by Steve Taylor and Joanie Wexler

Mirapoint helps university dodge Sobig bullet

Opinion
Sep 18, 20032 mins

* Covering all the Sobig bases

Last time, we mentioned that Wayne State University in Detroit largely dodged the recent Sobig.F e-mail worm bullet by being prepared when the attack began.  The network segments using the university’s Mirapoint centralized e-mail appliance, which provided system-wide virus protection and spam filtering, were spared the outages and slowdowns that plagued other educational institutions.

One of our first questions was whether any early instances of Sobig.F slipped through or whether this strain was similar enough to other Sobig variants that it was trapped right away. Tony Falzon, WSU’s director of research and Internet services, said that to the best of his knowledge, no Sobig virus got through the Mirapoint server to WSU users, because WSU’s virus filtering was already updated. In fact, Falzon said there were no help-desk notifications that any WSU users were infected.

Part of being a good network citizen is to contain outbreaks locally so as not to propagate “bad” network traffic.  Mark Murphy, lead applications technical analyst at WSU, confirmed that there are two actions that the university takes to limit the spread of infection.

First, WSU’s Mirapoint appliance scans all incoming and outgoing e-mail.  If a student, for instance, returns to school with an infected system, any outgoing mail from that system gets trapped. It neither leaves the campus nor gets spread around the campus. 

The second action compensates for well-intentioned e-mail scanning programs that automatically notify senders that they have sent an e-mail infected with a virus.  They do this by sending an alert to the e-mail address appearing in the “from” field of an infected e-mail, even when that address has been spoofed. This action thus propagates volumes of useless notifications and clogs networks and inboxes.

Sure enough, according to Murphy, WSU noticed an almost immediate burst of outgoing messages after the Sobig onslaught began. So the university disabled this notification function within an hour of the start of the attack.

A full case study of the WSU implementation of the Mirapoint system, written by IDC is available at https://www.webtorials.com/main/resource/papers/mirapoint/paper3.htm