<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Spyware Vulnerabilities - Why aren't the FQDNs in Malware Category? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42927#M31508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Networkadmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do understand your query &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;The PAN-DB classification engine is based on machine learning, so we can and are constantly tweaking the individual category models to improve.&amp;nbsp; In regards to URLs that are categorized as spyware, this is usually due to the fact that WildFire has detected malicious activity to/from this domain. Hence, we keep updating our database based on the wildfire result too. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A related discussion for your reference: &lt;A href="https://live.paloaltonetworks.com/thread/12348"&gt;Suspicious DNS Query ad nauseam&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Jan 2015 17:38:28 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2015-01-27T17:38:28Z</dc:date>
    <item>
      <title>DNS Spyware Vulnerabilities - Why aren't the FQDNs in Malware Category?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42924#M31505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Today I switched on the "strict" Spyware anti-spyware policy on my outbound Domain Controller DNS policy - I'm seeing a lot (I mean a lot) of requests blocked for things like advertising networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are 3 DNS queries that were blocked, and they're indicative as I've picked them at random:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;d.audienceiq.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;d.p-td.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;p.adsymptotic.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;Those flag as spyware domains.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;So how come when I do a URL filtering query (using PAN-DB) on those domains that they show as Business &amp;amp; Economy, Financial, and Computer and Internet Info?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;They don't show as adverts or malware or anything like that.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;Surely if someone has put them into the vulnerability database they should be in the URL database under a "bad" category shouldn't they?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p4"&gt;&lt;SPAN class="s1"&gt;Does anyone have any suggestions please? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 17:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42924#M31505</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2015-01-27T17:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Spyware Vulnerabilities - Why aren't the FQDNs in Malware Category?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42925#M31506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Networkadmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 13px;"&gt;In the event that a URL has been mis-categorized, a change request can be submitted in one of two ways: Please follow the KB doc mentioned below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3625"&gt;How to Submit a Mis-Categorized URL for PAN-DB&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 17:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42925#M31506</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-27T17:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Spyware Vulnerabilities - Why aren't the FQDNs in Malware Category?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42926#M31507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hulk, thanks and I get that I can do that, but I think the point for Palo Alto here is that &lt;EM&gt;&lt;STRONG&gt;I don't know&lt;/STRONG&gt;&lt;/EM&gt; if it's a good URL or a bad URL and Palo Alto are contradicting themselves with their behaviour IMO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;d.audienceiq.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;d.p-td.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="s1" style="font-weight: inherit; font-style: inherit; font-family: inherit;"&gt;p.adsymptotic.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How am I supposed to know what those are? :smileylaugh:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Palo Alto must &lt;EM&gt;know&lt;/EM&gt; it's bad else why is it in the vulnerability database as suspicious/spyware - someone at Palo Alto must have updated the database?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if it's known bad why would it &lt;EM&gt;not&lt;/EM&gt; be listed in a suitable category for URL filtering automatically?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You see what I'm saying hopefully? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 17:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42926#M31507</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2015-01-27T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Spyware Vulnerabilities - Why aren't the FQDNs in Malware Category?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42927#M31508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Networkadmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do understand your query &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;The PAN-DB classification engine is based on machine learning, so we can and are constantly tweaking the individual category models to improve.&amp;nbsp; In regards to URLs that are categorized as spyware, this is usually due to the fact that WildFire has detected malicious activity to/from this domain. Hence, we keep updating our database based on the wildfire result too. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A related discussion for your reference: &lt;A href="https://live.paloaltonetworks.com/thread/12348"&gt;Suspicious DNS Query ad nauseam&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2015 17:38:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-spyware-vulnerabilities-why-aren-t-the-fqdns-in-malware/m-p/42927#M31508</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-27T17:38:28Z</dc:date>
    </item>
  </channel>
</rss>

