|
|
BRAVO
TECHNOLOGY CENTER
|
SPAM Concepts and Strategies |
by Sam C. Chan |
First published: January 15, 2008 Last Updated: May 21, 2010 |
|
- Philosophical Points
- all Brute-force methods will fail by definition
- Asymmetrical war: zero-cost and infinite leverage
- Prevention vs Filtration
- most points are subtle and often counter-intuitive!
- vendors can only potentially supply tools, but never
solutions
- SPAM Filtering
-
Server-side vs. Client-side
- control & jurisdiction
- flexibility
- ease-of-use
- wasted traffic
- Filtering Methods (5 types)
- conservative DNSBL (against only
top known spammers)
- aggressive DNSBL (against all
likely spammers)
- banning servers from ISP consumer list
(avoid all "zombies")
- content keyword triggers
- content keyword Bayesian pattern
weighing
- content type ban policies (scripts,
forms, etc.)
- Challenge-Response white-list human
test
- Trade-off: false Negative rate vs. false Positive rate (FNR/FPR)
- damage of 1 piece of lost mail equates
that of 100 pieces of slip-thru
- different classes of email addresses
have varying degree of tolerance & need
- Cascaded Filtration
- resultant FNR is subtractive
- resultant FPR is additive!
- SPAM Prevention
- Sources
of Leaks & Circulation
- Defensive actions
- use multi-tier address scheme
- expire and rotate all but primary
address
- hide domain registrar contact email
- observe BCC and other rules regarding
group mailing
- use script/image for publishing email
on web, or use form mail for public
- establish tracking mechanism
(catch-all, source-coding)
- use "no-reply" address (1-way
email)
- blackhole policy
- Best Practice
- establish formal, comprehensive anti-SPAM
initiative
- employ sensible combination of methods
- primarily rely on SPAM prevention,
supplemented by
- lax filtration at server side, using
cascaded schemes, plus optionally
- mildly aggressive filtration at client
side, frequently adjust to personal taste
- note: Safe Sender list is
effective & acceptable, while Blocked sender list is not!
- do it right, from start
- maintain discipline
|
|
|
|
|
Copyright
@2005-2006
Bravo Technology Center *
Bravo:GO *
Contact Us
|
|