Re: Moving forward ...

"Jesse Dougherty" <[email protected]> Thu, 26 Feb 2004 15:07:17 -0800
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
>
> Yes, SUPERIDS might set some admin's pager off, or log something, or
> whatever.  But meanwhile someone downstream's had their email
> intercepted and/or altered, and might want to be notified of
> that.  The
> admin might call them, or send a separate email, but you
> could say the
> same about any type of filter down the line too; it seems that if
> anything should or could be inserting headers in the email to notify
> the downstream that some filtering action's been taken, then
> this would
> qualify, but doesn't, I think, fit in with any of the 3 things you'd
> outlined earlier.

This is similar to the case where a virus is stopped at the gateway and
a notification of this event is delivered to the recipient to make sure
they're aware the communication was blocked.  Is this a decent analogy?
In this case a header may explain that all/part of the communication was
blocked for some reason.

Not sure that this would apply to an IDS situation though, would it?
Like wormspew, the recipient probably doesn't want the notifications, as
the message is essentially spam.

(though perhaps the spam filter at the next tier should catch that?)

> C
>
> On Feb 26, 2004, at 2:44 PM, <[email protected]> wrote:
>
> > I think you're discussing an implementation of a protection scheme.
> > Generally this would be logged, or some sort of audit flag would be
> > raised for an admin.  I wouldn't see an email with a
> filtering header
> > as this flag though.
> >
> > Am I not grokking your point here?
>
>