Story image

Email prime target for cyber attacks, FirstWave responds with domain filter

20 Apr 2016

In response to increasing number of attacks targeting email, such as the C-Level Impersonation filter and other ‘whaling’ attacks, FirstWave Cloud Technology has launched a Typo Domain filter on its ESPTM Mail cloud security platform.

This new filter has been designed to deflect and block sophisticated email phishing threats targeting the wider attack surface of email users at any organisation level in the enterprise, according to a statement.

According to FirstWave, cyber attackers can take advantage of Internationalised Domain Names (IDNs) with special character sets to create and send phishing emails from servers using legitimately-established domain names - these are indistinguishable to most recipients from well-known or trusted domain names. Attacks such as this are sometimes known under the banner of homograph attacks or imposter email attacks.

FirstWave says attackers can apply this technique and use a homograph of a company’s own domain name or names to trick employees of that company to accept and click on links in emails that appear to be legitimately coming from within their own organisation.

The majority of existing email security and phishing filters cannot assure they will block such an attack, according to the company. Standard sender domain authentication techniques used by email transport nodes and email security gateways, such as SPF and DKIM, can be penetrated because these homograph domains can appear authentic in the DNS system.

To provide a broad yet enterprise specific defence against this form of attack, FirstWave Cloud Technology’s Typo Domain filter uses advanced ‘fuzzy matching‘ software library algorithms in its ESPTM Mail platform, tested against a wide range of homograph domain attack scenarios. As such, the filter is designed to provide high protection efficacy and very low false positives.

According to FirstWave, the Typo Domain filter will automatically protect all customer domains already configured on the FirstWave cloud Mail security service, without the need for any customer administrator configuration action.

Why SD-WAN is key for expanding businesses - SonicWall
One cost every organisation cannot compromise on is reliable and quick internet connection.
New threat rears its head in new malware report
Check Point’s researchers view Speakup as a significant threat, as it can be used to download and spread any malware.
Oracle updates enterprise blockchain platform
Oracle’s enterprise blockchain has been updated to include more capabilities to enhance development, integration, and deployment of customers’ new blockchain applications.
Used device market held back by lack of data security regulations
Mobile device users are sceptical about trading in their old device because they are concerned that data on those devices may be accessed or compromised after they hand it over.
Gartner names ExtraHop leader in network performance monitoring
ExtraHop provides enterprise cyber analytics that deliver security and performance from the inside out.
Symantec acquires zero trust innovator Luminate Security
Luminate’s Secure Access Cloud is supposedly natively constructed for a cloud-oriented, perimeter-less world.
Palo Alto releases new, feature-rich firewall
Palo Alto is calling it the ‘fastest-ever next-generation firewall’ with integrated cloud-based DNS Security service to stop attacks.
The right to be forgotten online could soon be forgotten
Despite bolstering free speech and access to information, the internet can be a double-edged sword, because that access to information goes both ways.