Providing an exceptional Email Hygiene Experience on Exchange Server
SITUATION/CHALLENGE - A big challenge that organizations face is the speed with which malware attacks during the lag period that single engine Anti-virus vendors have in order to create signatures to catch malware. Depending on the malware, some anti-virus labs were able to respond faster than others but organizations would not be able to take advantage of this since they only had a single engine within their organization. This was evident from ongoing AVTest.org data which shows that while some vendors would be faster to respond to some malware, they were rarely consistently among the most responsive. In this way, it is the luck of draw that will determine when an organization received the signatures it needed from its Anti-virus vendor to curb the malware spread. Organizations needed a way to consistently limit their window of vulnerability and reduce the security breaches caused by the ever evolving malware problem.
Name: Brett Tanzer
Team:Microsoft Forefront Security for Exchange Server Engineering team
Team Members: Brett Tanzer, Anthony Blumfield, Bob Bisso, Jay Muller
Company: Microsoft Corporation
SOLUTION - To reduce the window of vulnerability, Forefront partnered with 7 leading anti-Virus labs and integrated Microsoft’s engine with these 7 engines into a single product and enabled customers to scan with up to 5 different engines simultaneously. In this way, when there is a malware outbreak within the organization, Forefront’s response time will be the shortest of the engines that the user has specified. The window of vulnerability is minimized and the damage that the malware is able to inflict on the organization is limited. To further increase their defenses, Forefront also allows the customer to select any combination of engines at various stages in the email pipeline i.e. one set of 5 engines on the Exchange Edge and another set of 5 engines on the internal Hub. In this way, Forefront provides a high level of confidence that any incoming malware will be caught by one of the numerous engines being used to scan. With the heuristic capability of the included engines, many times, even older signatures are able to proactively detect new variants of existing virus families. Forefront also allows organizations to balance performance and security by allowing them to specify how many of the selected engines will be used to scan every piece of mail. In this way, customers in the middle of a malware attack can increase the scanning rigor (i.e. use all 5 engines for every piece of mail) whereas they could use a subset of the engines if it was just day to day operations. Forefront works very closely with our partners to minimize the time between signatures being delivered to Microsoft and when they would be made available to customers. These signatures are re-tested within the Forefront environment and then repackaged and sent out so that customers only have to download signatures from a single location, even though they are using multiple engines. Rigorous internal testing as well as partner and customer testing are used ensure that signatures meet our customers’ needs. To ensure that we continue to provide customers with superior protection, Forefront benchmarks itself against the independent AVTest.org data constantly to confirm that we provide a very consistent high level of protection against live malware.
Info Security Products Guide
CONCLUSION - Messaging security specialists using Forefront Security for Exchange Server have long experienced the high level of performance along with the best malware detection rates in the industry. As the messaging security space continues to evolve, we will be able to offer improved services to our customers through other filtering options including Exchange Hosted Services Filtering, where spam and viruses are filtered by Microsoft before ever reaching our customers’ Exchange Servers. As some businesses move into the services oriented world, others may even decide to host their entire messaging infrastructure, and in those cases, Exchange Online will not only provide messaging services to a business, but also the security and peace of mind knowing that their hosted messaging solution is still being protected by Forefront.
The Forefront Security for Exchange Server engineering team is a dynamic, diverse, highly motivated, and goal driven team that does not shy away from hard work. When deadlines are imminent, long nights full of work (and pizza and chatter) are not uncommon within this team. We are motivated by the challenges we face to solve complex collaboration security problems and drive for continuous innovation in this space. While we work hard, the team also knows how to take time off to relax and get to know the rest of the team as friends – to goof off over beer, chips and salsa as well as celebrate people’s successes. The light-hearted environment ensures that a laugh is always around the corner, enabling the team to work well and meet the goals we have set for ourselves.
Microsoft
2929 Expressway Drive
Ste 300,
Islandia, NY, 11749 USA
Tel: +1-425-706-0044