ThreatNet::DATN2004

ThreatNet::DATN2004 is a Proposal: The Decentralised Active Threat Network.
Download

ThreatNet::DATN2004 Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Perl Artistic License
  • Price:
  • FREE
  • Publisher Name:
  • Adam Kennedy
  • Publisher web site:
  • http://search.cpan.org/~adamk/

ThreatNet::DATN2004 Tags


ThreatNet::DATN2004 Description

ThreatNet::DATN2004 is a Proposal: The Decentralised Active Threat Network. ThreatNet::DATN2004 is a Proposal: The Decentralised Active Threat Network.This document has been created to describe a concept that may be of use in a variety of fields. It should be considered a general concept only and is subject to change.This CPAN/POD version of the document, first published in December 2004 at http://ali.as/devel/threatnetwork.html, has been released to independantly timestamp and archive the concept and proposal in case of future patent-related issues by companies and to attempt to keep the core idea available to all.On the Internet there exists an increasing number of different ways in which hosts are being misused or abused. Likewise there is also an increasing number of ways in which these known-bad hosts are being identified. Most of these occur in the process of a particular task, such as checking an email message for spam status.As these hosts are identified, their identify is transmitted across to internet to members of threat networks. The most common of these are the various email "black lists", most of which use DNS or some other method to publish lists of known-bad ips or ip ranges. Mail processing services submit requests to a DNS server storing these lists to determine if a particular host contacting them is a known spammer.This draft specification describes a system which would be used to identify a specific category of these bad ips, hosts that can be considered "Active Threats". An Active Threat is a host that is currently engaged in anti-social, damaging or criminal behaviour, such as actively sending out spam or viruses. This specification is NOT intended to deal with long-term offenders, as they are addressed by a number of current systems.If applied to long term offenders, hosts would be registered as an Active Threat when they commence their anti-social behaviour, and fall off any list during periods in which they are not conducting this behaviour.The general intent is to deal with only those hosts that are actively engaged in damaging behaviour, whether or not they are long term offenders or new offenders. And to deal with the hosts as soon as possible, ideally within a few seconds. Requirements: · Perl


ThreatNet::DATN2004 Related Software