ietf-asrg
[Top] [All Lists]

Re: [Asrg] 0. General - Define Spam

2004-01-05 10:21:52
AD>

  I've seen a ~10x increase in spam to my systems in the past two
months.  It's *ridiculous* that there's so much opposition to doing
anything.  Of *course* any anti-spam system will be short-term, and
won't solve the problem.  But it should give us the breathing room to
work on a more complete solution.


On the free webmail system that I'm familiar with, the "spam" problem has
been largely solved from the *user* perpective by simply using a couple
"low-power" and fairly conservative BLs
(currently stopping 31% of incoming mail)  followed up by SA based
filtering (37% to to a SPAM folder with automatic ageing out). a simple
whitelisting facility is also provided. Clearly, the provider is paying for
this with CPU and bandwidth, but both users and management seem quite happy

My employers use a broadly similar system on the corporate email system.
Again, usrs and mgmt seem happy.

 
Incidentally, on the webmail there's also a certain amount of egress
control. So it's thought that the potential for abuse is fairly well
controlled.

Now IS the breathing space. A complete solution (if such a thing is
possible) needs a problem definition. You know that I like the consent idea
- NOT because it gives us a "a 'perfect' definition of spam ... For a
particular system, any message locally determined to be spam.", but because
it enables us to work *without* a spam definition. Instead we have a thing
called consent which can be represented, transported, queried etc. We can
evaluate systems in terms of how well they support consent. We can worry
about edge/middle issues, anonymity and so on.

How to do all this - that's suitable matter for research - this may be the
long term way forward. This is not to say that all the work being done on
sender verification / content based filtering etc isn't worthy, of course
it is - that's what has given (is giving) us this breathing space.
 
Quick fixes have their place - I'm not convinced that place is a RG.





--

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg