Re: Single model or framework for reputation/trust
Ed Gerck <[email protected]> Tue, 04 May 2004 12:55:25 -0700
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Alan DeKok wrote: > Reputation is a strong indicator of future behavior. Not in the real-world. Reputation is a measure of past behavior. Surely, an indicator of future behavior can use reputation as one of its inputs. Reputation per se, however, is not an indicator of anything except that which *has* occurred and, even then, not objectively. For example, without a behavior model (which needs to be made explicit), there is no indication possible for future behavior, even though all relevant reputation data may be available. In Russell's example, the chicken was portrayed with a very naive behavior model: what you see today, you will see tomorrow. This model shunts the reputation input to the output of the predictor. The farmer had no reputation of evil intent, so that's how the farmer will behave in the future. Of course, this model involves a leap of faith and that's exactly why it failed. Russell cleverly used the word 'chicken' to describe this naive model. A fox would behave differently and would not have considered that reputation is a strong indicator of future behavior. Things get even more complicated in the cyber-world (email). Behavior models can be quite volatile. There is no inertia. Reputation becomes less important in a mix of inputs for a model predicting future behavior. In fact, reputation can become quite misleading. The standardization effort done here can be understood as the safe automation of a process of reliance. This goal requires the elimination from the automated process of violations of those policies (i.e., vulnerabilities) that might be hard to recognize or difficult to foresee. Experience shows that one such vulnerability comes from using a policy where reputation is a strong indicator of future behavior. It's frequently and easily violated in the cyber-world. Software behavior can change quickly, masking bad reputation. User data can be silently shared with no perceived loss of reputation. Email can be forwarded to and redistributed by a large number of unwilling senders. Senders are not authenticated, so reputation cannot even be well-defined to begin with. Cheers, Ed Gerck