PepiMK
2007-11-23, 20:16
Situation: Spybot-S&D immunizes a huge list of domains.
Experienced: Slow-downs; some of those domains might no longer carry any malware and are defunct.
Expected: after careful monitoring, using some kind of automation system, we probably could take those old inactive entries from the list. This could speed up systems.
Requirements would be that the immunization features are able to understand revert commands, which they should, but where speed would have to be tested on a larger scale than was done, since this feature was previously intended only to revert false positives.
A danger would be that sites could only be temporarily offline, so a constant monitoring over a lengthy period is required, as well as malware authors reverting back to domains we've given up blocking (if we can monitor domains, they can monitor Spybot-S&Ds block list for removed entries).