Abuse in New gTLDs

By Ali Fakeri-Tabrizi

Posted on September 4, 2015 in: Network, Security

Nominum Research continues to refine algorithms, working toward more generalized methods to quickly detect “anomalous” activity that might represent DDoS, bots, or various other undesirable behaviors.  To simplify somewhat, algorithms examine high speed, real-time, data streams and compare a small window of incoming queries to a very large “normal” historical sample on a continuous basis.   Unexpected variations are flagged and relevant data is captured for further analysis.

