Re: Email Web of Trust - Defining the metrics
Yakov Shafranovich <[email protected]> Thu, 18 Mar 2004 01:35:03 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | SolidMatrix Technologies, Inc. |
| Message-ID | <[email protected]> |
Ed Gerck wrote: > > Jeff Silverman wrote: > >>Regarding the counters, I would like to see number of messages >>successfully sent and the number of messages successfully received. My >>observation is that spammers send thousands of messages and receive few >>- normal people receive few messages and send fewer. So, in my mind, >>the ratio of inbound to outbound messages is telling. > > > A simple bound for the number of messages sent per hour is used by some webhosting and DSL companies to throttle the rate of messages sent, with > a warning sent back to the user when the bound is exceeded. One example > is SBC. They know their own counters are correct and take preventive > actions based on the values they read. > > However, when we want counters for (a) the number of messages sent > per hour and/or (b) the ratio of inbound to outbound messages, in order > to rate a third-party MTA by values provided by that MTA, we need to > take into account that those numbers (while useful) cannot be trusted. > What's required is an external agent, trusted to be a correct counter, > to provide or verify those numbers. The external agent needs to be as > independent as possible in gathering such information for the MTA being > rated. > > There are a number of places where such an external agent could > be placed. Random sampling, to reduce the agent's workload, should > work because spam messages would be sent in numbers large enough > to be detectable by sampling, both in time as well as in space > (i.e., we should not need many agents). > I think that our original thought was that any given MTA can publish counters based on the analysis of its incoming traffic. Of course, you can also have different systems like Senderbase which aggregate data from multiple MTAs. There are obviously issues of trusting a specific MTA or information provider to have the correct data. The most real life example is Senderbase (btw, have we invited them yet?), and I don't know if people question their numbers. Yakov