Custom Search

Thursday, February 4, 2010

How Many Bots Can a Greylisting System Detect?

According to a paper presented at TANET 2005(Taiwan Academic Network Conference 2005), titled "Spam Filtering with Open Source Software, and Some Hard Facts from NTU's Email System" (title translated by me, not necessarily correct), their daily mail volume was 800K, of which 58 per cent were blocked by greylisting.

I myself detected 3651 suspected bots while blocking 211178 spams yesterday, so if the folks at NTU (National Taiwan University) had a similiar bots/spam ratio, they would be able to detect (800K * 58% * 3651 / 211178) = 8021 bots daily in 2005. Though I believe greylisting should do much better than my current detection setup.

Now imagine what will happen if some large greylisting users, like Texas A&M University, SpamCop, and Computer Science in Aarhus (DAIMI), all contribute their logs: tens of thousands of bots will be uncovered every day.

For those of you interested in the paper mentioned above, remember that it is written in Chinese. If you can not read Chinese yourself, don't forget to find someone who can to help you:).

No comments:

Post a Comment