Re: [Asrg] DNSBL caches and IPv6, again
Dave Warren <lists@hireahit.com> Wed, 19 September 2012 21:55 UTC
Return-Path: <prvs=16098981ca=lists@hireahit.com>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
with ESMTP id 4635121E80B8 for <asrg@ietfa.amsl.com>;
Wed, 19 Sep 2012 14:55:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.11
X-Spam-Level:
X-Spam-Status: No,
score=-2.11 tagged_above=-999 required=5 tests=[BAYES_05=-1.11,
RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JbwpWjd2LjhK for
<asrg@ietfa.amsl.com>; Wed, 19 Sep 2012 14:55:10 -0700 (PDT)
Received: from vinny.hireahit.com (vinny.hireahit.com [72.51.42.137]) by
ietfa.amsl.com (Postfix) with ESMTP id 9C39421E80AF for <asrg@irtf.org>;
Wed, 19 Sep 2012 14:55:10 -0700 (PDT)
Received: from [172.24.0.107] by hireahit.com (vinny.hireahit.com)
(SecurityGateway 2.0.7) with SMTP id SG002718190.MSG for <asrg@irtf.org>;
Wed, 19 Sep 2012 14:54:52 -0700
Message-ID: <505A3F38.4030805@hireahit.com>
Date: Wed, 19 Sep 2012 14:55:04 -0700
From: Dave Warren <lists@hireahit.com>
User-Agent: Mozilla/5.0 (Windows NT 6.2; WOW64;
rv:16.0) Gecko/20120905 Thunderbird/16.0
MIME-Version: 1.0
To: asrg@irtf.org
References: <alpine.BSF.2.00.1209191729210.75412@joyce.lan>
In-Reply-To: <alpine.BSF.2.00.1209191729210.75412@joyce.lan>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-SGOP-RefID: fgs=0 (_st=1 _vt=0 _iwf=0)
Subject: Re: [Asrg] DNSBL caches and IPv6, again
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>,
<mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>,
<mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 19 Sep 2012 21:55:11 -0000
On 9/19/2012 2:33 PM, John R. Levine wrote: > As I've mentioned a few time, I'm trying to figure out the cache > behavior of DNSBLs, so we can try and predict whether IPv6 BLs would > make the DNS melt down. > > If I had traces of [IP,timestamp] from some medium sized mail sytems, > I could do some cache simulations. Medium is in in the range of a > million connections a day. Anyone have access to one of those? > Nobody has IPv6 mail at that scale yet, but IPv4 would do fine for this. > > I don't need to know whether the connection was for real mail or > spam. If you consider the IPs confidential, hashes or tokens would be > fine so long as the same token consistently corresponds to the same IP. Isn't the fear that with IPv6, spammers simply won't use the same address twice, thereby causing cache meltdown on a scale that isn't possible in today's IP-scarce IPv4 world? In other words, the data you get from legitimate mail servers in IPv4 may roughly correspond to the data you'd get from legitimate mail servers in IPv4, but the data you get from spammers today won't be at all representative of IPv6 spammer's potential behaviour. Heck, even the data from legitimate mail might not mean much going forward. I'd be at least a little tempted to send mail from different clients from different IPs (or possibly even with more granularity for clients who send person to person, bulk and transactional mail, but don't currently send enough to justify wasting IPs to segregate such traffic), so even legitimate sites might end up using a lot more outbound IPs, simply because they can. In other words, as much as I'd love to see some concrete data on this going forward, I'm not sure that these simulations will apply to future real-world situations. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren
- [Asrg] DNSBL caches and IPv6, again John R. Levine
- Re: [Asrg] DNSBL caches and IPv6, again Dave Warren
- Re: [Asrg] DNSBL caches and IPv6, again John Levine
- Re: [Asrg] DNSBL caches and IPv6, again Chris Lewis
- Re: [Asrg] DNSBL caches and IPv6, again John Levine
- Re: [Asrg] DNSBL caches and IPv6, again Matthias Leisi
- Re: [Asrg] DNSBL caches and IPv6, again John Levine