70 likes | 171 Views
Server Index Query Protocol for Email Reputation & Identity Presented by April Lorenzen of Server Authority Inc. SIQuery & Response UDP Packets. UDP w/HTTP fallback Exponential backoff retries Handles IPv6 & IPv4 addresses Query ID, version, and query type housekeeping bits
E N D
Server Index Query Protocolfor Email Reputation & IdentityPresented by April Lorenzen of Server Authority Inc
SIQuery & ResponseUDP Packets • UDP w/HTTP fallback • Exponential backoff retries • Handles IPv6 & IPv4 addresses • Query ID, version, and query type housekeeping bits • Flexible for wide variety of reputation data transmission
SIQueries in Production Use • SIQ clients & servers have exchanged approx. 9 million queries and responses in production use since July 2003 • Multiple SIQ clients in France have successfully received responses from SIQ server in USA (approx. 2 million queries thus far) • Sendmail milters for the SIQ protocol include a GPL'd Python version and a non-GPL C version • SIQ plug-in for Microsoft Exchange is in active development
Fowarding is an Issue in Reputation Systems A reputation system that scores an IP address and a domain together should be skipped if the message is coming from a forwarding service or forwarded account Simple public domain mechanisms such as VARA (Verified and Recipient Authorized) are needed to determine when the reputation server query should be skipped
VARA - Simple Public Domain Solution to the Forwarding Problem
Who is developing SIQ protocol reputation services • OutboundIndex.org – service available now • Return Path – evaluating SIQ for a new reputation service • David Hohn of Uptime.at and Philipp Baer of Npw.net announced the intention to write an open source SIQ server and operate a free reputation service. • Petru Paler has expressed interest in creating an SIQ protocol interface for GOSSiP
wiki.OutboundIndex.net/ProtocolDiscussion or type SIQ protocol into most any search engine Internet-Draft http://www.ietf.org/internet-drafts/draft-irtf-asrg-iar-howe-siq-00.txt FOR MORE INFORMATION