Propagation protection of email within a network
Described are methods and apparatus, including computer program products, for propagation protection within a network. A network appliance repeatedly stores received portions of data associated with email in a buffer associated with an email message until an end of message indicator is received for the email message or a predefined number of bytes have been stored in the buffer before the end of message indicator is received. At least a final portion of data associated with the email message is prevented from being transmitted from the network appliance until a threat determination is made.
1 . A computerized method for propagation protection of email traffic within a network, the method comprising:
repeatedly storing, by a network appliance, received portions of data associated with email in a buffer associated with an email message until an end of message indicator is received for the email message or a predefined number of bytes have been stored in the buffer before the end of message indicator is received; and
preventing at least a final portion of data associated with the email message from being transmitted from the network appliance until a threat determination is made.
2 . The method of claim 1 , further comprising, transmitting the final portion of data from the network appliance if the email message does not represent a threat to the network or permanently preventing the transmission of the final portion of data from the network appliance if the email message represents a threat to the network.
3 . The method of claim 1 , further comprising, rebuilding the email message associated with the buffer or a portion of the email message associated with the buffer using the received portions of data stored in the buffer.
4 . The method of claim 3 , further comprising analyzing the rebuilt email message or the rebuilt portion of the email message to make a threat determination.
5 . The method of claim 3 , further comprising comparing the rebuilt email message or the rebuilt portion of the email message with known threat signatures to make a threat determination.
6 . The method of claim 3 , further comprising transmitting the rebuilt email message or the rebuilt portion of the email message to an antivirus engine for comparison to known threat signatures to make a threat determination.
7 . The method of claim 1 , further comprising, determining, by the network appliance, whether a portion of data transmitted through the network appliance is associated with email.
8 . The method of claim 7 , wherein determining whether the portion of data is associated with an email comprises determining whether the data is transmitted across a port associated with Simple Mail Transfer Protocol (SMTP).
9 . The method of claim 8 , wherein repeatedly storing comprises repeatedly storing only after a DATA command associated with the email message is received.
10 . The method of claim 1 , wherein the final portion of data comprises a portion of data associated with
i) the end of message indicator for the email message or
ii) reaching the predefined number of bytes for the email message.
11 . The method of claim 1 , further comprising defining a number of buffers reserved for storage of received portions of data.
12 . The method of claim 11 , further comprising:
receiving portions of data associated with another email message;
determining that all of the defined number of buffers are currently associated with email messages different from the another email message; and
permanently preventing transmission of the received portions of data associated with the another email message from the network appliance.
13 . The method of claim 1 , further comprising transmitting an event message from the network appliance to a management server in response to a determination that the email message represents a threat to the network.
14 . The method of claim 1 , further comprising:
receiving additional portions of data associated with a server associated with a whitelist; and
transmitting the additional portions of data from the network appliances without storing them and analyzing them for a threat determination.
15 . The method of claim 1 , further comprising, transmitting all data from a first portion of the network to the second portion of a network through the network appliance.
16 . A network appliance for propagation protection of email traffic within a network, the network appliance comprising:
a network interface card configured to act as a bridge between a first portion of the network and a second portion of the network; and
a data analyzer module configured to repeatedly store portions of data received from the first portion of the network and associated with email in a buffer associated with an email message until an end of message indicator is received for the email message or a predefined number of bytes have been stored in the buffer before the end of message indicator is received, and prevent at least a final portion of data associated with the email message from being transmitted to the second portion of the network until a threat determination is made.
17 . The network appliance of claim 16 , wherein the network appliance further comprises a memory module for storing the received portions of data.
18 . The network appliance of claim 17 , wherein the memory module comprises an area for a predefined number of buffers for storing the received portions of data.
19 . The network appliance of claim 16 , wherein the data analyzer module is further configured to rebuild the email message associated with the buffer or a portion of the email message associated with the buffer using the received portions of data stored in the buffer.
20 . The network appliance of claim 16 , wherein the data analyzer module is further configured to transmit the final portion of data to the second portion of the network if the email message does not represent a threat to the network or permanently prevent the transmission of the final portion of data to the second portion of the network if the email message represents a threat to the network.
21 . A computer program product, tangibly embodied in an information carrier, for propagation protection of email traffic within a network, the computer program product including instructions being operable to cause data processing apparatus to:
repeatedly store, by a network appliance, received portions of data associated with email in a buffer associated with an email message until an end of message indicator is received for the email message or a predefined number of bytes have been stored in the buffer before the end of message indicator is received; and
prevent at least a final portion of data associated with the email message from being transmitted from the network appliance until a threat determination is made.