100 likes | 202 Views
A Retrospective on Future Anti-Spam Standards. Internet Society of China Beijing – September, 2004 Dave Crocker Brandenburg InternetWorking <http://brandenburg.com/current.html>. Retrospective on the Future. Spam is complex, confusing and emotional Imagine that time has passed
E N D
A Retrospective on Future Anti-Spam Standards Internet Society of China Beijing – September, 2004 Dave Crocker Brandenburg InternetWorking <http://brandenburg.com/current.html>
Retrospective on the Future • Spam is complex, confusing and emotional • Imagine that time has passed • What changes will be important? • Email • Will it still be easy to reach everyone? • Will it be cumbersome, with fragmented communities? • Spam • Legitimate business will behave acceptably (mostly) • Rogue (criminal) spammers will be worse than today D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
Security Functions D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
Accountability (Author & Operator) Authentication Authorization Reputation Filtering Format of rules Reporting & monitoring Immediate problems Aggregate statistics Enforcement (Contracts and laws are standards) Terminology Acceptable behavior What Will Be Standard? D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
Email Path(s) Today! MSA MTA MTA MTA PeerMTA MUA MTA MTA MTA PeerMTA MTA MTA MTA Mail Agents MUA = User MSA = Submission MTA = Transfer MDA = Delivery MTA MDA MDA MUA MUA D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
SPF and Sender-ID:Author Path Registration Assigns Sender & MailFrom oMUA MSA MTA1 Did MSA authorize MTA1to send this message? MTA2 Did MSA authorize MTA2 to send this message? PeerMTA • Authority and Accreditation of MSA and MSA domain administrators • MSA must pre-register and trust each MTA in path MTA3 Did MSA authorize MTA3to send this message? PeerMTA MTA4 MDA rMUA D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
Validate content DomainKeys Public key signature of the message Validate operator CSV Operator validates MTA [Validate MailFrom] [BATV] Reputation CSA & DNA (CSV) Reporting No candidates, yet Enforcement We are still learning My Personal Favorites D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
Client SMTP Validation: Assess Peer MTA MUA MSA MTA • Does a domain's operator authorize this MTA to be sending email? • Do independent accreditation services consider that domain's policies and practices sufficient for controlling email abuse? MTA MTA Peer MTA MTA MDA MUA D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
CSV Functions D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004
How to Choose the Future • Look at each choice • Who must adopt it? When? • How much effort is need to administer it? • How much does it change email? Xie Xie D. Crocker, Brandenburg InternetWorking ISOC China – Beijing,Saeptember 2004