
Originally Posted by
FN1910
Your 97% figure for spam etc. is about right. We have a Barracuda box and that thing is well worth the money. Since we have installed it about 7 years ago I have seen the percentage of spam slowly rise. Right now about 95% is blocked immediately because of blacklist or similar identies. Another 1-2% is then blocked for meeting the spam filter settings of types of email. Another 1-2% is the passed through but flagged in the subject line of the email as possible spam. That leaves 1-3% as getting through without any flagging. Out of that 1-3% it includes, advertisements from legitimate vendors, jokes being passed around the Internet, and pictures of babies or such stuff. Out of all the mail sent to us from outside the network about 0.5% is actual useful work related email.

Any time someone comes to my office complaining about spam in their email I just show them the graph from the Barracuda box and threaten to turn it off for them.

Very seldom do I have any more complaints.
I also have a Fortigate firewall that does some email and web filtering along with a monitoring server supplied by Homeland Security and the email server itself does some.
There are several different thigs that heuristics looks at including known and unknown codes. As you say it is marginal as to how much new stuff it finds. I think that is partly because the turnaround time on
patches for new stuff is so quick that there is very little that hit our machines that is not known. The biggest problem is the intentional stuff that people download that opens holes for everything else. When I investigate an infected machine I usually find that it started when they downloaded some "cute" program or didn't pay attention to what it was asking. I have seen machines where there litterally was no room left on the screen to display a web page because of all the toolbars at the top of the browser. I didn't realize that there were that many available.

Seems like you can't install anything now without having to uncheck a toolbar box.
For me, it is far better to grasp the Universe as it really is than to persist in delusion, however satisfying and reassuring. - Carl Sagan .When you understand why you dismiss all the other possible gods, you will understand why I dismiss yours - Stephen Roberts