Re: Email Web of Trust - Defining the metrics

"Alan DeKok" <[email protected]> Wed, 17 Mar 2004 13:17:20 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Mark Baugher <[email protected]> wrote:
>     I think we should try to capture the antispam counters as SNMP 
> Management Information objects (SMIv2), we should define access to these 
> counters using SNMPv3, and we should consider shortcomings and alternatives 
> to SMIv2 and to SNMPv3.

  I agree.  Having a standard for recording such information means
that it's easier to exchange data, and to talk about that data.

> For example, can IPsec be used for providing privacy and antidos as
> well as confidentiality and integrity to SNMP protocol operations?

  I would start off by defining what data needs to be recorded, and
worry about publication/exchange of that data later.

> Is the SNMP management information (SMI) definition suitable for
> what we need or are there better ways to represent the information?

  SNMP is probably sufficient.

>    This work should come after a description of one or two applications 
> that can use the counters such as a trusted reputation service.

  I would turn that around.  Once you define the foundation of a
service (what it's measuring), it's possible then, and only then, to
describe how that services uses that data.

>   I expect we would undertake this work only if we are sure that it
> can support a trusted reputation service using, for example, a web
> of trust model where members trust other members to maintain counter
> integrity.

  A system should be immune to attacks on the counters.  At the
minimum, if everyone maintains their own counters, you know how much
you can trust the data.

>    This work could be considered as a formal RG work item and intended to 
> be published as an Experimental RFC (such RGs publish on Experimental or 
> Informational RFCs).  I would be willing to author or co-author the 
> document.  I have previously done an SNMPv1 MIB using an SMIv2 compiler, 
> http://www.ietf.org/rfc/rfc2959.txt

  Sounds good to me.

  Alan DeKok.