The Threat of Malicious Outbound Email
Graham Peat · Computer Fraud & Security · 2002
You are probably familiar with the sounds that email programs make when they fetch messages. These days, ‘you've got mail’ is a cultural icon, reflecting the phenomenal popularity of email, which still leads Web surfing as the number one online activity. So it is ironic that this often welcome sound can also herald a most unwelcome visitor — unsolicited, malicious email, which may carry computer viruses or open your system to hackers. In this article we consider the risk that outgoing email poses to your organization and look at some of the defensive measures you can take. @mainhead1:The ins and outs of email threats @bodyout:Incoming email has become an indispensable tool for communications. It can also be a vehicle for outsiders to plant Trojan horses, viruses, and worms on your internal systems. At best, these intrusions represent unauthorized access and abuse of network resources. At worst they pave the way for more sophisticated intrusions that compromise corporate data. In this context, email facilitates allowed path attacks. This term describes attacks which take advantage of the requirement, inherent in all networks, to allow some data to be communicated between nodes of the network. In other words, a network is not a network if some data is not communicated. An allowed path attack subverts the data which the network allows to pass through it. There are a number of ways to reduce the threat from malicious incoming email. However, the technological solutions to inbound email threats do not necessarily reduce the threats from outbound email. Additional measures may be needed, and non-technical steps may have to be taken before any technology you apply to the problem will yield meaningful results.