RE: question about testing new rulesets
Is it possible to do the following when testing out a new ruleset:
(1) score that rule at 0.01 (of course this is possible... but then also...)
(2) copy the original source file that was "fed" to SA to a separate
directory if (a) the new rule being tested triggered ...AND... (b) if
that message ended up scoring "below threshold" and was therefore NOT
considered spam.
This would allow someone to audit those messages which would ONLY have
been blocked had that new ruleset been giving a higher score. Analysis
on such messages could then be done to see how many of these are FNs and
how many of these are FPs.
I'm thinking that, if SA can delete and re-write the source file with a
new header, it seems like it could also copy the message to a different
folder, under certain conditions?
Thanks!
--
Rob McEwen
http://dnsbl.invaluement.com/rob@...