Wednesday, June 15, 2011
Adding another tool in the fight against spam: enhanced email authentication for Postini customers
We’re constantly working to protect our users from email spam and phishing attempts. Some examples of these efforts include educating users about phishing and supporting open standards for email authentication such as DomainKeys Identified Mail (DKIM) in Google Apps - which can help reduce the risk of phishing attacks sent from spoofed domains.
And now our Postini services customers can take advantage of new capabilities to help protect users on legacy email servers such as Microsoft(R) Exchange. Recipient Policy Framework (RPF) is a new feature we developed for Postini that allows customers to authenticate inbound email to help ensure that each message is actually coming from who it says it’s from.
RPF uses an open Internet standard called Sender Policy Framework to authenticate inbound emails and allows customers to define policies on how to handle emails that don’t check out. When RPF is enabled by an administrator, it will help detect and block email spam and other suspicious messages.
To learn more about Postini services including our email security, compliance and continuity products, please visit our web site where you can compare pricing and sign up online.
Wednesday, September 22, 2010
Join us! Live Google Postini webinar featuring Enterprise Holdings on 9/28
Join us for a free webinar on September 28, where Michael Preuss, Manager of Windows Engineering for Enterprise Holdings, will discuss why his company chose a cloud-based message security solution and how Postini’s powerful spam filtering technology was able to help them address their email security challenges. Adam Swidler, Senior Manager with Google Enterprise, will also provide an overview of Google’s security solutions and facilitate a deep-dive discussion into best-in-class practices for organizations interested in enterprise-grade protection.
A live Q & A session will follow. We hope you can join us!
Message Security in the Cloud
Tuesday, September 28th, 2010
10 a.m. PDT / 1 p.m. EDT / 6 p.m. GMT
Register here
Posted by Adrian Soghoian, Google Postini Services team
Wednesday, April 14, 2010
Q1'10 spam & virus trends from Postini
Overall, spam volume fell 12% from Q4’09 to Q1’10, which follows a trend of quarterly decreases in overall spam levels that started after the surge in Q2’09. This may be attributed to some of the recent takedowns, but spam volume was still 6% higher this quarter than it was during the same period in 2009, and spam volume as a percentage of total email messages is holding steady.

Recently, our data centers showed a 30% increase in the size of individual spam messages (measured in bytes) that occurred toward the end of March, as shown below.

This spike points to a resurgence of image spam, similar to what we reported in Q2’09. This is likely due to the fact that reusing image templates makes it easier and faster for spammers to start new campaigns.

Virus levels fall after Q4’09 surge
During 2009, spam with attached viruses increased tenfold, with levels rising from 0.3% of total spam in the first half of the year to 3.7% in the second. Postini filters blocked more than 100 million virus-bearing messages per day during the worst of the attack.
Although the botnets that distribute spam are mindless drones, the spammers that take advantage of these botnets are a highly active and adaptable group. This is evidenced by the varied techniques and tactics that they employ in an ongoing effort to evade spam filters and deliver messages to their targets.
Wednesday, March 31, 2010
Give your Google Message Security filters a tune-up
Announcing Dual Delivery for Google Postini Services
Dual Delivery can also be used as a secondary email access point. If users are unable to access their primary mailbox for any reason, or if admins want to give users cloud-based remote or mobile email access, Dual Delivery can provide read/write email access through a secondary inbox.
Monday, March 15, 2010
Google Message Security wins SC Magazine Reader Trust award
A few months back, we learned that Google Message Security, powered by Postini, was selected as a finalist in the 2010 SC Awards for outstanding achievement in IT security. Today, we are thrilled to announce that Google Message Security has received the Reader Trust Award for Best Managed Security Service.At Google, we think about the user experience in all that we do, so we are especially honored to receive this award from the Reader Trust Voting Panel, which consists of security and technology experts from large, medium and small enterprises from all major vertical markets.
The Postini team would like to thank SC Magazine and the many readers who voted for Google Message Security. We'd also like to congratulate our fellow nominees and award-winners and acknowledge their contributions to the field of online security.
For more information on Google Message Security and the Postini suite of security and archiving products, please visit, www.google.com/postini
Posted by Gopal Shah, Google Postini team
Thursday, February 4, 2010
Bringing log search to the cloud: Introducing Message Log Search for Postini
When messages pass through the Postini service, header and transaction data about these messages is stored in a log. Previously, admins only had access to this data through customer support. With the Message Log Search feature, email administrators can now easily run searches on these logs and drill down to the details about how specific messages were processed.
For example, admins can view the disposition of messages, such as whether a message or group of messages was delivered, quarantined, archived, or encrypted.
Say an admin was checking the delivery status of all inbound emails from Matthew Smith:

Message Log Search returns results which include who received the message, date/time, disposition, and more. Click the image below for full view.

Customers trying a beta version of Message Log Search have found many useful, time-saving applications for the feature. For example, Dave Lugo at Affiliated Computer Systems is "very happy" that Message Log Search helps him track errant emails and easily resolve the "they didn't get it / we didn't get it" tickets he receives from his users. Joe Stark at HeidelbergCement uses log searching to "proactively search for problem senders" and block them entirely from his network.
Other customers have found that the Message Log Search interface is "very fast and responsive," and helps them to determine the effectiveness of new content policies and gain insight into traffic patterns across their organization.
These are a few examples that illustrate the flexibility and power of Message Log Search, and starting today, you can try the feature for yourself. Message Log Search is now available through the Postini service administration console to Postini and Google Apps Premier Edition customers.
For more information on Google Postini Services, please visit www.google.com/postini.
Note: Message Log Search data is managed and stored in Google datacenters pursuant to the privacy and data confidentiality provisions spelled out in our customer agreements. The message security service stores information about messages in a log, such as how it is processed, but does not store the content of messages.
Posted by Gopal Shah, Google Postini team
Thursday, October 8, 2009
Research finds that IT departments are thinking in the cloud
We're sharing the results of the study in a new whitepaper: the Google Communications Intelligence Report. The findings provide some insights on what types of organizations are moving to the cloud, what value they find there, and what the key drivers for and barriers to adoption are. Some of the key takeaways follow:
- More than 60% of respondents indicated that the IT department holds the majority of the responsibility for communications security and compliance, but fewer than 20% feel they are well equipped to handle it.
- Email security, web security, and messaging are the cloud applications most widely adopted, and organizations using these applications in the cloud report higher satisfaction than users of traditional platforms.
- Ease of use is cited as the key motivator for transitioning to cloud-based applications.
- Although price is mentioned as a key deterrent for respondents who are not yet using cloud-based apps, value is cited as a key benefit by respondents who already work in the cloud.
Posted by Adam Swidler, Google Postini Services team
Thursday, October 1, 2009
Q3'09 Spam & Virus Trends from Postini
Back in 2007, we saw the first variants of a big virus attack later labeled the "Storm" virus. During that summer, Storm attacked with force, pushing payload spam activity to then-unprecedented levels and sustaining them for several months. The security community eventually caught up, and payload spam activity fell to nominal levels and held there. That is, until this year: Q2'09 saw a significant surge in payload spam activity, and now Q3'09 levels have made the 2007 Storm virus attack look small in comparison. Postini data centers have blocked more than 100 million viruses every day during what has so far been the height of the attack.
However, at these volumes, it takes only a tiny fraction of the recipients being fooled for the spammers to add hundreds of computers to their botnets every day.
ISP takedowns continue, overall spam levels steady
Last quarter we saw a temporary 30% drop in overall spam levels following the 3FN ISP takedown, and the ISP takedown trend continues into Q3 with a new culprit called Real Host, a large Latvia-based ISP that was disconnected by upstream providers on August 1. This takedown didn't have the same drastic effects of McColo (last November), but it was comparable to 3FN. Ultimately, the effects of the Real Host takedown lasted only two days, with an initial 30% drop in spam followed by a quick resurgence.
Last quarter we reported on the trend toward larger message sizes, measured in bytes. The trend has continued into this quarter, making 2009 a year of resurgence in old techniques such as image spam and payload viruses. When considering the spam bytes processed per user, growth has been steep in 2009, with Q3'09 rates up 123% from Q3'08.
Organizations that process spam inside their network should pay attention to this trend. The larger sizes create a bandwidth burden that can impact speed across your network. As the chart shows, Q2'09 delivered the record high to date for spam size – and subsequently for bandwidth drag for teams that manage spam in-house, potentially forcing those organizations to upgrade their capacity limits.
Best practices to optimize your enterprise spam filter
A common piece of feedback we get from our customers is that many of the messages in their spam folder or quarantine seem to come from "them" – from what appear to be valid email addresses from their own domain. These email addresses are actually spoofed (a common technique to mask the real origins of a message), and spammers employ this technique to take advantage of a mistake organizations sometimes make in configuring their spam filters: adding their own domain to their approved sender list.
While this might seem like a good idea at first glance – we want to make sure we don't block email from our colleagues, right? – in practice all it does is open your organization up to spoofed email. With that in mind, we strongly recommend that organizations not add their own domains to their approved sender lists. (Don't worry – legitimate mail from within your domain is correctly identified by filters and generally gets through just fine.)
For more information on how Google email security services, powered by Postini, can help your organization provide better spam protection and take a load off your network by halting spam in the cloud, visit www.google.com/postini.
Posted by Adam Swidler, Google Postini Services team
Tuesday, September 29, 2009
How Google tackles IT security – and what you can learn from it
Providers of cloud computing services like Google are equipped to protect millions of users' data every day – it's core to how we run our business. Our users enjoy our economies of scale at minimal expense. We also employ some of the world's best security experts to help to make sure that your data stays safe.
On October 1, join us for a live webcast with some of our top security experts who are on the front lines of fighting spam, malware, and phishing for Google Apps users, designing identity management systems for hosted web apps, and monitoring the Google network for potential threats. Register for this live webcast, “How Google Tackles IT Security – and What You Can Learn From It,” to learn about security in the cloud and get your questions answered by members of Google's Security team. Participants include:
Eran Feigenbaum – As the Director of Security for Google Apps, Eran Feigenbaum defines and implements security strategy for Google's suite of solutions for enterprises. Prior to joining Google in 2007, Eran was the US Chief Information Security Officer for PricewaterhouseCoopers.
John Flynn – John “Four” Flynn has an extensive background in network monitoring, intrusion detection, and incident response. John currently leads Google's Security Monitoring program and is a founder of Google's Security Metrics group.
Bradley Taylor – Gmail's “Spam Czar,” Brad Taylor leads Gmail's technical anti-spam, anti-abuse, and email delivery engineering efforts. Brad has played a key role in the development of Gmail's spam filter since Gmail launched in April, 2004.
Eric Sachs – Eric Sachs has over 15 years of experience with user identity and security for hosted web applications. During his years at Google, he has worked as a Product Manager for many services including Google Accounts, Google Apps, orkut, Google Health, Google Security, and Internal Systems.
While circumstances may vary, most IT departments face similar security challenges. Find out more from the people who confront these issues every day here at Google.
Join us for our live webcast to learn about the people, best practices, and technologies that we have in place to minimize security threats.
How Google Tackles IT Security – and What You Can Learn From It
Thursday, October 1, 2009
11:00 a.m. PDT / 2:00 p.m. EDT / 6:00 p.m. GMT
We hope to see you there.
Posted by Serena Satyasai, Google Apps team
Wednesday, July 1, 2009
Q2 2009 Spam Trends
Our "Spam Trend" update last quarter summarized the rise in both levels and types of spam, with new players and techniques entering the market. This quarter, proliferation continues, with an unpredictable pattern of drops and spikes as 2009 moves along. Overall, spam is measurably up: Q2'09 average spam levels are 53% higher than in Q1'09 and 6% higher than in Q2'08.
After last November's McColo ISP takedown, when spam volumes dropped by 70%, spammers worked overtime to fill the void. They succeeded: Within four months, spam levels rose back to pre-McColo levels. This upward trend continued through June 4, when another large ISP spam source, 3FN, was reported to have been dismantled. Spam volume immediately dropped 30% – not as extreme as McColo, but still significant. Although this created a sudden dip in spam levels, it also created an open invitation for opportunistic spammers to once again seize a market opportunity.
Over the coming months, we anticipate watching new players once again drive spam levels back up. Since June 4, spammers have already made up a significant amount of ground, climbing 14% from the initial drop.
Here's what the trend looked like, as tracked through Postini filters, over the past six months:
"Unpredictability" summarizes the overall trend as Q2'09 winds down and spammers test both new and "retro" techniques. For example, on June 18 we tracked a new attack that unleashed 50% of a typical day's spam volume in just two hours' time. This attack used a simple "newsletter" template – somewhat "old school" by today's spam standard – with malevolent links and images inserted into the content. Google's Postini filters detected more than 11,000 variants of this spam during those two hours. Because this spam enabled spoofing of the recipient domain (meaning the "from" field was falsified), distribution lists were especially hard-hit by this attack.
One of the other trends we're watching closely is the sudden popularity of "image spam" – a form of spam that rose to prominence in 2007, before most anti-spam filters learned how to block it. It's simple stuff: basic email with advertising content, usually containing a related image. They can also include malicious links or content – and either way, the large file size of an image spam can place a heavy load on an email network.
An image spam email might look something like this:
There are a couple of possible explanations for the resurgence in image spam, despite the fact that most spam filters out there have adapted to the technique. One theory is that this wave is designed to test the defenses of the different spam filters out there, so that spammers can do statistical analysis on what subject lines and content have the highest probability of success.
Another is that there may be some new players entering the spam game, following the McColo and 3FN takedowns, and these new players are opening with some well-tested techniques. Either way, we're watching this trend and will share insights as we gain them in the weeks and months ahead.
As you can see in the chart below, June's activity is almost as high as the two-month payload virus surge seen in Q3'07. Fortunately, Google's Postini zero-hour heuristics detected this uprise early and kept payload attacks in the cloud and away from users' email networks.
Everything old might be new again
In summary, Q2'09 saw continued unpredictability and the resurgence of old-style spam attacks. Are spammers finally running out of original ideas? And if so, like Hollywood, are we now starting to see spam "remakes," based on originals of a few years ago? And what are spammers looking to accomplish as they unleash these remakes? Only time will tell.
Monday, April 6, 2009
In Cloud We Trust
Q: Ten years ago, packaged software was the norm. Yet Postini built a hosted service - what we today call cloud computing. Why did you drive a cloud architecture for Postini?
Scott: We believed that by offering a service infrastructure we could prove a lower TCO than an on-premise alternative. With that service infrastructure aggregating data, we'd also have insight into a wider sample of data, thus providing a more effective solution.
Q: How did the idea of having a "perimeter protection service" to protect email networks in the cloud first evolve? Is the right model for the future?
Scott: Postini's innovation was to see SMTP as an integration API and DNS as a way to access traffic, thus putting us "upstream" of the customers' infrastructure, alleviating integration challenges and stopping problems before they reached the firewall. We saw this as better for a number of reasons.
Email servers have a long shelf life, and customers typically add incrementally to their system, rather than get a complete replacement. This causes a management problem for IT, creating a heterogeneous environment into which they must layer in security and compliance services.
We never saw ourselves as just an anti-spam company, so we built infrastructure that allowed a business rule to be configured as tightly as a content string for a single user. This design decision is inherently linked to the cloud. It allows us to deliver a better anti-spam solution, and also expand into content compliance areas.
Q. Wolfgang, you've been keeping a tight watch on the latest vulnerabilities impacting networks worldwide via your Laws of Vulnerabilities research. What are some of the trends you're seeing in 2009?
Wolfgang: Our research into vulnerability trends has shown that the industry overall did not improve significantly its ability to address security problems in a timely manner At the same time attackers have been getting faster and more sophisticated. Proactive security by maintaining systems updated with the latest patches is the cheapest of all security tools, nevertheless it has not grown in the way I would have hoped.
The first three months of 2009 have been a great example. We've seen Conficker infect millions of machines. The simplest way of preventing the outbreak would have been to preventively apply a patch, if available, to stop the worm. But figuring out such patches takes time. In contrast to worms of the past which often gave us months to react, Conficker activated only two weeks after the official release of the patch, clearly showing that attackers have become faster in their timing. It's getting tougher for patches to keep up.
Q: As network security budgets continue to tighten, how can "security as a service" be advantageous to users?
Wolfgang: SaaS solutions have the advantage that they have minimal setup and are immediately usable. Companies can get their feet wet with a small pilot, show success, and then grow it at their own pace to address larger needs. Organizations of any size can take advantage of the functionality and the predictable steady cost of cloud solutions, while at the same time enjoying the usability brought through constant improvements.
Scott: Agreed. As IT faces more pressure from a changing threat landscape and increased compliance mandates, the cloud model gives maximum leverage to IT – always important, but especially in this economic climate.
Register here for "In Cloud we Trust"
Thursday, April 16, 2009 1:00 p.m. EST / 10:00 a.m. PST
Posted by Sundar Raghavan, Google security and archiving teamTuesday, March 31, 2009
Spam data and trends: Q1 2009
Read on for a quick overview of spam trends and events in the first quarter of 2009.
Spammers have clearly rallied following the McColo takedown, and overall spam volume growth during Q1 2009 was the strongest it's been since early 2008, increasing an average of 1.2% per day. To put that number into context, the growth rate of spam volume in Q1 2008 was approximately 1% per day – which, at the time, was a record high.
This year we've seen the payload viruses spread out across every day of the week, with no immediately obvious pattern in their distribution. It's difficult to say for certain what prompted the change, but one possible explanation is that spammers switched tactics because they weren't seeing the success they'd hoped for from the focused attacks.
Of course, payload viruses have also seen a recent spike overall -- in the month of March we saw a 9x increase from February. This pales in comparison to the highs we saw last summer, but it may indicate a developing trend that's worth keeping a close eye on.
Posted by Amanda Kleha, Google security and archiving team
Tuesday, March 3, 2009
Everything you always wanted to know about keeping email safe...in the cloud
Don't have 35 minutes? We know the feeling. The topic overview (on the left) lets you pinpoint the subjects that interest you most.
This tutorial is just one from a growing library of information and resources in our Security and Archiving Learning Center. Find a moment to come in and look around.
Posted by Ellen Petry Leanse, Google Enterprise Team