Sign In
Terry Zink's Cyber Security Blog
Discussing Internet security in (mostly) plain English
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Authentication
Backscatter
Botnets
Economics
Education
Entertainment
Facebook
Foreign language
Hacking
Legal
Malware
Miscellaneous
Net Neutrality
Outbound
Pages
Privacy
Reputation
Security
Social Networking
Spam
Stories
Monthly Archives
Archives
February 2012
(7)
January 2012
(21)
December 2011
(6)
November 2011
(12)
October 2011
(13)
September 2011
(12)
August 2011
(15)
July 2011
(14)
June 2011
(11)
May 2011
(11)
April 2011
(11)
March 2011
(11)
February 2011
(9)
January 2011
(1)
December 2010
(19)
November 2010
(16)
October 2010
(18)
September 2010
(16)
August 2010
(16)
July 2010
(16)
June 2010
(16)
May 2010
(16)
April 2010
(21)
March 2010
(25)
February 2010
(17)
January 2010
(13)
December 2009
(13)
November 2009
(17)
October 2009
(18)
September 2009
(13)
August 2009
(12)
July 2009
(15)
June 2009
(12)
May 2009
(13)
April 2009
(10)
March 2009
(9)
February 2009
(9)
January 2009
(16)
December 2008
(15)
November 2008
(16)
October 2008
(13)
September 2008
(19)
August 2008
(16)
July 2008
(16)
June 2008
(15)
May 2008
(14)
April 2008
(15)
March 2008
(17)
February 2008
(15)
January 2008
(14)
December 2007
(16)
November 2007
(12)
October 2007
(16)
September 2007
(16)
August 2007
(8)
July 2007
(15)
June 2007
(16)
May 2007
(15)
April 2007
(11)
March 2007
(10)
February 2007
(9)
January 2007
(20)
December 2006
(14)
November 2006
(8)
October 2006
(14)
September 2006
(13)
August 2006
(22)
July 2006
(12)
June, 2008
MSDN Blogs
>
Terry Zink's Cyber Security Blog
>
June, 2008
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Terry Zink's Cyber Security Blog
The problem of backscatter, part 3 - Legitimate bounces
Posted
over 4 years ago
by
tzink
6
Comments
When a mail server accepts a message and later decides that it can't deliver the message, it is required to send back a bounce email to the sender of the original message. There are a few kinds of bounce notifications that a mail server can send: Recipient...
Terry Zink's Cyber Security Blog
The problem of backscatter, part 2 - The legitimate case
Posted
over 4 years ago
by
tzink
2
Comments
Before getting into the problem of backscatter, let's look at how the system is supposed to work before spammers ruined it for everyone. Let's say that you want to mail a letter to your friend. You write the letter, put it in an envelope, and write...
Terry Zink's Cyber Security Blog
The problem of backscatter, part 1
Posted
over 4 years ago
by
tzink
3
Comments
As the creator, editor and sole content contributor to this blog, I like to write about topics that are relevant to myself at the present moment. For example, if we are dealing with a breakout of image spam, I will write a few posts about why image...
Terry Zink's Cyber Security Blog
Best looking phish I've seen in a long time
Posted
over 4 years ago
by
tzink
11
Comments
A month ago one of our spam analysts came across a Bank of America phishing spam. The thing about this one is that it is one of the best I've seen in a long time: This is very legitimate-looking. The logo is legitimate, it has correct grammar...
Terry Zink's Cyber Security Blog
Define before use should be an enforced rule in production code
Posted
over 4 years ago
by
tzink
4
Comments
This post is a bit of a rant... but just a bit. I've been at Frontbridge/Exchange Hosted Services for a while. We were a startup in 2000 (long before my time) and like any startups, the way to get going quickly is to use LAMP technology - Linux...
Terry Zink's Cyber Security Blog
My paper on spam metrics, part 3
Posted
over 4 years ago
by
tzink
1
Comments
Continuing on in my series of rebuttals to the reviewers of my paper, I'd like to respond to the third and final review. I agree with the author that a set of common metrics is paramount for being able to measure and compare current approaches, and use...
Terry Zink's Cyber Security Blog
My paper on spam metrics, part 2
Posted
over 4 years ago
by
tzink
1
Comments
Continuing on in my rebuttals to the reviewers who refused my paper (which I believe is my right... if they can review it and refuse then I can disagree with their reasons for refusal), I'd like to move on to the second reviewer. The definitions given...
Terry Zink's Cyber Security Blog
My paper on spam metrics, part 1
Posted
over 4 years ago
by
tzink
3
Comments
I just finished a series on spam metrics and I submitted to the CEAS in order to get it accepted such that I could speak at the conference this year. I put it together in two days. Well, as it turns out, it was rejected. The reviews on it were anonymous...
Terry Zink's Cyber Security Blog
Top 50 Tech Visionaries
Posted
over 4 years ago
by
tzink
1
Comments
I came across an article in PC World about the top 50 Tech Visionaries. I was only going to read a couple of them but ended up reading the entire thing. I thought I'd repost 5 of my favorites and maybe add a couple of comments. Steve Jobs...
Terry Zink's Cyber Security Blog
A Common Set of Metrics, part 5
Posted
over 4 years ago
by
tzink
2
Comments
6. Grey Mail For all of our discussions around spam and non-spam, there is still the issue of grey mail. What is grey mail? Do we include grey mail in our spam corpus? Should we include it in the non-spam corpus or omit it altogether? To begin with, let’s...
Terry Zink's Cyber Security Blog
A Common Set of Metrics, part 4
Posted
over 4 years ago
by
tzink
1
Comments
4. Combining FPs and FNs Suppose we were evaluating two filters, Filter A and Filter B. Filter A has a catch rate of 91% but an FP rate of 5%. Filter B has a catch rate of 75% but an FP rate of 2%. Which is better? How can we combine the two metrics?...
Terry Zink's Cyber Security Blog
It's like an episode of 24 around here
Posted
over 4 years ago
by
tzink
1
Comments
From time to time, we have major spam emergencies. Running a service, stuff invariably breaks. We try our best to monitor stuff, but something always comes up that we weren't aware of. Queues build up, perf monitors don't always get...
Terry Zink's Cyber Security Blog
A Common Set of Antispam Metrics, part 3
Posted
over 4 years ago
by
tzink
2
Comments
3. Measurements The first way to do this is by way of Catch Rate. Catch rate is defined by the following: Catch rate = = Spam correctly identified / (Spam correctly identified+missed spam) = TP / (TP+FN) This Catch rate gives us the effectiveness of a...
Terry Zink's Cyber Security Blog
A Common Set of Antispam Metrics, part 2
Posted
over 4 years ago
by
tzink
4
Comments
2. Definitions The email industry needs to converge on a set of standards around metrics. Specifically, while we all think we know what we mean, what we don’t know is what others think they mean. So, let’s define them: Legitimate mail (ham...
Terry Zink's Cyber Security Blog
A Common Set of Antispam Metrics, Part 1
Posted
over 4 years ago
by
tzink
0
Comments
A few weeks ago I submitted a paper to the CEAS (Conference on Email and Antispam). My paper was rejected but I thought I would reprint it here. I ended up writing this paper in two days. I either had to write a 10-page paper or a 3-page one...
Page 1 of 1 (15 items)