Threatcast High-level Architect
Third Party feeds
Different update intervals
sbnp conficker
zeus tracker
mdl zeus
spamhaus
sunbelt borderpatrol
Threatcast
Data Massage
WBNP data aggregation and Machine Learning
Threat Level Filtering
Unresolvable Domain Filtering
2 - 4 hour Update interval due to diff
ASA
Size limitation
8mb
4mb
2mb
Feeds
FP Pruning/Sorting Algorithm
Ranking entries with scores
Eliminating detected FP
WBNP Data Aggregation
IP/Domain Graph
Phalanx WBNP tabfile
WSA
Updater
Threatcast High-level Architecture