03.02.2014 Views

ePrism User Guide - EdgeWave

ePrism User Guide - EdgeWave

ePrism User Guide - EdgeWave

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

STA (Statistical Token Analysis)<br />

Dictionary Spam Count<br />

Recent changes to the way that spammers compose their messages have reduced the effectiveness<br />

of the basic Bayesian filter. By introducing large numbers of normal words into their spam<br />

messages, they can hide their content because the normal words outweigh the spam words and<br />

result in a low spam count. More aggressive settings may result in more false positives.<br />

<strong>ePrism</strong> counters this in two ways:<br />

1. All words in the <strong>ePrism</strong> dictionary are now assigned a base level of how likely they are to be<br />

spam. In a normal message, this increased level will not result in a false positive, since the<br />

overall count is low. In a spam message, the result is different; the normal words will not<br />

counteract the spam content, and the message is correctly identified as spam.<br />

2. Training on local mail now works to reduce this base level closer to zero. This further reduces<br />

the likelihood of a false positive.<br />

The Dictionary Count is set to one "1" by default. This should be sufficient for most situations. It is<br />

recommended that you only change the default value if the following conditions occur:<br />

• If there are too many false positives and this is not alleviated by training, then the Dictionary<br />

Count should be set to zero "0", disabling this feature.<br />

• If too much spam is passing, then the Dictionary Count can be increased. Try increasing the value<br />

to ten "10". If this results in too many false positives, reduce it to five "5".<br />

Note: This setting should only be considered for modification if other measures (training,<br />

threshold changes, uploading spam and/or legitimate mail) have been tried and have not<br />

provided the desired result.<br />

STA Mail Transport Log Entries<br />

STA log entries which indicate the metric for each message can be viewed in the Transport logs.<br />

Select Status/Reporting -> System Logs, and then select Mail Transport to view the<br />

Transport logs.<br />

For example:<br />

Apr 4 17:58:50 mail postfix/qmgr[64521]: BAFB2D2DDD: from=,<br />

size=3401, nrcpt=1 (queue active)<br />

Apr 4 17:58:50 mail postfix/smtpd[76468]: disconnect from<br />

mx2.freebsd.org[216.136.204.119] Apr 4 17:58:50 mail postfix/qmgr[64521]:<br />

BAFB2D2DDD: STA: spam_metric=12<br />

131

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!