Tuesday, 21 April 2009

Websense (finally) gets appliance religion

I sat down with the folks from Websense, here at the RSA Conference. Their big news is that they've finally come out with a pre-built appliance.

It's easy to be cynical. It wouldn't be hard to see this as Websense being "late to the party." Naturally, the company doesn't view it that way.

Websense didn't want to simply take its existing software platform and stuff it into a 19" rack. It already has 3rd parties who do that, which it says it's happy with.

Websense saw the need for a complete platform refresh. We're seeing the first fruits of this work in the new V10000 appliance.
  • It's based around a virtualized environment, based on Linux and the Xen hypervisor.
  • First version is simply a Web gateway / security proxy, but future add-ons will include DLP
  • Customers will be able to run multiple instances on one box.
  • A new centralized management platform can control a mixture of appliances and similar functionality provided by the Websense managed service (based on technology from the BlackSpider acquisition).

Tuesday, 14 April 2009

Spam and its Carbon Footprint

All uses of the Internet have an impact on climate change. Sadly, that includes the less-savory uses.

Spammers dumped 60 trillion messages onto the Internet in 2008. As the climate-change consensus becomes overwhelming, it's high time we looked at the environmental impact of spam.

Recently, McAfee commissioned climate-change consultants ICF calculate the carbon footprint of spam. McAfee also asked me to help. We calculated the energy use associated with each stage in the lifecycle of spam, including the energy used to transmit, process, and filter spam.

Globally, the annual spam energy use is 33 billion kilowatt-hours, or 33 TWh—that's as much electricity as 2.4 million U.S. homes use, with the same greenhouse gas emissions as 3.1 million passenger cars using 2 billion U.S. gallons of gasoline.[1]

Two Surprising Conclusions

Far from being a net consumer of energy, spam filtering actually saves an incredible amount of energy. Imagine if all the spam filters in the world were switched off for a day. It would actually increase the carbon footprint of spam by at least five times.[2] In other words, spam filtering saves 135 TWh of electricity per year—that's like taking 13 million cars off the road.

But we could do even better. Imagine if every inbox were protected by a state-of-the-art spam filter. We could save about 75% of the spam energy used today—25 TWh per year;[3] that's like taking 2.3 million cars off the road.

Other Results

The average greenhouse gas emission associated with a single spam message is 0.3 grams of CO2. That's like driving 3 feet (1 metre), but because of the annual volume of spam, it's like driving around the Earth 1.6 million times.[4]

A year's email at a typical medium-sized business uses 50,000 KWh, more than one fifth of which is associated with spam.[5]

Filtering spam is all well and good, but fighting spam at the source can have even better results. Taking McColo offline in late 2008 saved energy equivalent to taking 2.2 million cars off the road, before spammers rebuilt their sending capacity.

Energy use associated with spam is mainly consumed by end-users deleting spam and searching for legitimate email ("false positives"). Only 16% of energy use is from spam filtering itself.

Notes

My role in the McAfee project was to help ICF build a model that accurately reflected where energy was used in producing, transmitting, filtering, and dealing with spam. To this end I provided consultancy and data, plus some analysis of the results.

The data came from my 25 years of experience with email and spam, cross-correlated with data from other researchers (including McAfee and McAfee's competitors).
  1. 33 TWh of electricity use emits 17 million tonnes (19 million U.S. tons) of CO2, equivalent to 3.1 million passenger cars, burning 7.6 billion litres of gasoline (2 billion U.S. gallons), or 2.4 million U.S. homes' electrical usage.
  2. Switching off spam filtering for one day would multiply spam in the average inbox by 5x and multiply false positives by at least 10x. While no energy would be used by spam filters, this reduction is vastly outweighed by the energy used by end-users coping with spam.
  3. Most inboxes are protected by spam filters, but many of them are less accurate than the best filters. Some inboxes are still completely unprotected. State-of-the-art filters can achieve better than 98% effectiveness/0.01% false positives and use less power: assumes 25% power saving over legacy spam filters.
  4. Based on passenger car averaging 20 miles per U.S. gallon; mean equatorial circumference 40,041 km (24,870 miles).
  5. Refers to an organization with 200 average business email users.

Incremental Energy

In any calculation such as this, there's always the concern that we're double-counting energy that would have been used whether or not there was spam. Let me assure you that this isn't the case. I only wanted to be involved in the project if we were measuring this meaningfully.

So the data and calculations were carefully designed so as to only measure energy that is used as a direct result of there being spam. In other words, it is "incremental" energy.

PCs and servers use less energy when idle than when doing "work"—in most cases it's this additional energy that we measured.

More About the Methodology

Some wags have complained that ICF doesn't publish its methodology. They have clearly not read the full report, including the appendix, which helpfully titled, err, Statement of Methodology. Perhaps they're confused by the 8 page summary?

Download Full Report

You can now get the full 28 page version at the usual place.

Radio Interview

ORF interviewed me on Friday. Download it here: richi-on-orf.mp3.

Monday, 6 April 2009

Hidden Risks of Intellectual Property in Email

I was talking recently to a client. We were discussing how organizations use email and the conversation turned to "inappropriate" use.

Ah, no. Not that sort of inappropriate use.

I'm talking about storing confidential information in an organization's email. Perhaps even sending that confidential information to people who have no right to receive it.

Just about every organization has this type of confidential information. It could be customer data or intellectual property, such as future product plans or patentable know-how. Whatever it is, organizations run a huge risk by allowing their users to email it.

And I'm not necessarily talking about attacks on the email system. Even the most sophisticated user can accidentally send the wrong thing to the wrong person.

Even if the information stays inside the organization, it's at risk from malicious insiders—if someone has access to an Exchange server, they can read the entire message database without needing any passwords.

And I'm not talking about a few scraps of information, either. When you look at a typical organization that's reasonably email-centric, a significant number of them might have the vast majority of their confidential information stored in their email—as much as 85% of it.

So what to do about it?
  • You could try educating your users... but that sounds like the epitome of cat herding.
  • You could shut down your email system... but isn't that rather self-defeating?
  • Various vendors will sell you tools for data leak prevention (DLP).
Combined with user education, DLP can do a reasonable job of helping email users "keep it in the family." But it isn't magic; it does need care and feeding.

It does need to be taught what your confidential information looks like, and who should be permitted to see it. And that teaching process isn't just a one-off chore—it needs to be ongoing.

Wednesday, 18 March 2009

Where's Richi?

Yes, I'm not blogging here much these days. So what am I up to?

In addition to my Computerworld daily ramblings and Ferris Researchings, you can mostly find me microblogging on Twitter.

You'll also find me at Facebook, LinkedIn, FriendFeed, and FriendFace.

Here's a full list of contact details.

Friday, 6 March 2009

IT Blogwatch roundup

Here's a catchup of the last two week's of IT Blogwatching. Sorry I missed last week's post: I had a rush job on.


TomTom fights Microsoft to protect GPL?

TomTom logoIn a special IT Blogwatch Extra, Richi Jennings watches the growing disquiet over Microsoft's TomTom patent lawsuit. Not to mention what Darth Vader finds disturbing...

...Read more

Obama: we need a CIO before a CTO

ObamaIn Friday's IT Blogwatch, Richi Jennings watches a surprise Obama appointment: a CIO (confounding commentators' CTO conjectures). Not to mention MeggySeq...

...Read more


Windows 7 allows IE uninstall

Windows 7 screenshotIn Thursday's IT Blogwatch, Richi Jennings watches Microsoft allow users and OEMs to actually remove IE -- sop to Europe or misdirecting canard? Not to mention 3D street art...

...Read more


Skype SILK codec set free-as-in-beer

Skype logoIn Wednesday's IT Blogwatch, Richi Jennings watches Skype open up its fancy new voice encoding technology. Not to mention London Underground: run by people, not androids...

...Read more


New Apple desktops: fanbois drool

Apple logoIn a special IT Blogwatch extra, Richi Jennings watches Apple quietly revamp its entire desktop hardware line. Not to mention Square Root Day...

...Read more


Demonstrators demo at DEMO 09

Demo logoIn Tuesday's IT Blogwatch, Richi Jennings watches bloggers watch the DEMO 09 conference. Not to mention what not to wear...

...Read more


Iran leeches Obama's helo. plans, peer2peer

Marine One (U.S. Marines; public domain)In Monday's IT Blogwatch, Richi Jennings watches the fear, uncertainty, and doubt surrounding the discovery of Marine One blueprints on a peer-to-peer network. Not to mention how extra airline fees may have gone too far...

...Read more


Windows 7 RC on its way

Windows 7 screenshotIn Friday's IT Blogwatch, Richi Jennings watches Microsoft announce tweaks to Windows 7 in time for the upcoming Release Candidate build. Not to mention Darth Walkies...

...Read more


Microsoft "recalculating route" of Linux patents

TomTom logoIn Thursday's IT Blogwatch, Richi Jennings watches Microsoft sue TomTom over its Linux patent "infringement" -- is this the beginning of the end? Not to mention a Mac Mini inside a Disk ][ Drive...

...Read more


Apple Safari 4: better, stronger, faster?

Apple logoIn Wednesday's IT Blogwatch, Richi Jennings watches Apple launch the Safari 4 beta, claiming improved speed and standards-compliance. Not to mention paper computers...

...Read more


Microsoft: "Just kidding; keep the money"

MicrosoftIn Tuesday's IT Blogwatch, Richi Jennings watches Microsoft overpay redundant employees, ask for the money back, then change its mind. Not to mention Error'd...

...Read more


Steve Jobs is "offline"

Apple logoIn Monday's IT Blogwatch, Richi Jennings watches the curious case of Steve Jobs' instant messaging presence (or recent lack of it). Not to mention exploding, flying, and crashing servers...

...Read more