Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Microsoft to unveil antispam plans

Caller ID authentication technology tries to validate an e-mail's source address

By Paul Roberts, IDG News Service
February 24, 2004
 

Microsoft Corp. Chairman and Chief Software Architect Bill Gates will use this week's RSA Conference in San Francisco to unveil a proposed open technology standard that Microsoft hopes will make it harder to fake the source of unsolicited commercial e-mail.

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

On Tuesday, the company will release a specification for an antispam technology called Caller ID, a Microsoft-developed take on sender authentication technology that tries to validate the source address associated with an e-mail message, according to John Levine, co-chairman of the independent Antispam Research Group, part of the Internet Engineering Task Force (IETF).

A Microsoft spokesman could not confirm the information about Caller ID, but said that Gates will be talking about spam in a "variety of different contexts" in his keynote speech at the RSA security show, and that Microsoft's internal Anti-Spam Technology & Strategy Group will be making an announcement as well.

Sender authentication is rapidly gaining acceptance among e-mail experts and ISPs as a weapon in the fight against spam. On Monday, Sendmail Inc. announced that it will develop and distribute sender authentication technologies to its customers and the open source community to combat spam, viruses and identity fraud in e-mail.

Sendmail will incorporate a "selection of sender authentication technologies" into its open source Mail Transfer Agent (MTA), including a technology called DomainKeys that is championed by Yahoo Inc. and "proposals put forward by Microsoft and others," Sendmail said. A Microsoft spokesman confirmed reports that the company will be releasing a sender authentication plug-in along with Sendmail.

Caller ID is akin to other sender authentication proposals circulating among leading ISPs and e-mail security experts, Levine said. In particular, it is similar to a nascent technology called Sender Policy Framework (SPF), developed by independent antispam researcher Meng Wong of e-mail forwarding service Pobox.com.

Instead of analyzing the content of messages to spot spam, the SPF protocol allows Internet domain administrators to describe their e-mail servers in an SPF record that is attached to the DNS (Domain Name System) record using a special SPF description language. Other Internet domains can then reject any messages that claim to come from that domain but weren't sent from an approved server, Wong said.

Caller ID also relies on administrators adding lists of published e-mail servers to the DNS record for their Internet domains. Whereas SPF uses its own syntax for listing the domain addresses, Microsoft's Caller ID uses XML (Extensible Markup Language) to describe the valid e-mail servers, Levine said.

Also, SPF allows e-mail gateways to analyze the e-mail envelope, a wrapper for the message that is transferred between mail servers before the full message is sent. Messages that do not come from a valid server at the domain are dropped before any message content is sent. In contrast, Caller-ID analyzes the sender IP address information stored in the e-mail message header, which requires the whole message to be downloaded by the receiving e-mail server before it can be accepted or rejected, he said.

Microsoft has been developing Caller ID internally for the last year and consulting with antispam researchers in private for the last month, Wong and Levine said.

The Caller ID technology has both strong points and weaknesses, according to experts.

On the one hand, it requires mail servers to download the entire content of bogus messages before rejecting them, which could put a drag on e-mail servers. And, once it downloads a message, it only checks for it for the sender IP address, as opposed to running the message content through filters and other antispam tools, Levine said.

Caller ID also requires knowledge of XML, which makes implementation more complicated. And the added length of the XML content required by Caller ID may exceed the 512-character limit for response messages to DNS requests, Wong said.

According to the DNS specification, messages that exceed that limit require DNS information to be sent through a separate TCP (Transmission Control Protocol) circuit, instead of using UDP (User Datagram Protocol). While that is technically possible, it is rarely used, introducing an element of uncertainty into the implementation of Caller ID, Wong and Levine said.

"This is a feature that has been specified for 25 years, but never used," Levine said.

However, the technology could do a better job of determining the actual source of an e-mail message than SPF, especially since envelope e-mail addresses don't have to correspond to the e-mail header address, he said.

Microsoft's dominance of the e-mail client market may allow it to extend sender authentication technology to smaller Internet domains and the masses of Internet users, Wong said.

Levine also supports the release of the Caller ID specification and Microsoft's decision to develop Caller ID as an open standard.

"This is an important step. It's the way you get standards to work. You have people pick at them, but implement them," he said.

Caller ID could eventually work alongside SPF, Domain Keys and other sender authentication technologies, he said.

"Solving the spam problem is like curing cancer. It's not one disease but 100 diseases, each with their own issues," he said.

 





 

TOP NEWS:


»  Troubleshooting tool for Java offered
Sun's Java VisualVM open-source technology views apps while they run on a JVM and is billed as all-in-one solution

»  Python backing eyed for NetBeans
Scripting language capabilities of the open-source IDE continue to expand

»  Microsoft sets Windows XP SP3 automatic download for Thursday
The latest service pack for Windows XP will be pushed to Automatic Update at 7a.m. EDT on July 10

»  Real Software, Veryant bolster dev tools
RealBasic, Cobol apps platforms get improvements

»  Microsoft sets hosted-services pricing, irks partners
By offering 38 percent discount to customers who buy entire hosted business productivity suite, Microsoft undercuts partners selling similar services

»  Adobe readying new mashup tool for business users
Mashup interface code-named 'Genesis' will open up desktop 'workspace' combining business application data, documents, analytics, and instant messaging




Develop an integrated management and security strategy
Watch this Webcast and discover a scalable mobile software platform that combines mobile device management, enterprise-to-edge security, email/messaging, and back-office application extension capabilities, to empower employees to do their work anywhere, anytime, on any device. Sponsor: Sybase iAnywhere

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
SEE ALSO
• Ciphertrust adds support for SPF antispoofing


FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist