 Krispy Premium,VIP join:2001-12-11 the stix
| Re: My way said by mrchris: 1) Send an email to customer notifying they are infected/being used as spam relay, and giving information on how to remove the worm/virus/relay.
2) A letter to the customer stating the above and telling they failed to clean their machine of relay/worm/etc.
3) Final warning via written letter and email telling them it is their last warning to purge their system of the virus/etc before they are disconnected.
4) Termination of the customer(s) and a written letter telling them they will be reactivated once their machine is clean and secured. Contact info for customer to notify the ISP they are clean and secure so they can have access again.
While a wonderful idea the length of time this would take would negate the ability to stop the spread of the worm, the spewing of spam, etc. Plus...do you (the supposed clean and secure customer) really want to pay the extra costs associated with this because others have not secured their machine?
I try my best to warn subscribers (via email) before having to temporarily suspend but sometimes it is necessary to immediately suspend to not only protect the net but to also protect the subscriber.
These days I'm more of the opinion that an additional measure in the way of a quarantine pen needs to be implemented for all subscribers. Basically a new (or recently suspended) subscriber would not be able to get on the network until a MSR (minimum security requirement), ie: all windows critical patches applied or whatever, was met. Sure you'll still have the threat-of-the-day to contend with but at least this way the importance of security is clear at the onset. |