170 likes | 252 Views
Lecture no 33: E-mail systems. TDT4285 Planlegging og drift av IT-systemer Våren 2011 Anders Christensen, IDI. E-post – Privacy. It is expected that email is private Point to point encryption Signatures Framework is given by nationale laws. Different types of contents/information
E N D
Lecture no 33: E-mail systems TDT4285 Planlegging og drift av IT-systemer Våren 2011 Anders Christensen, IDI TDT4285 Planl&drift IT-syst
E-post – Privacy • It is expected that email is private • Point to point encryption • Signatures • Framework is given by nationale laws. • Different types of contents/information • Email contents • Info on sender and receiver • Info on volume TDT4285 Planl&drift IT-syst
Structure for E-mail systems Email client Email client imap pop SMTP Email server /var/mail (fs) SMTP Email server Email server DNS MX for idi.ntnu.no MX for whitehouse.gov TDT4285 Planl&drift IT-syst
E-mail – Name space • Name space for suborganizations • Name space for server machines • Name space for personal adresses. • Firstname.lastname@ format • Username@ format • Aliases structure. TDT4285 Planl&drift IT-syst
Email – Reliability • Main priority: email must not be lost. • Attachments: • That the attachments are delivered intact • That the attachments can be extracted. • Email must arrive in time. • Errors must be reported to sender. TDT4285 Planl&drift IT-syst
Examples of headers in email From orakel@ntnu.no Mon Apr 20 10:37:33 2009 Return-Path: <orakel@ntnu.no> Received: from bene2.itea.ntnu.no (bene2.itea.ntnu.no [129.241.56.57]) by pil.idi.ntnu.no (8.14.1/8.13.1) with ESMTP id n3K8b300006544 for <abuse@idi.ntnu.no>; Mon, 20 Apr 2009 10:37:03 +0200 (MEST) Received: from localhost (localhost [127.0.0.1]) by bene2.itea.ntnu.no (Postfix) with ESMTP id 0C08E9000B for <abuse@idi.ntnu.no>; Mon, 20 Apr 2009 10:37:03 +0200 (CEST) Received: from tssd.felles.ntnu.no (tssd.itea.ntnu.no [129.241.18.108]) by bene2.itea.ntnu.no (Postfix) with SMTP id 7187F9000C for <abuse@idi.ntnu.no>; Mon, 20 Apr 2009 10:37:02 +0200 (CEST) MIME-Version: 1.0 Reply-To: <orakel@ntnu.no> From: "Orakeltjenesten" <orakel@ntnu.no> To: <abuse@idi.ntnu.no> Date: Mon, 20 Apr 2009 10:37:02 +0200 Subject: Re: (Sak 93309) 129.241.110.160 (brudd på opphavsrett) X-Mailer: hp OpenView service deskMail Manager 4.5 Content-Type: text/plain; charset=iso-8859-1 Message-Id: <20090420083702.7187F9000C@bene2.itea.ntnu.no> X-Virus-Scanned: Debian amavisd-new at bene2.itea.ntnu.no X-Amavis-Alert: BAD HEADER Non-encoded 8-bit data (char E5 hex) in message header 'Subject': Subject: ...93309) 129.241.110.160 (brudd p\345 opphavsrett)\n X-Spam-Status: No, score=-11.971 required=6.31 tests=[AWL=0.017, BAYES_00=-2, NORMAL_HTTP_TO_IP=0.001, SUBJECT_NEEDS_ENCODING=0.001, T_L_HPOV=0.01, T_L_WHITELIST=-10] X-Spam-Score: -11.971 X-Spam-Level: X-Virus-Scanned-By: mimedefang.idi.ntnu.no, using CLAMD X-SMTP-From: Sender=<orakel@ntnu.no>, Relay/Client=bene2.itea.ntnu.no [129.241.56.57], EHLO=bene2.itea.ntnu.no X-Scanned-By: MIMEDefang 2.48 on 129.241.107.38 X-Scanned-By: mimedefang.idi.ntnu.no, using MIMEDefang 2.48 with local filter 16.42-idi X-Filter-Time: 1 seconds X-UID: 43762 Status: RO Content-Length: 1533 Vi har mottatt melding om at det distribueres rettighetsbeskyttet materiale fra en maskin på ett av deres subnett. Meldinga er sendt inn TDT4285 Planl&drift IT-syst
Email – standardisation • Standardisation • Between servers (SMTP) • Between server and client • Separation of functionality and reponsibility • Email transport • Email delivery • Hadling of email lists TDT4285 Planl&drift IT-syst
Email – the general setup • Single-point-of-entry • All email from and to one adress • Can communication with everyone • Clear separation between server and client TDT4285 Planl&drift IT-syst
Email - automation • Handling of email lists • Creation and deletion of accounts • Detection of inactive accounts • Checking for viruses • Redirection and forwards • Spam filtering TDT4285 Planl&drift IT-syst
Email – monitoring • Volume, to get the scaling correct • Peculiar use to detect abuse. • Error messages for postmaster • Uptime and service level • Log messages for errors TDT4285 Planl&drift IT-syst
Email - redundancy • Parallel system for automatic fail-over • Secondary systems for fall-back • Redundancy internally on the mail servers TDT4285 Planl&drift IT-syst
Email - scaling • Sufficient scaling • Email transfering between servers • Email buffering if case of downtime • Delivery to end user • List mail • Average traffic vs peak period • Polling vs notification wrt new mail TDT4285 Planl&drift IT-syst
Email response times • Time from it is sent to it is available to the recipient • Time to list all pending messages for a user. • Time to retrieve and show a message • Time to delete a message TDT4285 Planl&drift IT-syst
Email – security • Security of contents • While it is stored • Under transport (encyption • Ensure that the right person gets access • Ability to trace backwards. TDT4285 Planl&drift IT-syst
Metods Open relays Email lists Botnet Collecting email adresses on the web. Antidotes Black listing Gray listing Closing of relays Detection of spam fromanalysis of the contents Filtering of ports Email – spam TDT4285 Planl&drift IT-syst
Example of spam headers • Delivery-Date: Wed Mar 26 17:04:04 2003 • Received: from adsl-64-172-47-64.dsl.snfc21.pacbell.net (duqvhh@adsl-64-172-47-6 4.dsl.snfc21.pacbell.net [64.172.47.64]) by ray.idi.ntnu.no (8.12.8/8.12.8) with SMTP id h2QG3pAZ018184; Wed, 26 Mar 2003 17:03:56 +0100 (MET) • Received: from 0korj.5nmaeq.com [202.221.181.211] by adsl-64-172-47-64.dsl.snfc2 1.pacbell.net id ZBX55jmD268d; Wed, 26 Mar 2003 06:58:23 -0600 • Message-ID: <s-y-a---p8j73@kn7z9> • From: "Lottie Barajas" <a213jyla@amexmail.com> • To: <anders@idi.ntnu.no>, <asbjornm@idi.ntnu.no>, <Arne.Solvberg@idi.ntnu.no> • Subject: Fw: Valium, Buspar, Zoloft, Vioxx and more! • Date: Wed, 26 Mar 03 06:58:23 GMT • X-Priority: 3 • X-MSMail-Priority: Normal • X-Mailer: Microsoft Outlook Express 5.00.2615.200 • MIME-Version: 1.0 • Content-Type: multipart/alternative; boundary="4B_D874C5.DA23." • X-Spam-Status: No, hits=5.9 {E9} required=6.0 • tests=BIG_FONT,CLICK_BELOW,EXCUSE_3,HTML_FONT_COLOR_BLUE, • MIME_HTML_NO_CHARSET,MISSING_MIMEOLE,NORMAL_HTTP_TO_IP, • OUTLOOK_FW_MSG,REMOVE_PAGE,SPAM_PHRASE_08_13,USER_AGENT_OE • X-Spam-Flag: No • X-Virus-Scanned: by amavisd-new-IDI TDT4285 Planl&drift IT-syst
Email – informasjon • The users should be informed about the following: • AUP for the email system • Routins for backup • Privacy • Routines for deletion of old mail • Routines for termination of old accounts TDT4285 Planl&drift IT-syst