of the X-IMHT-EXT header, it moves the message to the Cloud Pre-Filter Quarantine Area. The administrator and end users can access and process these messages as normal quarantined mail. Web Reputation check (“Worry-free click”) principles TMASE extracts URLs during the anti-spam scanning If the URL reputation is not cached, TMUFE contacts the Rating Service The Rating Service returns the Web Reputation Score IMSVA compares the Web Reputation Score with the Threshold Classification * * URL Rating sequence Classification * * GET /RT/Size/Encrypted Request HTTP/1.1 User-Agent: TMUFE ... HTTP/1.1 200 OK Server: Trend Micro ... Size/Encrypted Result Web Reputation Scanning Result Classification * * Smart Feedback TMASE may provide report the feedback about the detected URLs and scanning results to the Trend Micro Feedback Service after extracting the URLs from the message. Only suspicious messages generate feedback. The feedback helps to do the SPN self-tuning. The feedback includes the following data: Extracted URLs Source IP address HELO string General message properties: size, number of lines, number of HTML tags MD5 hash values of the message headers, body and attachments Calculated TMASE score Criteria (rule id) for triggering the feedback Classification * * Spoofing and Anti-spoofing Classification * * Anti-spo


xina171127 + 关注


