[sanesecurity] Re: Long DB refresh times

  • From: Emanuele Balla <clam@xxxxxxxxxxxx>
  • To: sanesecurity@xxxxxxxxxxxxx
  • Date: Wed, 25 Apr 2012 16:59:42 +0200

On 4/25/12 4:49 PM, Alan Stern wrote:

>> May I add, FWIW: several of the malware sigs refer to drive-by malware
>> infection schemes, and the URLs they target are used for only a few
>> hours in email.
> 
> Which signature files are like that?

The malware one.


>> Even updating every hour is far from being optimal, IMHO (on my systems
>> those signatures are refreshed every 5 minutes directly from my own
>> repository)...
> 
> How do you update the repository?

More or less like any of you guys, but I rely on my own local repository
and use a very small selection of DBs only.
Reload times are usually about 30-35 secs, and dropped down to 4-6 secs
only after applying Steve's filters...


Other related posts: