
Received: from greendrazi.com (63-207-218-133.ded.pacbell.net [63.207.218.133]) by sb7.songbird.com (8.12.11/8.12.11) with ESMTP id j72FAu6e023721 for <abuse-feedback-report@mipassoc.org>; Tue, 2 Aug 2005 08:10:56 -0700
Received: from [192.168.147.5] (69-12-137-95.dsl.static.sonic.net [69.12.137.95]) by greendrazi.com (Postfix) with ESMTP id 6B07C13E; Tue,  2 Aug 2005 08:10:06 -0700 (PDT)
Message-ID: <42EF8CCD.4040507@habeas.com>
Date: Tue, 02 Aug 2005 08:10:05 -0700
From: "Carl S. Gutekunst" <csg@habeas.com>
User-Agent: Mozilla Thunderbird 1.0 (X11/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: abuse-feedback-report@mipassoc.org
Subject: Re: [feedback-report] So...
References: <42DED3FB.3070000@yahoo-inc.com> <42EE7F12.3060504@ols.es>	<42EEBB6B.3020609@yahoo-inc.com> <42EF2965.4090800@ols.es>
In-Reply-To: <42EF2965.4090800@ols.es>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-SpamCheck: 
X-Songbird-From: csg@habeas.com
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Aug 2005 15:11:08 -0000

David Saez wrote:

> ... the format here proposed
> lacks the datetime plus gtm zone data. You may argue that it can be
> extracted from the message headers, but it may be difficult for an
> automated process to do it well.

That wasn't an argument, it was a deliberate design decision. We 
generally agreed here that nothing should be in the metadata that was 
reliably available in the message. The purpose of the metadata is too 
convey information that only the receiver knows, not just replicate 
what's already in the message. "Extracting things from the message 
headers" is fundamental to everything we do, and there's lots of 
off-the-shelf software to do it.

> In the other hand, not having a format for reporting every kind of
> incident will mean that developers will need to implement different
> formats for different incidents.

There have been at least three efforts going back over the past four 
years to standardize incident reporting. All started from the premise 
you are making now, that a generalized solution should be no more 
difficult than a specific one. Yet all of those failed to even agree of 
fundamentals, let along publish a draft.

At seven months, this effort has already published two drafts, is close 
to a third (thanks Yakov!), and has running prototypes among multiple 
providers that are working so well that we're seriously considering 
putting them into production. More importantly, interest is growing from 
major providers who previously hadn't considered sharing this sort of 
data. The availability of a standard, even in draft form, is drawing 
them in.

This is all about picking a well-defined problem and solving it.

<csg>


Received: from a.mad.olsns.net (a.mad.olsns.net [213.195.75.88]) by sb7.songbird.com (8.12.11/8.12.11) with ESMTP id j728B1jt019631 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <abuse-feedback-report@mipassoc.org>; Tue, 2 Aug 2005 01:11:03 -0700
Received: from [62.97.103.92] (helo=ols.es) by b.mx.ols.es with esmtpa (Exim 4.50) id 1Dzrod-0003nE-1p for abuse-feedback-report@mipassoc.org; Tue, 02 Aug 2005 10:08:01 +0200
Message-ID: <42EF2965.4090800@ols.es>
Date: Tue, 02 Aug 2005 10:05:57 +0200
From: David Saez <david@ols.es>
User-Agent: Mozilla Thunderbird 0.5 (Windows/20040207)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: abuse-feedback-report@mipassoc.org
Subject: Re: [feedback-report] So...
References: <42DED3FB.3070000@yahoo-inc.com> <42EE7F12.3060504@ols.es> <42EEBB6B.3020609@yahoo-inc.com>
In-Reply-To: <42EEBB6B.3020609@yahoo-inc.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
X-Authenticated: david@ols.es at b.mx.ols.es
X-OLS-Security: OK - Virus scanned by ClamAV 0.86.2/1000/Sun Jul 31 21:28:06 2005
X-Complaints-To: abuse@ols.es
X-Complaints-To: abuse@ols.es
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-SpamCheck: 
X-Songbird-From: david@ols.es
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Aug 2005 08:11:22 -0000

Hi !!

> I think you may be misinterpreting the primary use scenario for this 
> format.  It isn't intended to replace human-to-human communications 
> between abuse teams,

well, i never said i want it to replace human-to-human communications,
in fact i prefer it over xml because it's human readable.

> but rather to support automated processing of 
> complaints.  Most of the examples you gave are much more difficult to 
> automate.

false, those cases are as easy to automate as spam complaints.
Every complain has an evidence, an email message is the evidence
of a spam, other incidents have other types of evidence, like just
a log line produced by some piece of software. It's just as easy as
adding that evidence to the complain.

> Rather than trying to create a format that encompasses everything 
> poorly, we chose to focus on doing a few things extremely well.

it does no encompass everything poorly and you are not doing thing
extremely well. First, every kind of complain needs a human explantion,
an evidence, and the origin ip and datetime plus gmt zone. With this
data you could encompass everything well. And the format here proposed
lacks the datetime plus gtm zone data. You may argue that it can be
extracted from the message headers, but it may be difficult for an
automated process to do it well.

In the other hand, not having a format for reporting every kind of
incident will mean that developers will need to implement different
formats for different incidents.

-- 
Best regards ...

----------------------------------------------------------------
    David Saez Padros                http://www.ols.es
    On-Line Services 2000 S.L.       e-mail  david@ols.es
    Pintor Vayreda 1                 telf    +34 902 50 29 75
    08184 Palau-Solita i Plegamans   movil   +34 670 35 27 53
----------------------------------------------------------------





Received: from smtp104.mail.sc5.yahoo.com (smtp104.mail.sc5.yahoo.com [66.163.169.223]) by sb7.songbird.com (8.12.11/8.12.11) with SMTP id j720Hhmq027289 for <abuse-feedback-report@mipassoc.org>; Mon, 1 Aug 2005 17:17:43 -0700
Received: (qmail 59704 invoked from network); 2 Aug 2005 00:16:45 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=snake; d=yahoo-inc.com; h=Received:Message-ID:Date:From:Organization:User-Agent:X-Accept-Language:MIME-Version:To:Subject:References:In-Reply-To:Content-Type:Content-Transfer-Encoding; b=UJkkjdCZvBVnQ78vHk0Xar/0SBEoKAU080hv/EzYTlH99A60MyHt+p21T7eZNBwi  ;
Received: from unknown (HELO ?192.168.1.113?) (jdfalk@216.145.49.15 with plain) by smtp104.mail.sc5.yahoo.com with SMTP; 2 Aug 2005 00:16:45 -0000
Message-ID: <42EEBB6B.3020609@yahoo-inc.com>
Date: Mon, 01 Aug 2005 17:16:43 -0700
From: "J.D. Falk" <jdfalk@yahoo-inc.com>
Organization: Yahoo!
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.7.5) Gecko/20041206 Thunderbird/1.0 Mnenhy/0.6.0.104
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: abuse-feedback-report@mipassoc.org
Subject: Re: [feedback-report] So...
References: <42DED3FB.3070000@yahoo-inc.com> <42EE7F12.3060504@ols.es>
In-Reply-To: <42EE7F12.3060504@ols.es>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-SpamCheck: 
X-Songbird-From: jdfalk@yahoo-inc.com
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Aug 2005 00:17:47 -0000

On 8/1/05 12:59 PM, David Saez wrote:

> i also did not receive any message about it, how should i
> interpret it ? nobody is against it or nobody aproves it ?

Perhaps try the list archives?

> The format proposed in this list is
> simple and nice, but it does not accomodate other kinds of
> incidents. With little modifications it could be used for any
> kind of incident without having to reach the complexity of
> IODEF, anybody has objections to this ?

I think you may be misinterpreting the primary use scenario for this 
format.  It isn't intended to replace human-to-human communications 
between abuse teams, but rather to support automated processing of 
complaints.  Most of the examples you gave are much more difficult to 
automate.

Rather than trying to create a format that encompasses everything 
poorly, we chose to focus on doing a few things extremely well.

-- 
J.D. Falk, Anti-spam Product Manager, Yahoo! Mail
jdfalk@yahoo-inc.com


Received: from a.mad.olsns.net (a.mad.olsns.net [213.195.75.88]) by sb7.songbird.com (8.12.11/8.12.11) with ESMTP id j71K6DEu005643 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <abuse-feedback-report@mipassoc.org>; Mon, 1 Aug 2005 13:06:15 -0700
Received: from [62.97.103.33] (helo=ols.es) by b.mx.ols.es with esmtpa (Exim 4.50) id 1DzgTM-0008G1-5N for abuse-feedback-report@mipassoc.org; Mon, 01 Aug 2005 22:01:21 +0200
Message-ID: <42EE7F12.3060504@ols.es>
Date: Mon, 01 Aug 2005 21:59:14 +0200
From: David Saez <david@ols.es>
User-Agent: Mozilla Thunderbird 0.5 (Windows/20040207)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: abuse-feedback-report@mipassoc.org
Subject: Re: [feedback-report] So...
References: <42DED3FB.3070000@yahoo-inc.com>
In-Reply-To: <42DED3FB.3070000@yahoo-inc.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
X-Authenticated: david@ols.es at b.mx.ols.es
X-OLS-Security: OK - Virus scanned by ClamAV 0.86.2/1000/Sun Jul 31 21:28:06 2005
X-Complaints-To: abuse@ols.es
X-Complaints-To: abuse@ols.es
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-SpamCheck: 
X-Songbird-From: david@ols.es
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Aug 2005 20:06:33 -0000

Hi !!

> ...either the list is entirely broken except for me, or nobody cares 
> about the additional use cases that have been proposed.  Right?

i also did not receive any message about it, how should i
interpret it ? nobody is against it or nobody aproves it ?

Other proposals exists for a format for incident interchange
between CSIRTs (IODEF) but it's very heavy and based on xml.
I've been this week on a abuse's team working group here in
Spain with large isp's, universities, etc ... For some of
them, specially the ones who provide dsl access, about 80%
of reported incidents are about copyright (P2P networks) and
the rest is pishing, scams, spam, ports scans, etc ... One
on the missions of that group is to define a format for
incident reporting via email, but that format should include
all kinds of incidents. The format proposed in this list is
simple and nice, but it does not accomodate other kinds of
incidents. With little modifications it could be used for any
kind of incident without having to reach the complexity of
IODEF, anybody has objections to this ?

Resources:

Object Description and Exchange Format Working Group (IODEF WG):
http://www.terena.nl/tech/task-forces/tf-csirt/iodef/index.html

-- 
Best regrads ...

----------------------------------------------------------------
    David Saez Padros                http://www.ols.es
    On-Line Services 2000 S.L.       e-mail  david@ols.es
    Pintor Vayreda 1                 telf    +34 902 50 29 75
    08184 Palau-Solita i Plegamans   movil   +34 670 35 27 53
----------------------------------------------------------------





