Symantec 10744983 Administration Guide - Page 70

Table 4-1, Description, Verdict, Filtering, Category

Page 70 highlights

70 Configuring email filtering About email filtering actions on a message based on the verdict applied to that message, and the groups that include the message recipient as a member. Table 4-1 describes filtering verdicts by filtering category. Table 4-1 Filtering verdicts by category Filtering Category Verdict Description Email Firewall Directory harvest attack Connection is blocked because an attempt is underway to capture valid email addresses. A directory harvest attack is accomplished by emailing to your domain with a specified number of non-existent recipient addresses sent from the same IP address. Spam attack Connection is blocked because a specified quantity of spam messages has been received from a particular IP address. Virus attack Connection is blocked because a specified quantity of infected messages has been received from a particular IP address. Virus Virus Email is flagged because it contains a virus, based on current Symantec virus filters. Mass-mailing worm Email is flagged because it contains a mass-mailing worm, based on current virus filters from Symantec. Unscannable for Email is flagged because it exceeds the container viruses limits configured on the Scanning Settings page, or because it is unscannable for other reasons, such as the email or the attachement containing malformed MIME. Encrypted attachment Email is flagged because it contains an attachment that is encrypted or password-protected and therefore cannot be scanned Spyware or adware Email is flagged because it contains any of the following types of security risks: spyware, adware, hack tools, dialers, joke programs, or remote access programs. See Security risks for descriptions of these risks. Suspicious attachment Email is flagged because it either shows virus like signs or becuse suspicious new patteres of message flow involving this attachment has been detected.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249

actions on a message based on the verdict applied to that message, and the groups
that include the message recipient as a member.
Table 4-1
describes filtering verdicts by filtering category.
Table 4-1
Filtering verdicts by category
Description
Verdict
Filtering
Category
Connection is blocked because an attempt is underway
to capture valid email addresses. A directory harvest
attack is accomplished by emailing to your domain
with a specified number of non-existent recipient
addresses sent from the same IP address.
Directory
harvest attack
Email Firewall
Connection is blocked because a specified quantity of
spam messages has been received from a particular
IP address.
Spam attack
Connection is blocked because a specified quantity of
infected messages has been received from a particular
IP address.
Virus attack
Email is flagged because it contains a virus, based on
current Symantec virus filters.
Virus
Virus
Email is flagged because it contains a mass-mailing
worm, based on current virus filters from Symantec.
Mass-mailing
worm
Email is flagged because it exceeds the container
limits configured on the Scanning Settings page, or
because it is unscannable for other reasons, such as
the email or the attachement containing malformed
MIME.
Unscannable for
viruses
Email is flagged because it contains an attachment
that is encrypted or password-protected and therefore
cannot be scanned
Encrypted
attachment
Email is flagged because it contains any of the
following types of security risks: spyware, adware,
hack tools, dialers, joke programs, or remote access
programs. See
Security risks
for descriptions of these
risks.
Spyware or
adware
Email is flagged because it either shows virus like
signs or becuse suspicious new patteres of message
flow involving this attachment has been detected.
Suspicious
attachment
Configuring email filtering
About email filtering
70