- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-27-2015 09:14 AM
Today I switched on the "strict" Spyware anti-spyware policy on my outbound Domain Controller DNS policy - I'm seeing a lot (I mean a lot) of requests blocked for things like advertising networks.
Here are 3 DNS queries that were blocked, and they're indicative as I've picked them at random:
d.audienceiq.com
d.p-td.com
p.adsymptotic.com
Those flag as spyware domains.
So how come when I do a URL filtering query (using PAN-DB) on those domains that they show as Business & Economy, Financial, and Computer and Internet Info?
They don't show as adverts or malware or anything like that.
Surely if someone has put them into the vulnerability database they should be in the URL database under a "bad" category shouldn't they?
Does anyone have any suggestions please?
01-27-2015 09:18 AM
Hello Networkadmin,
In the event that a URL has been mis-categorized, a change request can be submitted in one of two ways: Please follow the KB doc mentioned below.
How to Submit a Mis-Categorized URL for PAN-DB
Hope this helps.
Thanks
01-27-2015 09:25 AM
Hulk, thanks and I get that I can do that, but I think the point for Palo Alto here is that I don't know if it's a good URL or a bad URL and Palo Alto are contradicting themselves with their behaviour IMO.
How am I supposed to know what those are? :smileylaugh:
Palo Alto must know it's bad else why is it in the vulnerability database as suspicious/spyware - someone at Palo Alto must have updated the database?
So if it's known bad why would it not be listed in a suitable category for URL filtering automatically?
You see what I'm saying hopefully?
01-27-2015 09:38 AM
Hello Networkadmin,
I do understand your query
The PAN-DB classification engine is based on machine learning, so we can and are constantly tweaking the individual category models to improve. In regards to URLs that are categorized as spyware, this is usually due to the fact that WildFire has detected malicious activity to/from this domain. Hence, we keep updating our database based on the wildfire result too.
A related discussion for your reference: Suspicious DNS Query ad nauseam
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!