Proposed change in whitelist behaviour/undo whitelisting

Jens Finkhäuser <[email protected]> Sun, 22 May 2011 21:44:46 +0100
Newsgroups gmane.mail.spam.dspam.user,gmane.mail.spam.dspam.devel
Message-ID <[email protected]>
Hi all!

Over the past months (I've been distracted) I discussed with Stevan
Bajic some change in the way DSPAM whitelists email addresses, and
would like to ask what your take on it is.

Basically the one single aspect in which DSPAM fails me is that once
it's decided to whitelist an email address, it's really hard to tell
it not to.

The proposed change would affect how the whitelist threshold config
variable works, and therefore needs to be carefully considered, hence
my posting here.

The current behaviour:
  - A token needs 15x more innocent hits than spam hits to be
    considered for whitelisting, and
  - the token also needs to have more innocent hits than the whitelist
    threshold.

The proposed change is:
  - Consider a token whitelisted when:
    innocent hits - spam hits > whitelist threshold.
  - Reset innocent hits to zero once a whitelist token gets a spam
    hit.

Aside from removing a magic factor, the behaviour shouldn't be too
different. For a new token that hasn't got spam hits, the whitelist
threshold config variable would still determine how many innocent hits
are needed to whitelist the token.

It's when the token also has spam hits that the behaviour becomes much
more responsive. A single spam hit would stop a whitelisted token from
being whitelisted.

If you kicked the token out of the whitelist that way, you'd then not
need 15 *times* as many innocent hits as spam hits, but "whitelist threshold"
*more*. It still depends on how often the token has been marked as
spam how long it'll take to whitelist it again.

For the full discussion, visit
https://sourceforge.net/tracker/index.php?func=detail&aid=3142744&group_id=250683&atid=1126468

Thanks,
  Jens

-- 
1.21 Jiggabytes of memory should be enough for anybody.

------------------------------------------------------------------------------
What Every C/C++ and Fortran developer Should Know!
Read this article and learn how Intel has extended the reach of its 
next-generation tools to help Windows* and Linux* C/C++ and Fortran 
developers boost performance applications - including clusters. 
http://p.sf.net/sfu/intel-dev2devmay

_______________________________________________
Dspam-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/dspam-user
signature.asc (application/pgp-signature, 490 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)

iQEcBAEBCgAGBQJN2XW+AAoJEJ3L2gZ29FTgGOYH/1TsDnVYbCNzGJdzQa6x/pOj
ajqYjbaoBWIWDwJoFVX7vL/t8zc4WltCVSfVoXAFfhtainSp6+JBFwPnYM0rYZlh
TJ4KoM/uts8zMvbHmc06STAwunxUuPhnLdTrr+2k2eFtp0ncrmbtjlue0V9C6kEb
2olZp/NdXBTSJi76kTjkI9kvvfGUY3zV0L6zNB6KvHuBLFlASyPLFZoL7+Xq9bBW
A7k+Tz/mn8QARvHpaHzCiJxteDpoX2gOfIf665kzQzE5IU+cGpGvyVBKwnabRch6
FF/aAJywJcqtGWHD09PiZ+SRmG4YwI9ByLttfG0NXQrzvYc5UkDRBbebakofsu4=
=1+bg
-----END PGP SIGNATURE-----