Custom Search

Wednesday, February 2, 2011

Botnet Statistics [2011-02-01]

I have been trying to detect botnets with greylisting recently. Today I sent a small batch of botnet notification based on greylisting's detection for the first time. Fake open relay will still be my primary detection mechanism. Greylisting will be used only for those bots not reported by fake open relay. The following statistics does not include bots detected by greylisting.

detection period: 2011-02-01 00:00-23:59 UTC
total number of suspected botnet IPs: 881
number of botnet IPs notified to network operators: 719
number of blocked spams: 170267
recipient count of blocked spams: 3523360

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET231
2CHINANET-GD144
3CHINANET-ZJ-WZ22
4RCOM17
5BSNLNET14
6003.420.926/0002-0510
7CHINANET-ZJ9
8002.558.157/0001-629
9KORNET-KR7
10INTER-SAT7

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1China259
2Taiwan236
3India57
4Brazil53
5Russian Federation46
6United States24
7Colombia19
8Indonesia16
9Poland14
10South Korea14

No comments:

Post a Comment