Re: Spam sent from compromised (web)hosts vs botnet spam

Dan Oetting <[email protected]> Thu, 21 Mar 2013 10:20:03 -0600
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 21, 2013, at 2:51 AM, "Emanuele Balla (aka Skull)" <[email protected]> wrote:

> The side effect is the colo doesn't see any significant traffic, as the
> only traffic going in and out the machine they host is return traffic
> (non-tunneled going IN, tunneled going OUT). So, unless you (as colo)
> know what to look at, there's nothing triggering your alarms…

Many years ago, i suggested a simple solution. In cases where traffic is presumed to be abusive such as an SMTP transaction involving multiple invalid accounts, send back an ICMP error that network providers would be able to watch for as a hint to what traffic they should be monitoring. Since these reports would be returning in real time, automated monitoring tools could be developed to snapshot the transactions that triggered the report so the provider would have all the evidence from their own network if they chose to look into it. The tools themselves could even do much of the preliminary analysis looking for common patterns and triggering alarms when problems are discovered.

-- Dan Oetting


-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org