John August wrote:
> I've noticed spam which has a section of "extracted" text after the spam
> content. It seems to me that by taking things line by line, you'll reach
> a point at which the spam index peaks, and then trails off after. This
> is a pattern which would remain even if the "overall" spam index is low.
> 
> Does the current spam assassin implement such an approach ? Or is the 
> algorithm sufficiently subtle to null out these attempts ?

AFAIK, no part of SA takes such an approach.

However, these attempts are only going to be effective against the bayes portion
of SA.

Since the rest of SA (all the static rule, SURBLs, etc) are completely
unaffected by the adding of "pad" text, SA is overall fairly resistant to this
kind of attack.

It might be an interesting development for SA's bayes subsystem to do a
partial-text analysis and see if it improves accuracy, but right now it does a
full-text analysis.

Reply via email to