Slashdot Mirror


Catching Spam by Looking at Traffic, Not Content

AngryDad writes "HexView has proposed a method to deal with spam without scanning actual message bodies. The method is based solely on traffic analysis. They call it STP (Source Trust Prediction). A server, like a Real-time Spam Black list, collects SMTP session source and destination addresses from participating Mail Transfer Agents (MTAs) and applies statistics to identify spam-like traffic patterns. A credibility score is returned to the MTA, so it can throttle down or drop possibly unwanted traffic. While I find it questionable, the method might be useful when combined with traditional keyword analysis." What do you think? Is this snake oil, or is there something to this?

12 of 265 comments (clear)

  1. Re:This is painfully obvious and hopelessly naive by jimicus · · Score: 5, Funny

    As soon as you've found a way to get that message through effectively to 100% of the population, do let us know.

  2. I'll never stop by diskofish · · Score: 5, Funny

    Where else would I get my Viagra from?

    1. Re:I'll never stop by El_Muerte_TDS · · Score: 4, Funny

      You shouldn't. Impotence is nature's signal that you are not fit for reproduction. Your reproduction will only result in more people responding to spam, which is ofcourse a bad thing.

      So do the world a favor... please...

  3. request by illuminatedwax · · Score: 3, Funny

    please put obligatory Standard Spam Form joke below here please

    we've got to keep this place organized

    --
    Did you ever notice that *nix doesn't even cover Linux?
  4. Re:This is painfully obvious and hopelessly naive by Grey+Ninja · · Score: 5, Funny

    We could try mass mailing them. I've had some success with that in the past. =)

  5. Obligatory by teslar · · Score: 4, Funny

    Your post advocates a

    (x) technical ( ) legislative ( ) market-based ( ) vigilante

    approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)

    ( ) Spammers can easily use it to harvest email addresses
    (x) Mailing lists and other legitimate email uses would be affected
    ( ) No one will be able to find the guy or collect the money
    (x) It is defenseless against brute force attacks
    (x) It will stop spam for two weeks and then we'll be stuck with it
    ( ) Users of email will not put up with it
    ( ) Microsoft will not put up with it
    ( ) The police will not put up with it
    ( ) Requires too much cooperation from spammers
    ( ) Requires immediate total cooperation from everybody at once
    ( ) Many email users cannot afford to lose business or alienate potential employers
    ( ) Spammers don't care about invalid addresses in their lists
    ( ) Anyone could anonymously destroy anyone else's career or business

    Specifically, your plan fails to account for

    ( ) Laws expressly prohibiting it
    ( ) Lack of centrally controlling authority for email
    ( ) Open relays in foreign countries
    ( ) Ease of searching tiny alphanumeric address space of all email addresses
    ( ) Asshats
    ( ) Jurisdictional problems
    ( ) Unpopularity of weird new taxes
    ( ) Public reluctance to accept weird new forms of money
    ( ) Huge existing software investment in SMTP
    ( ) Susceptibility of protocols other than SMTP to attack
    ( ) Willingness of users to install OS patches received by email
    ( ) Armies of worm riddled broadband-connected Windows boxes
    (x) Eternal arms race involved in all filtering approaches
    ( ) Extreme profitability of spam
    ( ) Joe jobs and/or identity theft
    ( ) Technically illiterate politicians
    ( ) Extreme stupidity on the part of people who do business with spammers
    ( ) Dishonesty on the part of spammers themselves
    ( ) Bandwidth costs that are unaffected by client filtering
    ( ) Outlook

    and the following philosophical objections may also apply:

    ( ) Ideas similar to yours are easy to come up with, yet none have ever
    been shown practical
    ( ) Any scheme based on opt-out is unacceptable
    ( ) SMTP headers should not be the subject of legislation
    ( ) Blacklists suck
    ( ) Whitelists suck
    ( ) We should be able to talk about Viagra without being censored
    ( ) Countermeasures should not involve wire fraud or credit card fraud
    ( ) Countermeasures should not involve sabotage of public networks
    ( ) Countermeasures must work if phased in gradually
    ( ) Sending email should be free
    (x) Why should we have to trust you and your servers?
    ( ) Incompatiblity with open source or open source licenses
    (x) Feel-good measures do nothing to solve the problem
    ( ) Temporary/one-time email addresses are cumbersome
    ( ) I don't want the government reading my email
    ( ) Killing them that way is not slow and painful enough

    Furthermore, this is what I think about you:

    (x) Sorry dude, but I don't think it would work.
    ( ) This is a stupid idea, and you're a stupid person for suggesting it.
    ( ) Nice try, assh0le! I'm going to find out where you live and burn your
    house down!

  6. OPPOTUNITY. == DISCRETION REQUIRED == by Anonymous Coward · · Score: 5, Funny

    SIR,

    OUR TECHNOLOGY DEPARTMENT HAS COME UP WITH A GREAT OPPUTUNITY TO STOP ALL YOUR SPAM. THIS TECHNOLOGY IS CALLED source Trust Prediction (STP). IT WORKS BASED ON identifying patterns and trends in real time AND IN THIS WAY PREVENT SPAM. HOWEVER TO MAKE PROFIT FROM THIS NEW TECHNOLOGYY WE NEED TO DO A PATENT APPLICATION. YOUR NAME CAME FORWARD AS AN EXCELLENT INVESTOR FOR THIS. WITH THE CURRENT RISE OF SPAM THIS TECH WILL BE REQUIRED QUICKLY BY A LOT OF PEOPLE.

    I am only contacting you as a foreigner, I will use my influence to
    effect legal approvals and onward transfer into your account At the
    conclusion of this business, you will be given 50% of the total
    PROFITS, 50% will be for me and my family AFTER DEDUCTION OF THE PATENT COSTS
    . I await to hear from you.

    Yours truly,

    Mr.Barry Leoard.

    FNB OF SOUTH AFRICA
    THIS
    IS MY PRIVATE EMAIL ADDRESS, YOU CAN SEND YOUR REPLY HERE:-
    barryleonard@walla.com

    1. Re:OPPOTUNITY. == DISCRETION REQUIRED == by Archangel+Michael · · Score: 3, Funny

      Source Trust Detection (STD)

      There, fixed your spelling ...

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
  7. No! by Penguinisto · · Score: 3, Funny
    We have enough problems with idiots who leave all their backscatter-inducing defaults on @ their mail servers - coupled with the common joe-jobs, it would quickly turn the Internet into a gelatinous mass choked with bounces.

    Thx in advance,

    /P

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
  8. Re:sounds good to me by goofyspouse · · Score: 2, Funny

    Zombie Bread, a whole brain in every loaf!

  9. Re:sounds good to me by GreggBz · · Score: 4, Funny

    It's blue! It's moldy! It's the The night of the living Bread.

  10. I don't need no steenkin' introduction by DrSkwid · · Score: 2, Funny

    Thanks for you misguided rant, quite amusing.

    My ISP (and I mean mine, I'm a shareholder) doesn't give a flying fuck what I do with the bandwidth I paid for (and yes, I do pay). The fixed IP of my 2Mb ADSL suits my needs, and many of the needs of other business users we have as customers, extra QoS not required

    Get off your high horse and suck it's cock.

    --
    There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter