Retext block reason in domain heuristics

This commit is contained in:
Patrick Pacher 2020-08-11 15:44:46 +02:00
parent 3b896ee892
commit c229031521
No known key found for this signature in database
GPG key ID: E8CD2DA160925A6D

View file

@ -315,7 +315,7 @@ func checkDomainHeuristics(ctx context.Context, conn *network.Connection, _ pack
domainToCheck,
score,
)
conn.Block("Possible data tunnel")
conn.Block("possible DGA domain commonly used by malware")
return true
}
log.Tracer(ctx).Infof("LMS score of eTLD+1 %s is %.2f", etld1, score)
@ -335,7 +335,7 @@ func checkDomainHeuristics(ctx context.Context, conn *network.Connection, _ pack
domainToCheck,
score,
)
conn.Block("Possible data tunnel")
conn.Block("possible data tunnel for covert communication and protection bypassing")
return true
}
log.Tracer(ctx).Infof("LMS score of entire domain is %.2f", score)