 GFi
|
 Trend Micro
|
Anti-spam for Exchange, anti-phishing and email management
GFI MailEssentials for Exchange/SMTP offers spam and phishing protection and email management at server level. GFI MailEssentials offers a fast set-up and a high spam detection rate using Bayesian analysis and other methods - no configuration required, very low false positives through its automatic whitelist, and the ability to automatically adapt to your email environment to constantly tune and improve spam detection. GFI MailEssentials also adds email management tools to your mail server: disclaimers, email archiving and monitoring, Internet mail reporting, list server, server-based auto replies and POP3 downloading.
Anti-spam software for Exchange server
With fraudulent, inappropriate and offensive emails being delivered in vast quantities to businesses every day, anti-spam software is a vital component of your network security strategy. Spam wastes network users’ time and network resources, and can also be dangerous. GFI MailEssentials offers anti-spam for Exchange server and other email servers and eliminates the need to install and update anti-spam software on each desktop.
GFI MailEssentials offers a fast set-up and a high spam detection rate using Bayesian filtering and other methods – no configuration required, very low false positives through its automatic whitelist, and the ability to automatically adapt to your email environment to constantly tune and improve spam detection. GFI MailEssentials will eliminate over 98% of the spam from your network! GFI MailEssentials also detects and blocks phishing emails through a system of Uniform Resource Identifier (URI) and keyword checks. In addition to anti-spam filtering and anti-phishing protection, GFI MailEssentials also adds email management tools to your mail server: disclaimers, mail monitoring, Internet mail reporting, list server, server-based auto replies and POP3 downloading.
Server-based anti-spam and anti-phishing
GFI MailEssentials is server-based and installs on the mail server or at the Gateway, eliminating the deployment and administration hassle of desktop-based anti-spam and anti-phishing products. Desktop-based software involves training your users to create anti-spam rule sets, and subsequently users have to spend time updating these rules. Besides, this system does not prevent your server message stores from filling up with spam.
Bayesian filtering technology
Bayesian filtering is widely acknowledged by leading experts and publications as the best way to catch spam. A Bayesian filter uses a mathematical approach based on known spam and ham (valid email). This gives it a tremendous advantage over other spam solutions that just check for keywords or rely on downloading signatures of known spam. GFI’s Bayesian filter uses an advanced mathematical formula and a dataset which is ‘custom-created’ for your installation: The spam data is continuously updated by GFI and is automatically downloaded by GFI MailEssentials, whereas the ham data is automatically collected from your own outbound mail. This means that the Bayesian filter is constantly learning new spam tricks, and spammers cannot circumvent the dataset used. This results in a 98+% spam detection rate, after the required two-week learning period. In short, Bayesian filtering has the following advantages:
- Looks at the whole spam message, not just keywords or known spam signatures
- Learns from your outbound email (ham) and therefore greatly reduces false positives
- Adapts itself over time by learning about new spam and new valid email
- Dataset is unique to your company, making it impossible to bypass
- Multilingual and international
Email anti-virus, content policies, exploit detection and anti-trojan
GFI MailSecurity for Exchange/SMTP is an email content policies, exploit detection, threats analysis and anti-virus solution that removes all types of email-borne threats before they can affect your email users. GFI MailSecurity's key features include multiple virus engines, to guarantee higher detection rate and faster response to new viruses; email content and attachment checking, to quarantine dangerous attachments and content; an exploit shield, to protect against present and future viruses based on exploits (e.g., Nimda, Bugbear); an HTML Sanitizer, to disable HTML scripts; a Trojan & Executable Scanner, to detect malicious executables; and more.
Email anti-virus software protecting against email viruses, exploits and trojans
The need to monitor email messages for dangerous, offensive or confidential content has never been more evident. The most deadly viruses, able to cripple your email server and corporate network in minutes, are being distributed worldwide via email in a matter of hours. Products that perform single vendor anti-virus scanning do not provide sufficient protection. Worse still, email has become the means for installing backdoors (trojans) and other harmful programs to help potential intruders break into your network. Products restricted to a single anti-virus engine will not protect against email exploits and attacks of this kind.
Your only defense is to install comprehensive granular user-based email content policy and anti-virus software to safeguard your mail server and network. GFI MailSecurity acts as an email firewall and provides mail security by protecting you from email viruses, exploits and threats, as well as email attacks targeted at your organization.
GFI MailSecurity may be deployed in Gateway or VS API mode. The gateway version should be deployed at the perimeter of the network as an email relay server and scans inbound and outbound mail. The VS API version integrates seamlessly with Exchange Server 2000/2003 and scans the Exchange information stores.
Virus checking with multiple virus scanning engines
GFI MailSecurity uses multiple virus scanners to scan inbound email. Using multiple scanners drastically reduces the average time to obtain virus signatures which combat the latest threats, and therefore greatly reduces the chances of an infection. The reason for this is that a single anti-virus company can never ALWAYS be the quickest to respond. For each outbreak, virus companies have varying response times to a virus, depending on where the virus was discovered, etc. By using multiple virus engines, you have a much better chance of having at least one of your virus engines up-to-date and able to protect against the latest virus. In addition, since each engine has its own heuristics and methods, one virus engine is likely to be better at detecting a particular virus and its variants, while another virus engine would be stronger at detecting a different virus. Overall, more virus engines means better protection.
Note: Independent research showed that brand names are no guarantee for faster response times; in fact some of the big brand names were found to be among the slowest.
Scan against trojans and executables
The GFI MailSecurity Trojan & Executable Scanner detects unknown malicious executables (for example, trojans) by analyzing what an executable does. Trojans are dangerous as they can enter a victim’s computer undetected, granting an attacker unrestricted access to the data stored on that computer. Anti-virus software will NOT catch unknown trojans because it is signature-based. The Trojan & Executable Scanner takes a different approach by using built-in intelligence to rate an executable's risk level. It does this by disassembling the executable, detecting in real time what it might do, and comparing its actions to a database of malicious actions. The scanner then quarantines any executables that perform suspicious activities, such as accessing a modem, making network connections or accessing the address book.
Real-time HTTP/FTP monitoring, anti-virus & access control
GFI WebMonitor is a utility for Microsoft ISA Server that allows you to monitor the sites users are browsing and what files they are downloading – in REAL TIME. In addition it can block access to adult sites as well as performing anti-virus scanning on all downloads. GFI WebMonitor is the perfect solution to transparently exercise a degree of access control over users’ browsing habits and ensure legal compliance – in a manner that will not alienate your network users!
Internet access control & real time monitoring of users’ web activity
Companies must exercise some control over users’ web browsing habits – not only to ensure productive use of the Internet but also to safeguard users from adult sites and to ensure that downloads are virus free. The traditional full-blown web proxy filters are cumbersome to install/administer and expensive to buy, while log file analyzers are awkward to use and do not allow for real-time monitoring and blocking.
Virus scanning of downloads and real-time access control
GFI WebMonitor is a utility for Microsoft ISA Server that allows you to monitor the sites users are browsing and what files they are downloading – in REAL TIME. In addition it can block access to adult sites as well as performing anti-virus scanning on all downloads. GFI WebMonitor is the perfect solution to transparently exercise a degree of access control over users’ browsing habits and ensure legal compliance – in a manner that will not alienate your network users!
Internet access control made easy and affordable
With GFI WebMonitor, administrators can review current and recent website access and downloads right from their browser. They can type in http://monitor.isa to see a list of websites accessed by users and files downloaded. GFI WebMonitor costs a fraction of the price of other Internet access control, monitoring and anti-virus products. For networks of up to 50 users, the cost is USD 695, for networks of up to 100 users, the cost is USD 1195 and for networks of up to 500 users, the cost is USD 4500. Because the product runs on ISA Server, no dedicated machine or network re-configuration is required.
Multiple anti-virus protection through Norman Virus Control and BitDefender
GFI WebMonitor is bundled with Norman Virus Control and BitDefender. Norman Virus Control is an industrial strength virus engine that has received the 100% Virus Bulletin award 16 times running. It also has ICSA and Checkmark certification. BitDefender is a very fast and flexible virus engine that excels in the number of formats it can recognize and scan. BitDefender is ICSA certified and has won the 100% Virus Bulletin award and the European Information Technologies Prize 2002. GFI WebMonitor automatically checks and updates the Norman Virus Control and BitDefender definition files as they become available. The GFI WebMonitor price includes updates for one year.
Malware (Trojans, spyware, etc) blocking via Kaspersky – optional
To achieve even greater security and benefit from scanning via multiple virus engines, users can add the Kaspersky SuperSecure anti-virus engine, available as an optional add-on. The Kaspersky SuperSecure database includes support for the detection of malicious software that can perform remote administration, keyboard espionage, password detection, automatic dial-up to paid sites, automatic downloads of files containing explicit materials and more. GFI WebMonitor automatically checks and updates the Kaspersky definition files as they become available.
Blocking of adult websites based on Yahoo!’s SafeSearch
GFI WebMonitor allows you to block adult websites depending on their content classification by Yahoo! SafeSearch. Rather than using a custom local categorization database, which will invariably fast become out-of-date with the hundreds of new adult content sites being introduced daily. Through GFI WebMonitor, you need not manually update filter lists, which is both time-consuming and expensive. When a user requests access to a particular site, GFI WebMonitor queries the Yahoo! SafeSearch service to see whether the site contains adult content. If it does, the site is added on the fly to ISA Server ‘Adult’ Destination set. An ISA administrator can block this URL set by creating a common access blocking rule on the server. It is also possible to further configure this GFI WebMonitor feature by editing a script to use different websites for site-checking, such as Google; however, these sites' terms and conditions apply.
Real filetype signature checks
Dangerous files (such as Trojan downloader programs) often attempt to penetrate a system masked as innocuous files. GFI WebMonitor uses its built-in file signature scanner to analyze and detect the REAL filetype signatures of downloaded HTTP/FTP files.
Trend Micro: Comprehensive Outbreak Protection
Trend Micro is a global leading provider of comprehensive antivirus, Internet content security, and outbreak management software and services. Our products and services are designed to deliver coordinated protection at application and network layers to proactively manage the outbreak lifecycle—from vulnerability prevention to malicious code prevention and elimination. Trend Micro's product and services categories are designed to address all major areas of the enterprise including:
Desktop & Client – Virus protection for the enterprise end-user or home user.
Outbreak Management – Centralized outbreak management and threat-specific expertise and knowledge for proactive outbreak lifecycle management.
Network Protection – Network virus and network layer threat protection for the enterprise.
Email & Groupware –Virus and content security protection for Lotus Notes and Microsoft Exchange environments.
Internet Gateway – Virus, content security, and spam protection for the SMTP, HTTP, and FTP server gateway.
File Server & Storage – Virus protection for multiple servers and domains.
Mobile Security – Virus protection for data-centric smartphones & PDAs.
|