A3sal0n / FalconGate

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard
https://falconguard.cz
GNU General Public License v3.0
252 stars 59 forks source link

Reduce false positives in DGA detection rule #30

Closed A3sal0n closed 7 years ago

A3sal0n commented 7 years ago

Added whitelisting for well-known domains in the DGA count routine. This should still identify all the DGAs on SLDs plus the vast majority of the ones at the level of CNAME.

See commit 92bdcaf for details.