[79362] in North American Network Operators' Group
Re: botted hosts
daemon@ATHENA.MIT.EDU (John Dupuy)
Mon Apr 4 16:33:24 2005
Date: Mon, 04 Apr 2005 15:32:58 -0500
To: Nanog <nanog@nanog.org>
From: John Dupuy <jdupuy-list@socket.net>
In-Reply-To: <Pine.LNX.4.44.0504041526560.9069-100000@localhost.localdom
ain>
Errors-To: owner-nanog@merit.edu
<html>
<body>
<font size=3D3>I think many folks agree with you. Spam, at it's heart, is
an intractable social problem, not a technical problem. I'll refrain from
my regular "tragedy of the commons" economics
discussion.<br><br>
However, most of the folks on this list must work at the technical angle.
How do we reduce spam by making it more difficult to spam?<br><br>
I'd be interested in seeing your proof when you finish it.<br><br>
John<br><br>
<br>
<blockquote type=3Dcite class=3Dcite cite>On a deeper level, I discovered
(its not at proof level, but probably at<br>
'strong conjecture' level) that results from information theory show
that<br>
spam cannot be stopped technically. I'll write it up a bit more
formally,<br>
and post a link. (And I'll see if I can carry it out to a proof)
To<br>
summarize, I show that spam is equivalent to a covert/sneaky channel
[or<br>
rather, "sneaky channel" in the network liturature and
other names in<br>
other areas of liturature--e.g. "covert channel" is usually
specific to<br>
multi-user OS analysis, but the concepts are the same]. Then I show
that<br>
since one can't prove an information system is free of=20
covert/sneaky<br>
channels, it can't be proven free of spam either. And the
conclusion is<br>
that a technical solution to spam doesn't exist. Yes, there are
things<br>
that can still be done---one can continue to play whack-a-mole, but
it<br>
never gets better than whack-a-mole. There are still technical
methods<br>
that aren't fully exploited (text analysis for intent, bayesian, etc)
but<br>
for each of these things, there are countermeasures that the abuser can
do<br>
to fool them. If you want to talk information theory and spam,
contact me<br>
off-list.<br><br>
<x-tab> </x-tab><x-tab> =
</x-tab>--Dean<br><br>
-- <br>
Av8 Internet Prepared to pay a premium for better
service?<br>
<a href=3D"http://www.av8.net=A0=A0=A0=A0=A0=A0=A0=A0/" eudora=3D"autourl">w=
ww.av8.net
</a> faster, more reliable, better service<br>
617 344 9000 </font></blockquote></body>
</html>