In its continuing fight against unsolicited commercial email, Microsoft plans to filter outgoing messages on its consumer mail services and is busy developing new "proofing" technologies, the software maker's chief spam fighter says.
The fight is also one against the clock. Microsoft recently set a two-year goal to make spam a problem of the past. There are 19 months left, says Ryan Hamlin, general manager of Microsoft's Security Technology and Strategy group, speaking at this week's INBOX, a conference on email in San Jose, California.
More than 14.5bn spam messages are sent each day, according to Hamlin, who cites figures from antispam vendor Brightmail. Microsoft's Hotmail web-based email service receives 2.7bn spam messages a day, Hamlin says.
As part of its efforts to stop spam, Microsoft in the coming months plans to apply spam filters not only to incoming mail on its Hotmail and MSN services, but also to outbound mail. The filtering will kick in when users send a large number of messages and is intended to help stop abuse of Microsoft's services by senders of spam, Hamlin says.
He called on ISPs and other email service providers to do the same. "All of the ISPs and large senders of mail need to be filtering on the outbound side," he says. "There is a lot of abuse happening. We need to have better outbound filtering to look for people that are abusing our systems."
Hamlin referred to Comcast as an example. The large US cable Internet access provider last month said it was cutting off Internet service for some customers whose computers had been hijacked to relay spam messages.
Filtering, however, is only part of Microsoft's attack on spam. The company is also investing heavily in proof and prevention utilities, Hamlin says. Filters will really only work well after proper spam-proofing and prevention technologies have been applied, he says.
"Protection today has been very reactive. We want to make it very proactive, and we think the way to do that is by having great proof and prevention technologies," Hamlin says.
One proofing technology that Microsoft is working on sends a challenge in the form of a computational puzzle to the sender of a message if the filtering system suspects a message may be spam. The sender, or the sender's computer, would have to solve the puzzle to validate the legitimacy of an e-mail message.
Solving a challenge would take little time for a regular e-mail sender's computer but would overwhelm the computing cycles of someone sending large amounts e-mail, according to Microsoft. The technology is now being developed and should be ready within a year, Hamlin says.
The challenge system would work in concert with other technologies Microsoft is developing as part of its coordinated spam reduction initiative announced in February. The plan also includes Microsoft's SmartScreen filtering technology, a sender authentication technology called Caller ID for E-mail, and "white lists" that contain certified e-mail senders.