BCP on dealing with hijacked machines

Yakov Shafranovich <[email protected]> Sat, 28 Feb 2004 23:10:59 -0500
Newsgroups gmane.ietf.asrg.bcp
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
This message is from the SMTP VERIFY list. Does anyone want to volunteer 
to help with drafting a BCP for this, can provide real-life deployment 
experience, and perhaps provide information regarding the effectiveness 
of this?

Yakov

-------- Original Message --------
Date: Sat, 28 Feb 2004 20:25:22 -0800 (PST)
From: William Leibzon <[email protected]>
CC: [email protected]

On 29 Feb 2004, John Levine wrote:

> ISPs that care have been dealing with this all along.  You count the
> messages from each host, and if you see a big spike, you either
> suspend the account or confine the host to a web jail that tells them
> to disinfect their computer and call in to get out of jail after they
> do.  The jail's like the one you're in when you connect to a hotel
> network and haven't agreed to pay the ten bucks yet.  The mail spikes
> are not subtle.  Hosts that normally send five messages a day start
> sending blasts of thousands.  

The above "jail" system is not as widely used. More common is simply
redirection of port25 to main ISP mail server relay and calculating how
much traffic is coming from specific user/port.

> This is not a research topic, since ISPs
> do this in production now and the techniques are well known. 

That particular anti-spam technique is done in production does not mean 
it  should not be an issue for ASRG. ASRG should still research how 
effective  the technique both currently and towards the future and 
compare it to any other proposals that are being made.

Additionally since this has not been documented by IETF it maybe good
idea to work towards BCP document for mail setup for ISPs that service
dial/dsl/cable customers. It does not mean that ISPs will necessarily
follow it, but it might still improve the situation with availability of
hijacked PCs.