Re: Strawman abuse report format proposal

Brian McNett <[email protected]> Mon, 27 Sep 2004 21:28:06 -0700
Newsgroups gmane.ietf.asrg.abuserep
Message-ID <[email protected]>
On Monday 27 September 2004 20:18, Steve Atkins wrote:
> This is a strawman proposal for an abuse reporting format. Comments and
> discussion actively encouraged:

I'm not a big fan of MIME attachments in abuse reports, for largely historical
reasons.  I'm glad to see that you recognize that some recipients of abuse
reports are using systems for which MIME support is insecure and MIME
attachments are not to be trusted on.

I think MIME message/rfc822 and MIME text/plain are acceptable and reasonable
proposals, however.  I'm leery of creating new MIME types and requiring
recipient abuse desks to support them as part of any standard, but as these
are pre-existing types I see less of a problem with them.

> A single line in the body of the message for each recipient, giving
> enough information to triage the report. Each line should have an
> (optional) tag to define which recipient the information is intended
> for, a keyword chosen from a short set of keywords (TBD) to define
> different complaint types, e.g SPAM - generic unwanted email
> complaint, and an associated (optional) IP address, email address,
> hostname or URL.

This works as long as each recipient is responsible for exactly one
domain/URL/IP address per report.  In cases where more than one resource is
being abused per recipient, what would be the appropriate format?  A single
line for each abused resource, indicating which recipient is responsible,
presents signifigant duplication of data.

Lets say for example that spam originates from a comcast.net IP address
spamvertising pages hosted or reverse-proxied on/through zombie machines on
comcast, roadrunner, and cox, with the DNS rotating through a list of 20 IPs
at two minute intervals.  The two nameservers are on Hanaro Telecom. That's
seven IP addresses for each end-user ISP and two IP addresses for Hanaro
Telecom.  This may be an extreme scenario, but I have personally encountered
it in the past.

Add to this one other class of report recipient:  Domain registrars.  Several
domain registrars take a dim view of their customers registering domain names
to send spam.  They will enthusiastically revoke a domain registration given
appropriate evidence.  Let's say in the above example the spammer has two
domains both registered through GoDaddy.  That's 24 abused resources spread
across five recipients, all encompased within a single spam.

The above is actually a modest example.  Spammers engaged in this behavior
employ upwards of thrity domain names at once, mapped to between 75 and 400
rotating IP addresses.  With roughly a dozen IPs per recipient abuse desk,
what will the report look like?

It's not possible to predict whether or not today's extreme cases will become
tomorrow's norm.  However, as asian countries crack down on "bulletproof"
hosting, spammers will look for other ways to protect themselves from
complaints. The above scenario is a method which already exists and is in
use, and plays havoc with a "one-line-per-recipient" report format.

Basically, this is a scaling issue.  How well does this format scale when
reports involve multiple abused resources spread across multiple recipient
abuse-desks?  Does a report involving 400 abused addresses (in regards to a
single spam) require a 400-line report?

--B

--
"Stick a wick in a can of Spam, light it, and the room will glow for hours
with the sweet smell of pressed pig parts..."
                                          --Palm Beach Post, Sept 12, 2004