Catégories : Tous - update - architecture

par Yifeng Liu Il y a 11 années

311

Threatcast High-level Architect

A system utilizes various third-party feeds to monitor and track cyber threats, including sources like Zeus Tracker and Spamhaus. Different update intervals are employed to ensure timely data refresh.

Threatcast High-level Architect

Third Party feeds

Different update intervals

sbnp conficker
zeus tracker
mdl zeus
spamhaus
sunbelt borderpatrol

Threatcast

Data Massage

WBNP data aggregation and Machine Learning
Threat Level Filtering
Unresolvable Domain Filtering

2 - 4 hour Update interval due to diff

ASA

Size limitation

8mb
4mb
2mb

Feeds

FP Pruning/Sorting Algorithm

Ranking entries with scores
Eliminating detected FP

WBNP Data Aggregation

IP/Domain Graph
Phalanx WBNP tabfile

WSA

Updater

Threatcast High-level Architecture