SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis case study describes the process of researching and implementing a filter for email 'SPAM' in an organization of modest size running Microsoft Exchange 5.5 and IMC. At the time of the implementation in Fall 2002 there were few commercial software products available to address this issue in a Microsoft environment. While open source approaches to the problem were fairly mature the organization does not have expertise with open source software so a commercial solution was desired. The article outlines the effect of SPAM in our environment the process we went through in selecting and installing an email filtering system and the resulting situation today. It discusses the network environment in place before the implementation and compares native capabilities in MS Exchange 5.5 against our requirements. Based on needs that were not addressed in Exchange IMS I discuss why we chose commercial solutions: X-Wall by Data Enter and SpamAssassin by Deersoft and how they fit in our environment. The philosophy used to make this decision is examined along with the set up and installation of our system. The results of the final system setup are discussed along with 'lessons learned'.