FINDING · DETECTION

Majority-vote ML inference (OCSVM + IF) over OONI data uncovered at least 5 previously undocumented DNS injection IPs active in Russia (e.g., 195.19.90.226, 95.167.13.51, 61.95.167.13.50, 188.19.132.154, 144.85.142.29.248) absent from OONI's existing blocking-fingerprints database, along with novel fingerprints in Italy, Czech Republic, and the UK. Records with fewer than 50 instances were excluded as a conservative false-positive filter.

From 2024-calle-towardToward Automated DNS Tampering Detection Using Machine Learning · §4.3, Table 5 · 2024 · Free and Open Communications on the Internet

Implications

Tags

censors
ru
techniques
dns-poisoningml-classifiermeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.