The Register® — Biting the hand that feeds IT

Feeds

Mirapoint adds directory to email gateway

Local anti-spam checks mean less network load

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Mirapoint has developed what it says is the first secure email gateway with a built-in directory and policy engine. According to the company, this increases security and lightens the load on the gateway because it no longer has to query the corporate directory server through the firewall for every incoming message.

The directory software is now a standard feature on Mirapoint's RazorGate appliances and will be a free upgrade to customers on support contracts, said Mike Dodson, the company's security accounts technical director.

He said that the Mirapoint directory software can copy email addresses and associated policies - but not more sensitive data such as passwords or user names - from a variety of LDAP servers, such as Active Directory, Domino or eDirectory. It also has features to detect and prevent directory harvesting, he added.

"Historically, the gateway would have a steady stream of traffic going back to the directory - checking for valid recipients, whether they can receive that type of attachment, and so on," he explained. "The problem is that spikes in email traffic are passed on to the directory servers.

"Also, email gateways are hardened, but if your gateway server were ever compromised, the attacker would be able to attack your directory. This way, the most they could get is a list of email addresses."

But doesn't the addition of policy enforcement increase the workload on the email appliance, reducing the amount of email it can handle? Dodson claimed not.

"Quite the opposite," he said. "Now when we query the directory it's process-to-process, not over the network, so it works in our favour. We actually get a marginal performance improvement."

He claimed that while the technology to replicate directory data is pretty standard in the metadata world, this is the first time it has been used in an email appliance.

The increasing importance of the directory in messaging means that Mirapoint's competitors are sure to follow suit, but Dodson suggested that integrating the replication technology and the directory into the email appliance, and providing the right management tools, would take them many months. ®

Agentless Backup is Not a Myth

Latest Comments

This is new?

The email systems from OpenWave (previously Software.com) have been able to use local LDAP directory cache servers for almost a decade now. I'm not convinced Mirapoint have come up with anything new.

0
0
Anonymous Coward

Hardly an overhead

Hitting the AD for such information is hardly an overhead. If it is, they either have an elderly infrastructure or need to look at tackling spam off their network, rather than on this box once it's already within it.

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key