<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jason's .plan &#187; Spam</title>
	<atom:link href="http://blogs.digitar.com/jjww/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.digitar.com/jjww</link>
	<description>thoughts &#38; musings</description>
	<lastBuildDate>Thu, 18 Mar 2010 06:29:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Trying to nail jello to the wall</title>
		<link>http://blogs.digitar.com/jjww/2005/08/trying-to-nail-jello-to-the-wall/</link>
		<comments>http://blogs.digitar.com/jjww/2005/08/trying-to-nail-jello-to-the-wall/#comments</comments>
		<pubDate>Mon, 01 Aug 2005 22:40:09 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The anti-spam industry sure does like their jello. At least that&#39;s what it seems like. Just try and compare &#8220;catch rates&#8221;&#8230;I dare you. The meaning keeps moving. Trying to wrap your mind around the cock-a-mamey way some vendor from East Timor calculates their accuracy is like trying to nail jello to the wall. The damn [...]]]></description>
			<content:encoded><![CDATA[<p>The anti-spam industry sure does like their jello. At least that&#39;s what it seems like. Just try and compare &#8220;catch rates&#8221;&#8230;I dare you. The meaning keeps moving. Trying to wrap your mind around the cock-a-mamey way some vendor from East Timor calculates their accuracy is like trying to nail jello to the wall. The damn thing keeps moving. <strong>It&#39;s really not that hard folks.</strong></p>
<p>You&#39;ve basically got three questions:</p>
<p>* Of the <strong>spams</strong> that went through my engine what % of them were correctly identified?</p>
<p>* Of the <strong>innocents</strong> that went through my engine what % of them were correctly identified?</p>
<p>* Of <strong>ALL</strong> the messages that my engine processed what % where correctly classified (spam or innocent)?</p>
<p>
That&#39;s it. That&#39;s all. Not that tough. Let&#39;s be honest&#8230;that&#39;s all an average Joe really wants to know.</p>
<p>Well&#8230;maybe that&#39;s not ALL an average Joe wants to know. He also wants to know you&#39;re being straight with him. Wanna know a dirty little secret&#8230;.sshhh&#8230;be very quiet&#8230;..the term &#8220;catch-rate&#8221; only takes off accuracy points for spam misclassifications (i.e.<a href="http://en.wikipedia.org/wiki/False_negative"> false-negatives</a> only). You want <a href="http://en.wikipedia.org/wiki/False_positive">false-positives</a> in that number? &#8220;Ha! We can&#39;t tell you that!&#8221; cackles the anti-spam vendor.</p>
<p>We call the three questions above Spam Classification Accuracy (SCA), Innocent Classification Accuracy (ICA) and Overall Classification Accuracy (OCA). Next time you&#39;re talking to an anti-spam vendor ask for them.<sup><a href="#2005080101">**</a></sup> Push hard. At least you&#39;ll be able to make a clean choice.</p>
<p><sup><a name="2005080101">**</a></sup>Just a heads up. Your friendly anti-spam vendor of choice will almost certainly stare at you like a <a href="http://en.wikipedia.org/wiki/Wildebeest">wildebeest</a> caught in the headlights if you ask for SCA, ICA and OCA by name. You&#39;ll probably have to tell them what you want in English&#8230;and speak reaaaalllyyy sloooow. They&#39;re not used to all the honesty. <img src='http://blogs.digitar.com/jjww/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p><a href="http://www.amazon.com/exec/obidos/tg/detail/-/6307493615/qid=1122959468/sr=8-3/ref=sr_8_xs_ap_i1_xgl14/102-2395933-3802514?v=glance&amp;s=books&amp;n=507846">Deep Dish:<strong>Way2tite &#8211; Situation 2wo</strong>:Global Underground 025: Toronto [UK] Disc 2[<em>23:59</em>]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.digitar.com/jjww/2005/08/trying-to-nail-jello-to-the-wall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Excellent mid-year review</title>
		<link>http://blogs.digitar.com/jjww/2005/07/excellent-mid-year-review/</link>
		<comments>http://blogs.digitar.com/jjww/2005/07/excellent-mid-year-review/#comments</comments>
		<pubDate>Fri, 29 Jul 2005 12:20:07 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Kaspersky has released today an excellent write-up summing up mal-ware trends so far in &#39;05 and what the means for the second half of the year. Overall it really reinforces what we&#39;re seeing with our service line. More and more unique hits on the HTTP scanners and IPS engines&#8230;
It&#39;s really not that surprising. Traditionally e-mail [...]]]></description>
			<content:encoded><![CDATA[<p>Kaspersky has released today an excellent <a href="http://www.viruslist.com/en/analysis?pubid=167798878">write-up</a> summing up mal-ware trends so far in &#39;05 and what the means for the second half of the year. Overall it really reinforces what we&#39;re seeing with our service line. More and more unique hits on the HTTP scanners and IPS engines&#8230;</p>
<p>It&#39;s really not that surprising. Traditionally e-mail has been the focus of tighter security, and its been easier to secure from a performance point of view. If you can deliver your mal-ware successfully using the web or IM, you&#39;re going to knock over a lot more systems. It&#39;s normally just too hard to protect those streams because users complain about performance hits. Its amazing how fast an HTTP AV scanner gets shutdown after the 34th user complaint along the lines of &#8220;What did y&#39;all do?! It takes forever to download this really cute program from Gmail that my new Afghani friend sent me!&#8221;.</p>
<p>One of the interesting comments in the article confirms malware writers are looking to counter the &#8220;rapid-response&#8221; update architecture the AV industy has put together. It means signature update windows are going to continue to get smaller. An effective pre-scan of vulnerable systems means that a mal-ware writer can hit critical mass of infection that much more quickly. Whereas you might have had 12-24 hours to get an AV signature updated before, this could mean you&#39;ve got 4 hours or less.</p>
<p>One thing Kaspersky doesn&#39;t talk about that we discuss a lot is the evolution of malware along biological lines. Ebola for example, is a very bad virus in terms of effectiveness. It kills the host really quickly, and limits the lifetime of the virus. Which is a primary reason Ebola never really became a global problem. You could say the same thing about Blaster or MyDoom. Everybody noticed them &#39;cause they knocked your system over hard. You couldn&#39;t work, and maybe even lost data as a result of the crashing. While they did infect A LOT of machines, the fact is they don&#39;t infect many machines anymore. They made a big splash and everybody raced to close the holes. </p>
<p>We expect to see new malware in the future that is very stealthy as a result of being tied to wanting to make money. A worm that doesn&#39;t kill your bandwidth or your system would be a silent parasite that you probably wouldn&#39;t notice. It could live a long time stealing data or whatever it was supposed to do. Or it could simply &#8220;soften&#8221; up the infected systems by disabling AV scanners. When money&#39;s the motivator its not as important to cause damage to computing infrastructure&#8230;unless of course that&#39;s the service you&#39;re selling.</p>
<p>
<a href="http://www.amazon.com/exec/obidos/tg/detail/-/B00005OAIE/qid=1122959554/sr=8-2/ref=pd_bbs_2/102-2395933-3802514?v=glance&amp;s=music&amp;n=507846">John Mayer:<strong>Neon</strong>:Room for Squares[<em>4:22</em>]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.digitar.com/jjww/2005/07/excellent-mid-year-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
