Disruption partner monitoring

Quick Description

The disruption partner monitoring system meticulously scans the feeds of our partners, including VirusTotal, Spamhaus and quad9 to authenticate the accurate representation of the attacks we have reported to them. This tool is instrumental in enabling us to vigilantly oversee the status of the attacks our partners communicate, ensuring the visibility of our reports on their feeds. The ultimate goal is to ascertain that the specified domains are appropriately identified by our disruption partner network, thereby curbing or intercepting traffic to these nefarious domains that have detrimental effects on users.
In the Precrime platform, this monitoring information is ensured by the dots just after the Disruption partner name. The dot color will reflect the partner status (see below).

drpl

Partner monitoring system

In the "Attack Detail" section corresponding to any attack listed on the "Disrupted Attacks" page, there is a widget card displayed, resembling the example shown below. This display offers a concise summary of the current status concerning our top three partners.

drpl2

Clicking "View All" enables you to view every partner in our network, along with a detailed description in a pop-up page (refer below). For Virustotal, Spamhaus, and Quad9, the disruption status indicates their current level of effectiveness.

drpl3

Disruption Status
The disruption status may appear as follows:

  • Disrupted: The partner has acknowledged our request, confirmed they reviewed our attack submission, and categorized it as an attack in their database.
  • Processing: The partner has received the request, but we cannot verify if it has been acknowledged yet.

Status updates occur differently depending on the partners. For Virustotal and Quad9, the status is updated every 12 hours. For Spamhaus, it is updated every 6 hours.

 

Monitoring schedule

Bellow the current monitoring schedule:

VIRUSTOTAL:

 - Runs every day at 00:10 and 12:10 UTC

SPAMHAUS:

- Runs every day at: 00:00, 06:00, 12:00, 18:00 UTC

QUAD9:

- Runs every day at: 00:50, 12:50 UTC