Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update DomainTools Analyzer to pull Risk and Proximity Score #214

Closed
syloktools opened this issue Mar 29, 2018 · 3 comments
Closed

Update DomainTools Analyzer to pull Risk and Proximity Score #214

syloktools opened this issue Mar 29, 2018 · 3 comments
Assignees
Labels
category:enhancement Issue is related to an existing feature to improve category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related
Milestone

Comments

@syloktools
Copy link
Contributor

Request Type

Feature

Description

Can someone update the Domain Tools Analyzer so that it pulls the new Risk Score and Proximity Score that Domain Tools has if you have an API access?

Some examples are here: https://github.com/DomainTools/domaintools_misp

@3c7 3c7 added category:enhancement Issue is related to an existing feature to improve scope:analyzer Issue is analyzer related category:feature-request Issue is related to a feature request labels Mar 29, 2018
@jeromeleonard jeromeleonard self-assigned this Jun 8, 2018
@jeromeleonard jeromeleonard added this to the 1.11.0 milestone Jun 8, 2018
jeromeleonard added a commit that referenced this issue Jun 9, 2018
jeromeleonard added a commit that referenced this issue Jun 9, 2018
jeromeleonard added a commit that referenced this issue Jun 9, 2018
jeromeleonard added a commit that referenced this issue Jun 9, 2018
jeromeleonard added a commit that referenced this issue Jun 9, 2018
@jeromeleonard
Copy link
Contributor

I was able to update the analyzer with Risk Evidence service and tested it. I also added Reputation service, but was not able to test it due to some API access limitations.

@aeetos
Copy link
Contributor

aeetos commented Jun 25, 2018

Hi, Mark here from DomainTools. I was about to dive into writing some analyzers for this and was please to see work already progressing on it.

I'll happily provide API keys to anyone wanting to work on this, just contact me directly.

We have at present two different scoring technologies, offered in two different API endpoints. The first is at /v1/reputation/ and is based on proximity to known badness. Many of our customers have access to that already as it was our first iteration of the risk score, and we should add a flavor for that to so folks with that endpoint can use it.

The other score is our Risk score, which has an overall score composed of different components, including a machine learning algorithm and the previous reputation algorithm. It's at /v1/risk/ and is our default offering for any new customers. The response format has an overall risk score, which is perfect for the summary reports, and a list of components, each with their own score. That would be great for a detail report. Finally, we also have the /v1/risk/evidence/ endpoint that some customers have access to which can give additional details.

Hopefully that helps explain the various reasons for all this. I'll check out the branch you've got underway here and test it out and report back soon.

Thanks for all the work on this - LMK if I can help with anything.

@jeromeleonard
Copy link
Contributor

will be released in 1.11.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:enhancement Issue is related to an existing feature to improve category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related
Projects
None yet
Development

No branches or pull requests

4 participants