FireEye

FireEye

Anti-targeted email "FireEye Email Security - Server Edition"

FireEye Email Security - Server Edition is a solution for targeted email attacks, which have been increasing rapidly in recent years. Targeted e-mail attacks in recent years use clever spoofing e-mails, making it difficult for users to determine whether they are spoofed e-mails. In addition, the malware included is not distributed and tends to be customized for each attack, which can be bypassed by signature products. FireEye Email Security - Server Edition executes, analyzes suspicious attachments and embedded URLs, and blocks any that are determined to be fraudulent, helping organizations prevent targeted email-triggered cyber-attacks.

Email traffic (SMTP) entrance countermeasures

FireEye's proprietary virtual execution engine (MVX) analyzes attachments to detect unknown vulnerabilities and malware. In addition, the URL in the text is also detected by matching it with FireEye's intelligence. After detecting that it is malware, MVX swims the malware, identifies the C&C server with which it communicates, and creates a signature. In addition, depending on the deployment mode, it is also possible to block targeted emails.

Deployment options

  • SPAN/TAP mode
    1. Receive SMTP mirror packet
    2. Send alerts to administrators when detected
    3. No impact on mail traffic (delays/failures)
SPAN/TAP mode
  • BCC mode
    1. Receiving BCC forwarded mail from previous MTA
    2. Send alerts to administrators when detected
    3. No impact on mail traffic (delays/failures)
BCC mode
  • MTA mode
    1. Act as MTA
    2. Block and monitor can be selected as post-detection actions
    3. Impact on mail traffic (delay/failure)
MTA mode