Re: limitations of reputation, was Spam sent from compromised
Steve Atkins <[email protected]> Sat, 23 Mar 2013 11:21:22 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Mar 23, 2013, at 10:51 AM, Barry Shein <[email protected]> wrote: > > On March 23, 2013 at 13:38 [email protected] (Barry Shein) wrote: >> >> 1. When you see an id you haven't seen before then at least you know >> "hmm, this is an id I have seen before!" > > I hope the typo is obvious, "I HAVEN'T seen before". > > But it raises another research issue: > > How good is good enough? > > Is there any way to suggest a threshold a spam-fighting technique > should reach before we as a group (?) would issue a seal of approval? > > That threshold has multiple dimensions: > > 1. Types of spam etc it might stop > 2. How much it might stop > 3. Reliability > 4. Integrity (e.g., can viruses overcome it?) > 5. Likelihood of adoption by target audience (ISPs, end-users) > 6. Cost-benefit > 7. Approx time to adoption, reasons for resistance. Good list. I might expand it to 1. Types of spam etc it might stop Types of wanted mail it might stop Types of unwanted mail it might stop 2. How much it might stop How much wanted mail it might stop How much unwanted mail it might stop 3. Reliability Random failures vs Systemic failures - each user losing 0.1% legitmate mail is different to 0.1% of users losing 100% of their legitimate mail 4. Integrity (e.g., can viruses overcome it?) What evolution might it encourage in an intelligent, hostile attacker. 5. Likelihood of adoption by target audience (ISPs, end-users) 6. Cost-benefit 7. Approx time to adoption, reasons for resistance. > Obviously one can't (easily) put absolute numbers on such criteria but > we might be able to at least roughly partial-order them, this > technique is likely more effective on #N than that technique. > > How would we order current popular techniques such as SPF, DKIM, > Spamassassin, C/R, whitelisting, etc on these criteria? That's pretty complex, because many things we do with a vague thought of spam, don't actually have any effect on spam. (SPF, DKIM and whitelisting don't stop any spam at all, for instance.) It's the effectiveness of approaches when they're applied together that's interesting - if approach X stops 55% of spam and approach Y also stops 55% of spam then you can't use them both to stop 110% of spam. Maybe they stop 55% combined, maybe they stop 90% combined. I'm not sure whether it's easier to look at various combinations of approaches, or to look at the improvement delta when adding a new (theoretical?) approach to a baseline, whatever that baseline might be. Cheers, Steve - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org