This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/anti-abuse-wg@ripe.net/
[anti-abuse-wg] passive botnet tracker
- Previous message (by thread): [anti-abuse-wg] passive botnet tracker
- Next message (by thread): [anti-abuse-wg] passive botnet tracker
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Florian Weimer
fweimer at bfk.de
Wed Mar 4 11:12:35 CET 2009
* Jan Pieter Cornet: >> Why do you expect bots to touch dark address space? >> >> Or put differently, I think any approach based on darkspace monitoring >> signficantly restricts the types of bots you can detect. > > Not if you use "dark" corners of your own PA space, eg unused /28s in > your DSL space, or hosting space. Again, why would this work? There seems to be an underlying assumption that all bots gather information through scanning (possibly neighboring) addresses, but this is simply not true. -- Florian Weimer <fweimer at bfk.de> BFK edv-consulting GmbH http://www.bfk.de/ Kriegsstraße 100 tel: +49-721-96201-1 D-76133 Karlsruhe fax: +49-721-96201-99
- Previous message (by thread): [anti-abuse-wg] passive botnet tracker
- Next message (by thread): [anti-abuse-wg] passive botnet tracker
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]