[dns-operations] ok, DNS RRL (rate limits) are officially, seriously, cool
Phil Regnauld
regnauld at nsrc.org
Mon Jun 25 08:28:41 UTC 2012
On 25/06/2012, at 09.40, Klaus Darilion <klaus.mailinglists at pernau.at> wrote:
> I would expect that outgoing traffic is constant. Maybe, in this case also legitimate queries are blocked (false positive)
That's assuming all other clients are behaving properly in the first place, could be a non negligible number of malware generating this background noise. Their existence might be revealed by rate limitation.
But yes, it's worth digging.
More information about the dns-operations
mailing list