|
From: Heiko Z. <smi...@us...> - 2008-03-27 14:27:10
|
Update of /cvsroot/devil-linux/build/scripts/configuration/help In directory sc8-pr-cvs12.sourceforge.net:/tmp/cvs-serv25468/scripts/configuration/help Added Files: dcc.help Log Message: - updated razor-agents-2.84.tar.bz2 - updated kernel to 2.6.24.4 - updated pax-linux-2.6.24.4-test36.patch.bz2 - updated gradm-2.1.11-200803102037.tar.gz - updated grsecurity-2.1.11-2.6.24.4-200803251800.patch.bz2 - updated Linux-PAM to 0.99.10.0 - su is now wokring again - updated open-vm-tools to 2008.03.19-82724 - updated shadow 4.1.0 - added libdnet 1.11 - updated pam configurations files from BLFS book - corrected permissions on su and some code cleanup --- NEW FILE: dcc.help --- CONFIG_DCC The DCC or Distributed Checksum Clearinghouse is an anti-spam content filter that runs on a variety of operating systems. As of the middle of 2007, it involves millions of users, more than one hundred thousand client computer systems, and more than 250 servers collecting and counting checksums related to more than 300 million mail messages on week days. The counts can be used by SMTP servers and mail user agents to detect and reject or filter spam or unsolicited bulk mail. DCC servers exchange or "flood" common checksums. The checksums include values that are constant across common variations in bulk messages, including "personalizations." The idea of the DCC is that if mail recipients could compare the mail they receive, they could recognize unsolicited bulk mail. A DCC server totals reports of checksums of messages from clients and answers queries about the total counts for checksums of mail messages. A DCC client reports the checksums for a mail message to a server and is told the total number of recipients of mail with each checksum. If one of the totals is higher than a threshold set by the client and according to local whitelists the message is unsolicited, the DCC client can log, discard, or reject the message. Because simplistic checksums of spam would not be effective, the main DCC checksums are fuzzy and ignore aspects of messages. The fuzzy checksums are changed as spam evolves. Since the DCC started being used in late 2000, the fuzzy checksums have been modified several times. Unless used with isolated DCC servers and so losing much of its power, the DCC causes some additional network traffic. However, the client-server interaction for a mail message consists of exchanging a single pair of UDP/IP datagrams of about 100 bytes. That is often less than the several pairs of UDP/IP datagrams required for a single DNS query. SMTP servers make DNS queries to check the envelope Mail_From value and often several more. As with the Domain Name System, DCC servers should be placed near active clients to reduce the DCC network costs. DCC servers exchange or flood reports of checksums, but only the checksums of bulk mail. Since most mail is not bulk and only representative checksums of bulk mail need to be exchanged, flooding checksums among DCC servers involves a manageable amount of data. |