RE: My Gnutella spam reduction idea revised

"Philippe Verdy" <[email protected]>
Newsgroups gmane.network.gnutella.devel
Organization Ordinateur Personnel
Message-ID <[email protected]>
I tend to agree with the conclusion; in fact it's quite simple to test the
effect of the modified query string, and to compare the results;
One of the easiest way to see spam is the human eye, we select them, declare
them as garbage, this records the spamming sources, and then we can perform
or continue our request, these ips will be blocked for the current session.

The other way is to declare the content as spam using the hash value and
content length, because they want us to download their garbage, and those
files with many matching "titles" have these in common.

The other type of spam is the contamination of existing valid files, that
they distribute with data injection; the hashes are "valid" but change with
each source, as well as the content length. This requires much more
resources for spammers, as they need to download and distribute the useful
content before being able to contaminate it, so they need large storage
space. But most of these cases come from "legit" users whose PC has been
contaminated by virus that are injecting malicious code in their shared
files: notably executable files, zip/cab archives, and MPEG or images whose
format is known to have security issues on some platforms (for example GIF,
icons, WMF...). Vigilance of users (and running an antivirus) is the best
tool to allow those infected files to be scanned and dropped immediately
before they can be shared again to the network after download.


> -----Message d'origine-----
> De : [email protected] [mailto:[email protected]] De la part
> de Elias Athanasopoulos
> Envoyé : lundi 23 avril 2007 20:59
> À : [email protected]
> Objet : Re: [the_gdf] My Gnutella spam reduction idea revised
> 
> Hello!
> 
> just_courtney_girl wrote:
> > I just rejoned under a new address.  In a post
> > sometime back, I came up with a spam reduction
> > idea.  I had an idea for eliminating junk hits.
> > The problem is the On-The_Fly spam generators
> > that take the Gnutella search string and
> > create files with the search strings in the
> > name.
> [snipped]
> > Now lets say I searched for voic trainin:
> >
> > voic_trainin_install.exe
> > voic trainin porn video.avi
> > voic trainin xxx.mpg
> > voice training - control breath and tone.mp3
> > [crack] voic trainin.zip
> > voic trainin sales affiliate program.doc
> > xxx voic trainin.mpeg
> >
> > Now, do you tell which is the intended result
> > and which is the spam?
> 
> You are just forcing the spammers to become more sophisticated, and,
> IMHO, it takes no more than a few lines of code for a spammer to defeat
> your spam defense algorithm. Simply, the spammer just passively modifies
> QueryHits, which has even better effect, from the spammer's view point:
> (a) you can not say in any similar way to your algorithm that the Hits
> are spam, since they are produced from a legitimate peer (b) the spammer
> does not need to care if Hits from legitimate peers travel faster than
> her own Hits to the original querier, since she just altered the
> original Hits with her own spam IPs.
> 
> I am against in using naive algos in order to defeat trivial spammers,
> since you are just forcing them to become even more clever. Today the
> majority of Gnutella users can filter on their own spam results, because
> spam is easily spotted using the human eye. Tomorrow, if spammers employ
> techniques like the ones I mentioned above, the spam will become much
> much more serious issue...
> 
> Regards,
> --
> Elias Athanasopoulos
> Distributed Computing Systems (DCS)
> Institute of Computer Science (ICS/FORTH)
> Heraklion, Crete
> 
> A bug can become a feature by documenting it.
> 
> 
> 
> 
> Yahoo! Groups Links
> 
> 
> 
> 
> --------------------------------------------------------------------------
> -------------
> Orange vous informe que cet  e-mail a ete controle par l'anti-virus mail.
> Aucun virus connu a ce jour par nos services n'a ete detecte.
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.