Re: Some last info regarding analysis

"Kurt Magnusson" <[email protected]> Tue, 24 Feb 2004 16:45:40 -0300
Newsgroups gmane.ietf.asrg.analysis
Message-ID <[email protected]>
Jose Marcio,

>We use URL blocking here, but it seems, for our domain, that it is somewhat 
>limited.
>
>We begun adding some URLs a day, and the number of URLs grew till little 
>more than a thousand. After that, I begun tweaking the URLs to lower the 
>number. I also begun to remove URLs that weren't seen for more than four 
>months. Now, I have only 130 URLs.

Seems that you found the same as I did, i.e. if you removes the prefix
domains and works with the least common denominator, you get far fewer
domains. Then the filter only need to grep them properly, because there
is only that many ways to disguise them.

My problem is that I use the Solaris grep and something is wrong in that
one, making the match not only from the found URL's against the data
file, but also for the domains in the data file against other words in the
mails, a completely wrong behaviour.

I have some 19000 domains in my data file, but most of those I sieved
out from ca 150000 spams I retreived from Spamarchive, so I block
url's I never seen.

>OBS - the time spent by the filter looking for regular expressions grows 
>fast with the number of URLs (faster than linear).

True, true, that is the fault of my own filter, it works OK for a single
mbox as in my shellscript PoC, but you need to have some hashed dbs
to speed it up. My problem is that redoing it, is out of scope for me.

Terry have looked at alternate methods, but it seems that it have to be
exact matches to be really efficient.

>So, I think there shall be some number of tweaked URLs that can be used to 
>get some effectiveness with little maintainance - adding/removing few URLs 
>a week.
>
>After that threshold, the work necessary to increase effectiveness grows 
>vary fast, and you need to add/remove too many expressions a week.

I simply has a honeytrap, to which I send over the spams. It extracts
and build a new data file. I then have a cron job updating the data
file based on the reworked file from the honeypot. I.e. the manual
part is the remailing. I don't do statisticals on the existing URL's, so
I can't remove unused domains.

>So, IMO, it's better to use URLs to get some effectiveness and complete it 
>with a different approach.

I have today a second step, where my ISP's SpamAssasin filter labels
spams in subject. Spam Earnest did not caught, I then take and
send automaticlly to the honeypot.

This is the drawback of all content blacklists, new content can't be
caught automaticlly, which was Kee Hinckleys main critisism when I
presented Earnest last year. I still is to get to the finish line on that,
but while my ISPs SA presently letting through 5 of 35 spams a day,
I am now back to 1-2 a day.

Regards Kurt

_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE* 
http://join.msn.com/?page=features/virus