1、 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 1Borderless Network 新服 务 : IronPort、 ScanSafeWind WanOct, 2010 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 2今天的威 胁Countervailing ForcesGlobalizationCollaborationData LossMobilityEnter
2、prise SaaSThreatsAcceptable Use 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 3全球最近的安全攻 击 迈 克杰克 逊组 合攻 击 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 4在几个小 时 之内,犯罪分子通 过 20亿 封垃圾 邮 件 发 送了大量的 恶 意程序 2009 Cisco Systems, Inc. All rights r
3、eserved. Cisco ConfidentialPresentation_ID 5猪流感的全球垃圾 邮 件也随着疫情 发 起社会型攻 击 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 6Remote ExploitConfickerdriving down costs:自 动获 取 “新用 户 ”USB Network Shares 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresenta
4、tion_ID 7组 合攻 击 101:Conficker and WaledacWaledac 被用来组建Conficker的僵尸网络伪造防恶意软件伪造防病毒软件 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 8Cisco SIO安全智能运 营 中心(云 计 算)Corporate Headquarters Branch Office Coffee ShopData CenterSecurity in every form factorSecurity in every loca
5、tionCisco Threat Operations CenterCiscoSecurity ServicesGlobalThreatTelemetryGlobalThreatTelemetrySecurity Module Security SoftwareAppliance Hybrid Hosted 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 9The IronPort SenderBase全球动态名誉度数据网络全球部署达到超级精准度 每天承载 300亿次查询 每个 IP
6、超过 150个以上的邮件和Web信息参数 实时采集全球 25%的 IP流量 利用 Cisco 网络设备监控全球流量IronPort 邮件安全网关IronPort WEB安全网关IronPort SenderBase综合邮件与网站流量分析 通过监控 email & Web 流量显著提高侦测能力 80% 的垃圾邮件包含 URL钓鱼 电子邮件是散布恶意软件的主要手段 垃圾邮件僵尸网络又是以恶意软件为主要传播手段 2009 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID 10Global Volume
7、DataOver 100,000 organizations, email traffic, web trafficMessageCompositionDataMessage size, attachment volume, attachment types, URLs, host namesSpam TrapsSpamCop, ISPs, customer contributionsIP Blacklists &WhitelistsSpamCop, SpamHaus (SBL), NJABL, Bonded SenderCompromisedHost ListsDownloaded file
8、s, linking URLs, threat heuristicsSORBS, OPM, DSBLFortune 1000, length of sending history, location, where the domain is hosted, how long has it been registered, how long has the site been upComplaintReportsSpam, phishing, virus reportsSpamvertized URLs, phishing URLs, spyware sitesDomain Blacklist& SafelistsSenderBaseOther DataWeb SiteCompositionDataCisco IronPort SenderBase Breadth and Quality of Data Makes the Difference