Threatcast High-level Architecture

Updater

WSA

Feeds

WBNP Data Aggregation

Phalanx WBNP tabfile

IP/Domain Graph

FP Pruning/Sorting Algorithm

Eliminating detected FP

Ranking entries with scores

ASA

Size limitation

2mb

4mb

8mb

Threatcast

2 - 4 hour Update interval due to diff

Data Massage

Unresolvable Domain Filtering

Threat Level Filtering

WBNP data aggregation and Machine Learning

Third Party feeds

Different update intervals

sunbelt borderpatrol

spamhaus

mdl zeus

zeus tracker

sbnp conficker