GCN Home > 11/06/06 issue
Defend against a billion spammers (and win)
GCN Lab Review | Sendio's I.C.E. Box appliance successfully stood up to more than a billion pieces of spam and virus-laden e-mail
By John Breeden II, GCN Staff
This is the story of how a filtering appliance successfully stood up to more than a billion pieces of spam- and virus-laden e-mail.

While other units buckled under this deluge, Sendio Inc.s I.C.E. Box, which looks at spam in a completely different way, shot down 100 percent of the bad e-mail, generated no false positives and successfully delivered the good e-mail. It took on an army of bad guys and won.

We learned about I.C.E.s superior spam-fighting capabilities the hard waytrying to sort through our own mountain of junk e-mail. We set up the GCN Lab test network to take in a lot of spam and viruses for our testing zoo. Its an important part of how we test filtering and e-mail scanning devices.

And while this approach worked for many years, we had become victims of our own success. The lab network was getting over 10,000 spam e-mail messages per hour, along with perhaps two or three items of legitimate e-mail. But the good ones were not being delivered in a timely manner, and sometimes not at all.

Overwhelmed defenses

The lab had purchased a Barracuda 200 Spam Firewall to shoot down all the bad e-mail. We figured that, because we only have a handful of valid users, the lower-end Barracuda should be fine.

But we didnt take into account the huge volume of spam. The Barracuda could not handle the load. It was running at between 95 and 98 percent capacity, creating a three-hour queue for e-mail. And even though it was only a small percentage of the total, so much was getting through that the e-mail server was getting overloaded even after the filtering step.

The problem was that even though we only have about five valid user accounts, the Barracuda was processing everything that came into the lab, even if it was going to former employees or to nonvalid, made-up addresses such as bob@gcnlab.com or hrmanager@gcnlab.com.

More news on related topics: Hardware, IT Security, Content / Record Management