nanog mailing list archives
RE: Country of Origin for Malicious Attacks
From: "McBurnett, Jim" <jmcburnett () msmgmt com>
Date: Wed, 25 Jun 2003 12:06:21 -0400
Sean,
of the scans I get and have seen..
60% APNIC region
Most noteably- Taiwan, China, and Korea (north)
20% RIPE
Most noteable- Former Soviet Block nations then
Scandanavian countries...
20% ARIN/LACNIC
This is a rough estimate from the last 3 weeks...
I guess you may be after this kind of fact:
When I blocked HINET
(Taiwan based-- has a single /16 to my knowledge)
I cut scans/probes by 20%....
Later,
Jim
-----Original Message-----
From: sgorman1 () gmu edu [mailto:sgorman1 () gmu edu]
Sent: Wednesday, June 25, 2003 11:58 AM
To: nanog () merit edu
Subject: Country of Origin for Malicious Attacks
I was wondering if folks had noticed any trends with malicious
network attacks predominantly originating from any individual
or group of countries. Any observations, comments or help
would be greatly appreciated.
Thanks,
sean
Current thread:
- Country of Origin for Malicious Attacks sgorman1 (Jun 25)
- Re: Country of Origin for Malicious Attacks Sean Donelan (Jun 25)
- <Possible follow-ups>
- RE: Country of Origin for Malicious Attacks netadm (Jun 25)
- RE: Country of Origin for Malicious Attacks Scott Weeks (Jun 25)
- Re: Country of Origin for Malicious Attacks Adam Debus (Jun 25)
- Re: Country of Origin for Malicious Attacks Scott A. McIntyre (Jun 25)
- RE: Country of Origin for Malicious Attacks Scott Weeks (Jun 25)
- RE: Country of Origin for Malicious Attacks McBurnett, Jim (Jun 25)
- Re: Country of Origin for Malicious Attacks sgorman1 (Jun 25)
- Re: Country of Origin for Malicious Attacks Jamie Reid (Jun 26)
- Live attackers or blind worms? (was Re: Country of Origin for Malicious Attacks) Bill Zeng (Jun 26)
- Re: Country of Origin for Malicious Attacks Peter Galbavy (Jun 27)
- Re: Country of Origin for Malicious Attacks sgorman1 (Jun 27)
- Re: Country of Origin for Malicious Attacks sgorman1 (Jun 27)
