Abstract: Identifying Compromised Hosts by Analyzing Real-Time Blacklists

Rick Wesson, Alice's Registry

We inverted DNSRBLs and aggregated them in a database with a real-time BGP feed to compile a "hit list" of potential issues. The reports aided network managers in discovering abuse, compromised systems, and stale DNSRBL listings. The experience continues to be interesting and beneficial.

PDF presentation
RealMedia stream