WHO CONTROLS THE COMPUTER: CUSTOMER OR FRAUDSTER?ThreatMetrix uses a combination of real-time device analytics and the ThreatIndex mass forensic processing platform to detect when a device is under the control of a fraudster. Since inception ThreatMetrix has tracked over 180 million hosts, and tracks 7 – 12 million compromised devices at any given time. ThreatIndex is updated every 15 minutes. In order to reduce false positives, ThreatMetrix uses patent-pending correlation and aging algorithms that retire nodes from the live database after a certain amount of inactivity.Real-time device analytics looks for anomalous patterns that indiciate the use of botnets. This includes detection of unusual packet characteristics suggesting the installation of root-kits, and detection of the use of botnet proxies via connection characteristics and inconsistencies. ThreatIndex mass forensic processing platform aggregates, correlates and scores botnet reputation data across these multiple submission sources and sensors: enterprise firewall logs, honey pots, darknet sensors, spam feeds, submissions, command and control host interception, and forums. Learn More
|