Title: Office of Information Technology
1Office of Information Technology
http//www.oit.gatech.edu
1
2What have we been doing?
- User education, such as the Whistle article, CSR
meetings
- ITAC committee looking at CAMPUS solution,
consulting with GT Legal on legal requirements,
gathering campus requirements, and drafting the
requirements document - Talking to vendors to understand state of the
art and discussing integration and architectural
issues
- Working to promote needed policy changes
- Demo planned with Proofpoint to measure and
characterize spam, and test a promising type of
architecture
- Research on products, training, and policy
Office of Information Technology
http//www.oit.gatech.edu
2
3Our Research
- Campus input is included in draft requirements
document
- ITAC recommended policy changes
- Talking to vendors, demo of Proofpoint
- Sticker shock on solutions
- It makes sense to outsource to an expert, just
as we do with antivirus
- GT Legal limitations
Office of Information Technology
http//www.oit.gatech.edu
3
4Limitations
- Cannot blindly drop possible spam Note We
can protect ourselves - can drop malware, block
DoS servers, can block servers sending
- us bad or bad volumes of email (eg
Cyberbuzz)
- Cannot have extensive Remote Block List (RBL)
- Cannot block possible spam servers
- Cannot drop outgoing spam
- Cannot drop incoming spam, unless user
individually okays this action
Office of Information Technology
http//www.oit.gatech.edu
4
5Possibilities
- Can drop malware, block DoS servers, block
servers sending us bad or bad volumes of email
(e.g. Cyberbuzz)
- Can drop spam on an individual OK
- Can quarantine system wide and notify user
Note This must be an automated process a human
cannot be responsible for this action
- Can tag possible spam system-wide
Office of Information Technology
http//www.oit.gatech.edu
5
6What we do now
Virus Scanning / No Spam Detection
Sticking our head in the sand and hoping the
problem will go away
Office of Information Technology
http//www.oit.gatech.edu
6
7Spam Tagging
Virus Scanning / Spam Detection (tagging only)
Office of Information Technology
http//www.oit.gatech.edu
7
8Spam Tagging Quarantine
Virus Scanning / Spam Detection (tagging
quarantine)
Office of Information Technology
http//www.oit.gatech.edu
8
9Spam Tagging Quarantine
Virus Scanning / Spam Detection (tagging
quarantine)
SPECTRUM-ONLY SOLUTION
Office of Information Technology
http//www.oit.gatech.edu
9
10Appliance vs Standalone Software
- Both can allow outsourcing of spam and virus
expertise to a specialist vendor.
- Both can be cost effective for administration.
Sun hardware plus commercial software solution
would be preferred over Linux or Windows.
- Both methods can be secure, but patching is
slower on appliances. The Bluesocket failure for
LAWN is a good example. Appliances are
administered to the vendors standards and
timelines, not ours. - Appliances are less flexible if our needs change
(Bluesocket, FW examples, etc. - DNS box is a
good counter example) and vendor must be reliable
and responsive. - Appliances are single use systems. Standalone
boxes can be used to complete multiple tasks
relating to the same functions.
- With appliances, we do not have access to the
source code. Therefore, there is no verifiable
security of the box. We must trust the vendor to
provide good code, supply patches, turn off
un-needed and unwanted services (i.e. telnet) - Sometimes appliances can be cheaper.
Office of Information Technology
http//www.oit.gatech.edu
10
11Beware... Sticker Shock Coming
- CURRENT
- Antivirus per year for desktop clients
36,000 (includes UNIX client that we use on
Spectrum)
- SPAM 0 Usertime Storage Bandwidth
(internal external) Risks
- Units are building non-scalable point solutions
(Spam assassin)
- FUTURE (note Desktop virus scanning is not
included in the quotes below)
- Server-side Antivirus server-side anti-SPAM
- Brightmail - 30,000 per year (two year minimum
, no support included)
- CipherTrust (appliance) Spectrum - 126,200,000
/ year
- NAI McAfee (appliance) - 151,500 initial,
90,000 yearly
- Proofpoint 174,500 initial, 168k yearly
- Proofpoint (we supply AV license) - 99,600
initial, 93,000 yearly
- Proofpoint (appliance) - 182,500 initial,
176k yearly
- Sophos PureMessage - 79,000 / year
- Educational Discounts Apply
Office of Information Technology
http//www.oit.gatech.edu
11