advancedNS PDF
advancedNS PDF
advancedNS PDF
Security
Richard Clayton
• Secure BGP(s)
( ) experimental
p at p
present
– concerns about performance (cf MD5)
– concerns about key distribution
– when will it be stable and inter-working?
ISP
S
Complaints
abuse@
team
7th September 2009 Advanced Network Security
Log processing heuristics
Report “too many” failures to deliver
– more than 20 works pretty well
• Ignore “bounces” !
– have null “<
<> >” return path,
path these often fail
– detect rejection daemons without < > paths
• Ignore “mailing
mailing lists”
lists (fixed sender)
– most destinations work, only some fail (10%)
– more than one “mailing list” is a spam indicator!
• Ignore “forwarding” (fixed destination)
– multiple forwarding destinations is common
HELO = lkrw.hotmail.com
HELO = pshw.netscape.net
HELO = zmgp
zmgp.cs.com
cs com
Smarthost
Th Internet
The I
MX host