Re: [gnso-ff-pdp-may08] Fwd: NCUC FF Statement
- To: dave.piscitello@xxxxxxxxx
- Subject: Re: [gnso-ff-pdp-may08] Fwd: NCUC FF Statement
- From: Joe St Sauver <joe@xxxxxxxxxxxxxxxxxx>
- Date: Mon, 18 Aug 2008 23:32:41 -0700
#At one point we were on a very constructive path towards enumerating the
#characteristics of fast flux networks and thus defining the varieties of
#such networks. I really wish we would go back to that enumeration and
#complete it very analytically and dispassionately.
I continue to be quite pleased with the Mannheim definition for
fastflux (see "Measuring and Detecting Fast-Flux Service Networks,"
16_measuring_and_detecting.pdf , URL wrapped due to length), and I've yet
to see an example where it provides an incorrect "false positive"
classification of a non-fastflux domain as fastflux.
For those who'd like to try a quick test, hotnoun.com (yet another
Canadian Pharmacy pillz domain) currently scores 341.58 at
http://www.uoregon.edu/~joe/fastflux/simple.cgi , well above
the 142.38 cutoff threshold even on just a single pass...
Found 20 IPs:
184.108.40.206 --> AS42610
220.127.116.11 --> AS9318
18.104.22.168 --> AS18231
22.214.171.124 --> AS12695
126.96.36.199 --> AS29562
188.8.131.52 --> AS9908
184.108.40.206 --> AS9304
220.127.116.11 --> AS12695
18.104.22.168 --> AS9318
22.214.171.124 --> AS33491
126.96.36.199 --> AS4766
188.8.131.52 --> AS9824
184.108.40.206 --> AS31514
220.127.116.11 --> AS30764
18.104.22.168 --> AS8813
22.214.171.124 --> AS33491
126.96.36.199 --> AS3462
188.8.131.52 --> AS33287
184.108.40.206 --> AS10066
220.127.116.11 --> AS12714
17 unique ASNs
Mannheim score = 341.58
Could we agree to use the Mannheim definition unless/until someone
else proposes something else that is empirically based and which
seems to do a better job of identifying these domains? The Mannheim
test is simple, fast, objective and seems to provide good
Disclaimer: all opinions strictly my own.