Re: [Asrg] An Anti-Spam Heuristic

Rich Kulawiec <rsk@gsp.org> Thu, 13 December 2012 14:04 UTC

Return-Path: <rsk@gsp.org>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F74E21F8AD6 for <asrg@ietfa.amsl.com>; Thu, 13 Dec 2012 06:04:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.293
X-Spam-Level:
X-Spam-Status: No, score=-6.293 tagged_above=-999 required=5 tests=[AWL=-0.009, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, SARE_MILLIONSOF=0.315]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id htBp4C-57Ppq for <asrg@ietfa.amsl.com>; Thu, 13 Dec 2012 06:04:23 -0800 (PST)
Received: from taos.firemountain.net (taos.firemountain.net [207.114.3.54]) by ietfa.amsl.com (Postfix) with ESMTP id D3C3B21F8AD5 for <asrg@irtf.org>; Thu, 13 Dec 2012 06:04:22 -0800 (PST)
Received: from gsp.org (bltmd-207.114.17.210.dsl.charm.net [207.114.17.210]) by taos.firemountain.net (8.14.5/8.14.5) with ESMTP id qBDE44QI019391 for <asrg@irtf.org>; Thu, 13 Dec 2012 09:04:05 -0500 (EST)
Date: Thu, 13 Dec 2012 09:03:59 -0500
From: Rich Kulawiec <rsk@gsp.org>
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
Message-ID: <20121213140359.GA2187@gsp.org>
References: <SNT002-W143FB9A867C92FA80D90E04C54E0@phx.gbl>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <SNT002-W143FB9A867C92FA80D90E04C54E0@phx.gbl>
User-Agent: Mutt/1.5.20 (2009-06-14)
Subject: Re: [Asrg] An Anti-Spam Heuristic
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Dec 2012 14:04:23 -0000

> A number of heuristics include increasing the computation required to
> send and receive an email, for example one to a few minutes of computation
> per email on desktop computers.

Presume an adversary with computing resources that routinely range in
the area of "tens of millions of systems", with all the processing,
memory, disk, and bandwidth resources that implies.  Presume that those
systems are capable of coordinated or independent tasks as designated
by the adversary.  Show how this approach will have a meaningful effect
on the adversary's ability to generate/transmit [SMTP] spam.

Simultaneously, presume the existence of hundreds of thousands of highly
useful mailing lists (e.g., "ietf", "nanog") with varying numbers of
members and show how this approach will not adversely affect their
ability to function in the way they've been functioning for decades.

I don't think you can do this.  I think you're trying to drown someone
who owns the ocean, and that the attempt is futile.  But perhaps you have
an approach that's eluded others, that overcomes the obvious problems,
and I just don't see it yet due to insufficient caffeine intake.

---rsk