Re: Single model or framework for reputation/trust

Ed Gerck <[email protected]> Tue, 04 May 2004 12:55:25 -0700
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Alan DeKok wrote:

>         Reputation is a strong indicator of future behavior.

Not in the real-world. Reputation is a measure of past behavior.
Surely, an indicator of future behavior can use reputation as one of its
inputs. Reputation per se, however, is not an indicator of anything
except that which *has* occurred and, even then, not objectively.

For example, without a behavior model (which needs to be made
explicit), there is no indication possible for future behavior, even
though all relevant reputation data may be available.

In Russell's example, the chicken was portrayed with a very naive
behavior model: what you see today, you will see tomorrow. This
model shunts the reputation input to the output of the predictor.
The farmer had no reputation of evil intent, so that's how the farmer
will behave in the future. Of course, this model involves a leap of faith
and that's exactly why it failed.

Russell cleverly used the word 'chicken' to describe this naive model.
A fox would behave differently and would not have considered that
reputation is a strong indicator of future behavior.

Things get even more complicated in the cyber-world (email). Behavior
models can be quite volatile. There is no inertia. Reputation becomes
less important in a mix of inputs for a model predicting future behavior.
In fact, reputation can become quite misleading.

The standardization effort done here can be understood as the safe
automation of a process of reliance. This goal requires the elimination
from the automated process of violations of those policies (i.e.,
vulnerabilities) that might be hard to recognize or difficult to foresee.

Experience shows that one such vulnerability comes from using a policy
where reputation is a strong indicator of future behavior. It's frequently
and easily violated in the cyber-world. Software behavior can change
quickly, masking bad reputation. User data can be silently shared
with no perceived loss of reputation. Email can be forwarded to and
redistributed by a large number of unwilling senders. Senders are not
authenticated, so reputation cannot even be well-defined to begin with.

Cheers,
Ed Gerck