mflu / collective-intelligence-framework

Automatically exported from code.google.com/p/collective-intelligence-framework
0 stars 0 forks source link

smtp monitor #178

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
 * acts like SMTP gateway
 * parses out malware, and other intel (urls, language, etc)

strip out domains, test for wildcard domains, if it resolves to same address 
(or set of addresses), and the ratios of known bad addresses to asn (or 
allocation) is high, possible botnet

Original issue reported on code.google.com by saxjazm...@gmail.com on 16 Jul 2012 at 2:18

GoogleCodeExporter commented 9 years ago

Original comment by saxjazm...@gmail.com on 24 Jul 2012 at 4:26

GoogleCodeExporter commented 9 years ago

Original comment by saxjazm...@gmail.com on 17 Oct 2012 at 4:14

GoogleCodeExporter commented 9 years ago

Original comment by saxjazm...@gmail.com on 5 Apr 2013 at 2:18

GoogleCodeExporter commented 9 years ago

Original comment by saxjazm...@gmail.com on 5 Apr 2013 at 2:19