Business Services Industry
IBM Releases Open Software to Improve Security, Performance & Reliability of Internet E-mail Systems
Business Wire, Dec 15, 1998
YORKTOWN HEIGHTS, N.Y.--(BUSINESS WIRE)--Dec. 14, 1998--
Free Secure Mailer Code Could Ensure Security of Systems
Transferring Billions of E-mails Daily
IBM today announced it is making available open source software designed to improve the security, reliability and performance of e-mail delivery services, a crucial component of the Internet's infrastructure. Called Secure Mailer, the new software could replace e-mail delivery software that processes more than three-quarters of the Internet's e-mail traffic today.
Developed by IBM researcher Wietse Venema, Secure Mailer is far more robust and flexible than similar messaging components, called Mail Transfer Agents (MTA). According to Venema, the majority of e-mail -- more than a billion messages sent daily worldwide -- is processed by MTA technology that originated in the early eighties and was not designed with today's Internet traffic and security needs in mind.
Secure Mailer is available for download beginning today from IBM's alphaWorks Web site at www.ibm.com/alphaworks. Secure Mailer is open-source software, so anyone can freely copy, use, modify and distribute it.
"By offering Secure Mailer free without licensing restrictions, IBM is helping build a stronger base for secure e-business," said Jeff Jaffe, general manager for IBM's IT Security. "This is an important step because MTAs with poor security are one of the most common ways for intruders to invade a company's network."
Secure Mailer Offers Security, Reliability, Speed
Messaging systems are comprised of Mail User Agents (MUAs), which send and request mail from users to their designated mail server, and Mail Transfer Agents (MTAs), which deliver mail to and from the various servers on a network. These mail systems are some of the most heavily used pieces of software on the Internet and form the basic plumbing for direct information exchange. Historically, e-mail systems have been a security risk because they must maintain some degree of openness to accept and distribute information.
Secure Mailer is built to be an industrial-strength, general purpose MTA. It is specifically designed to keep up with the daily delivery of millions of messages, while maintaining a performance level nearly three times that of existing MTAs. IBM Research employed "defensive programming" techniques when developing Secure Mailer so it avoids operations and assumptions that could make it vulnerable to intruders, system errors, and malformed or suspicious e-mail. If any irregularities occur, safety nets in the various Secure Mailer components prevent them from adversely affecting the system.
"We designed Secure Mailer so it proactively combats possible threats by assuming there will be attacks and fortifying those potential points of entry," said Venema. "It also protects against inadvertent user or administration errors that could lead to service interruptions."
Secure Mailer was also designed to behave rationally under stress. For example, most mail systems can be dramatically slowed and even frozen by heavy traffic or resource requests, making mission-critical business communications difficult. A malicious attack such as a mail bomb -- when huge amounts of mail are sent to one user or host -- are intended to cripple mail systems. Because these systems cannot differentiate between a mail bomb and legitimate mass mailings on company servers and ISPs, these types of ill-intentioned deeds are difficult to defend against. With Secure Mailer, extremely heavy e-mail traffic will gracefully degrade performance, rather than crash the system.
Modular Structure Enhances Customization and Security
Secure Mailer has a modular architecture, so that each component can focus on its task alone and any problems or irregularities remain isolated to that piece of the application. Most other MTAs are built as singular monolithic programs, making the entire system potentially vulnerable to any problems.
"E-mail systems are like people -- if you gave one person too many responsibilities and too little time, they could suffer burnout," Venema explained. "But Secure Mailer's sturdy components do one task each and do it well."
The modular structure of Secure Mailer makes it much easier to port, configure, maintain and test, as well. Available from IBM for the UNIX/AIX platform, this modular design allows for easy configuration, letting system administrators pick and choose which MTA capabilities they need. It is standards-compliant and is built to be interoperable with the more common standards-compliant MTAs in use today. Migration to this new system is seamless from a user's perspective since the user interface is similar to other MTAs.
"Secure Mailer is intended to be a building block that will evolve under the control of its users working as a team," Venema said. "With widespread input and continued development from the Internet community, Secure Mailer will raise the bar for mail system security and reliability."
IBM has been a leader in system security research and development for several decades. Other contributions this year include:
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Business Articles
- Multiple criteria evaluation and optimization of transportation systems
- Multi-criteria analysis procedure for sustainable mobility evaluation in urban areas
- A two-leveled multi-objective symbiotic evolutionary algorithm for the hub and spoke location problem
- Multi-criteria analysis for evaluating the impacts of intelligent speed adaptation
- The development of Taiwan arterial traffic-adaptive signal control system and its field test: a Taiwan experience
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FAS 109: a primer for non-accountants - Financial Accounting Standards Board's "Statement 109: Accounting for Income Taxes"
- LIFO vs. FIFO: a return to the basics
- Too Young to Rent a Car? - 25-years-old the minimum age for car renting - Brief Article
- Design a commission plan that drives sales - Sales Commissions



