Cyber Security Institute

§ Current Worries

Top 3 Worries

  • Regulations
  • Old Firewall Configurations
  • Security Awareness

§ Listening

For the best information

  • The underground
  • Audible
  • Executive Excellence
  • Music (to keep me sane)

§ Watching

For early warnings

  • 150 Security Websites
  • AP Newsfeeds
  • Vendors

Thursday, June 17, 2004

Net visionary urges e-mail ID standard

Making mass e-mailers identifiable is the first step toward curing the epidemic of spam, said Vint Cerf, one of the architects of the Internet.

Cerf, who co-created the TCP/IP (Transmission Control Protocol/Internet Protocol) of the Internet and now works as chief corporate strategist for MCI, delivered opening remarks Thursday here at the first inaugural Email Technology Conference.  The chief topic of debate at the conference was spam.

Cerf said that standardizing methods for authenticating e-mail senders would ultimately lead to successful filtering—technologies that many companies that attended the conference are developing.  “Getting to critical mass with those sorts of mechanisms will be really interesting,” Cerf said to an audience of technology executives attending the two-day conference.  “Starting from that angle will be more productive than anything,” he added.

Previously, Cerf had jokingly suggested that the industry hold public floggings of spammers as a deterrent.

Spam has skyrocketed to epic proportions since the first e-mail was sent in 1971.  Back then, there were just a few geeks sending e-mail, as Cerf put it in his presentation on the history of the Internet, so there was no one to send unsolicited commercial e-mail.  Spam has risen to such heights partly because of a fundamental weakness in the Simple Mail Transfer Protocol, or SMTP, the messaging protocol that has defined e-mail for more than two decades.

The Federal Trade Commission in its report on the proposed federal Do Not Email registry said the industry needs to develop a common system for verifying e-mail senders before it could work.  Microsoft recently brokered a deal to consolidate Sender Policy Framework and Microsoft’s Caller ID for E-mail—two antispam authentication schemes that look at DNS (Domain Name System) records to determine senders.  Others, including Yahoo, are testing key encryption protocols to verify senders.

Cerf touched on digital signatures as a means to encrypt and verify senders, which his company MCI has used effectively.  The digital signatures, or unique codes given to each individual, are attached to e-mail and must be authenticated to deliver the message.

Various solutions are in development.  Some systems will run into problems in a public forum, he said, because of a lack of a central authority from country to country or state to state to govern the technology. 

Another system, called Cloudmark Immunity, builds up a spam “immunity” based on input on what is unwanted e-mail from employees, according to the company.  The technology, called Virus Outbreak Filters, is used to detect and quarantine suspicious e-mail or viruses before they can infect the entire network.

For consumers, Cerf suggested that everyone adopt a regimen of “cyberhygiene” to protect themselves from spam, viruses and spyware.  Running filters and anti-spyware programs like Ad-aware should be a regular habit, he said, because active HTML (Hypertext Markup Language) and XML (Extensible Markup Language) have made receiving unwanted software to the PC dangerous.

More info:

Posted on 06/17