Filtering messages of the same type lets you configure a limit on the number of messages sent by a user of your organization per unit of time. The main purpose of this limit is to prevent a situation where an infected mailbox automatically generates an endless stream of messages sent to internal and external recipients. When filtering attachments of the same type, Kaspersky Security searches for messages that meet the specified filtering criteria. Filtering messages of the same type is available if the Anti-Virus for the Hub Transport role component is installed on the Microsoft Exchange Server.
Messages are classified as being of the same type if they have one of the following attributes:
The application identifies messages that have the same subject. The message subject analysis is case sensitive.
The application identifies messages that contain file attachments with the same extension and the same name (case sensitive).
The application identifies messages that satisfy at least one of the criteria.
You can also apply a limit to any messages sent by internal recipients, regardless of whether they have common attributes.
The application can apply one of the following actions to messages of a quantity exceeding the set limit:
The application keeps a separate tally of the number of messages for each Security Server.
If necessary, you can configure exclusions based on email address, and not apply limits to specific users of your organization.
The application can log events related to filtering messages of the same type to the Windows Event Log, and notify you about those events by email. You can configure the necessary settings in the Notifications node.