ESET Threat Intelligence data improves detection
Last Update: Thursday, June 21, 2018 : 01:58 (+4GMT)
A test conducted by Whalebone, a provider of DNS filtering services, showed that adding Indicators of Compromise from ESET to DNS filtering detection data significantly improves detection.
Experts from Whalebone and ESET revealed the results of a DNS filtering test in their joint presentation at the IS2 Conference, an information security event held in Prague, Czech Republic. The test was run on a sample of 100,000 internet connections, representing around half a million connected devices in two countries, the Czech Republic and Slovakia.
Before, Whalebone had utilized Indicators of Compromise (IoC) generated via methods such as sandbox simulations, analysis of network traffic or utilizing known malware patterns. „We wanted to include detection data from endpoints as a new source of IoC, hoping for improved detection capability,“ said Robert Šefr, Whalebone’s Chief Technology Officer.
The test was aimed at confirming the expectation that including IoC from ESET Threat Intelligence would lead to new, previously unavailable detections – while keeping false positives at a minimum.
The test was run in the first quarter of 2018 and involved around 55,000 unique malicious domains in the tested IoC feed. Out of those, around 1100 domains were detected. 18.5% of the devices in the test made at least one attempt to contact a malicious domain from the feed; the overall number of incidents in the test was around 1.75 million. Out of those, around half (866,000 incidents, precisely 49.51%) were detected based solely on the IoC provided by ESET – i.e., without data from ESET, these incidents would have gone undetected. Only 0.47% of incidents were detected based on both ESET’s and original Whalebone data; the remaining 50.02% of incidents were detected independently from ESET.
Out of the 866,000 incidents detected based on the IoC by ESET, only one single domain blocking was found to be a false positive.
"The Whalebone test clearly showed that rigorous categorization of data, which is paramount for ESET, allows for both a high detection rate and keeping false positives close to zero", comments Peter Dekýš, ESET’s IT Security Director.
“The testing has shown that by including IoC from ESET Threat Intelligence, detections significantly increased, with false positives amounting virtually to zero. Overall, the test has proven that it is appropriate to use endpoint-sourced IoC for DNS-level protection”, concludes Whalebone’s Robert Šefr.
- Saudi Ministry Boosts International Cooperation for Hajj Compliance... [2278-Views]
- AI Security Forum to Highlight the Role of AI in Shaping National Security Fra... [2102-Views]
- Mercato Mall Presents Unfolding in Blue — A Moving Tribute to Inclusion, Creat... [1796-Views]
- Lg electronics releases first-quarter 2026 financial results... [1318-Views]
- Uae Pavilion At Expo 2025 Osaka Highlights Youth Ambassador Programme At Keio ... [1025-Views]
- RTA Announces Service Hours During Eid Al-Adha Holiday 1447 AH / 2026... [923-Views]
- UAE honors 20 companies and individuals for driving billions back into the nat... [918-Views]
- Make it in the Emirates 2026: A Record-Breaking Fifth Edition Backed by Key Pa... [908-Views]
- SHEGLAM Returns to the Glam Multiverse with the Rick and Morty 2.0 x SHEGLAM... [904-Views]
- TCL Launches 2026 SQD-Mini LED TV Lineup in the UAE, Introducing the C7L, C8L,... [845-Views]
- UAE-based sindan collaborates with new york university abu dhabi to boost rese... [837-Views]
- EDGE Launches Case Quest, a Gamified Learning Experience for the Future Workfo... [836-Views]
- EDGE Group Signs Agreement to Acquire CMD, a Top-Tier Italian Engine Company... [820-Views]
- The International Exhibition for National Security and Resilience 2026 conclud... [804-Views]
- Dubai Festivals and Retail Establishment Brings Dubai's Retail Sector Together... [785-Views]
- Emirates Skywards launches global ‘Season of Rewards' campaign for members wor... [784-Views]
- The International Exhibition for National Security and Resilience (ISNR 2026) ... [779-Views]
- EDGE Awards AED 200 Million Contract to Abu Dhabi Cable Harness Manufacturer E... [753-Views]
- Core42 and Solutions+ Partner to Build Sovereign AI Infrastructure Across Muba... [748-Views]
- ISNR 2026 to Spotlight Eight Critical Sectors in National Security... [745-Views]



