[Discussion] features (mainly dns)

Florian Weimer fw at deneb.enyo.de
Sun Dec 7 07:59:14 UTC 2008


* David Dagon:

>> How do you mean? Loke looking for a client that's making repeated dns
>> queries within the TTL? Maybe poorly coded bots?
>
> I'd say you have a winner here; this is a single class classifier,
> almost.  Your false positives are now just NAT, much of the Pacific
> rim, etc.

And all UNIX-like clients which do not perform local caching by
default. 8-(



More information about the Discussion mailing list