Re: Single model or framework for reputation/trust

"Alan DeKok" <[email protected]> Mon, 03 May 2004 16:17:56 -0400
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Jeff_Silverman <[email protected]> wrote:
>      If reputation is a poor indicator in the "real" world, then is it 
> possible to use reputation for any useful purpose in the "cyber" world?

  That's not quite what I said.  I'll try to make it clearer.

  We have to distinguish positive statements about repututation (he
did X in the past, and thus will probably do X in the future), from
negative statements about reputation (he did X in the past, so we
don't think he'll do Y.)

  That is, even though reputations can themselves be positive and
negative (I'll try to use "good" and "bad"), the statements about
reputations can be positive (they WILL do X), or negative (they WON'T
do X).

  Positive statements about good or bad reputations are generally
strongly associated with future behavior.

  Negative statements about good or bad reputations are poorly
associated with future behavior.

  e.g. You send me 10^6 non-spam messages in a year.  Over the next
week...

  Q: What's the probability of you sending me a non-spam message?
  A: Pretty good.

  Q: What's the probability of you sending me a spam message?
  A: I'm not sure.


  So the idea behind reputation is NOT to catch people who behave in
unexpected ways.  Reputations can't do that.  The idea is to group
people into two sets: good (non-spam), and bad (spam).  If you can
group them with a high degree of confidence, you've got a good handle
on dealing with the spam problem.

  Alan DeKok.