protecting your brand: email security

18
Email Security: Keeping Your Brand Safe

Upload: dyn

Post on 16-Apr-2017

974 views

Category:

Internet


0 download

TRANSCRIPT

Page 2: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Your Presenters

Chris BrentonSenior Director of Information [email protected]

Scott GrantProduct Marketing Manager | Message [email protected]

Page 3: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

Page 4: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

16 million get through spam filters

Page 5: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

16 million get through spam filters

8 million are opened

Page 6: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

16 million get through spam filters

8 million are opened

800k are clicked

Page 7: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

16 million get through spam filters

8 million are opened

800k are clicked

80,000 people fall victim each day

Page 8: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Email Security?

156 million phishing emails per day

16 million get through spam filters

8 million are opened

800k are clicked

80,000 people fall victim each day

One test found:• 89% Confident• 92% Failed• 50% Misclassified & Deleted

Page 9: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

• Q3 2013: $1.66 Billion Lost

• Growing 30% / Month• Estimated $1.4m per

attack

$$$ Big Money $$$

• Payment Services• Financial• Retail• Government / Education• Auctions• Social Networks• Gaming• Classified

Frequently Targeted

Page 10: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Protect Your Email

Securely Transmitting Messages

Email Authentication– Brand Protection, Active and Parked Domains

Page 11: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Secure Delivery

Opportunistic TLS

Attempts to encrypt the communications channel otherwise falling back to unencrypted communications

Sending Receiving

Page 12: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Avoiding Phishing With Email Authentication

Page 13: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Why Authenticate?

Marketing Transactional Interpersonal

PhishingSpoofing Botnets

Page 14: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Sender Policy Framework (SPF)

Preventing spam email spam by detecting email spoofing

Authenticates Sending IP address

Based off DNS TXT record

"v=spf1 ip4:216.146.45.0/24 include:_spf.google.com include:spf.dynect.net include:support.zendesk.com

~all"

Spoofing

Page 15: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

DomainKeys Identified Mail (DKIM)Uses Public / Private Key to authenticate

Public key provided in DNS TXT records

Private key hashed with message and inserted in headers

Validate the sending server or software

Sending

Receiving

Public Key

Botnets

Page 16: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

DMARCDomain-based Message Authentication, Reporting and Conformance

Provides ISPs direction on what to do with mail

Used to reduce (and possibly stop!) phishing

Utilizes SPF and/or DKIM

ISPs provide reports on emails sent on your domain

"v=DMARC1; p=reject; rua=mailto:[email protected]; ruf=mailto:[email protected]; pct=100”

Phishing

Page 17: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Recap: Protect your brand AND your customers

Securely transmitting messages– Opportunistic TLS

Email Authentication via DNS records– SPF, DKIM, and DMARC

Additional resources– Openspf.org– DKIM.org– DMARC.org– http://dyn.com/content-hub/

Page 18: Protecting Your Brand: Email Security

Email Security: Protecting Your Brand

Questions?

Chris BrentonSenior Director of Information [email protected] | @Chris_Brenton

Scott GrantProduct Marketing Manager | Message [email protected] | @ScottGrantJr