Custom Search

Wednesday, December 16, 2009

Botnet Statistics [2009-12-15]

I set up another botnet detection system about 10 days ago. Although it employees the same detection technique as the old one, the results are vastly different. Almost all botnet computers it detected were located in Taiwan, but I can't explain it. Today I tried to combine the botnet statistics from both systems.

detection period: 2009-12-15 00:00-23:59 UTC
total number of suspected botnet IPs: 5408
number of botnet IPs notified to network operators: 5178

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET2585
2CHINANET-GD544
3APOL-NET461
4BSNLNET233
5TFN-NET183
6002.558.157/0001-6299
7AR-TEAR7-LACNIC85
8TATACOMM-IN41
9UNICOM-SD38
10RCOM38

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan3229
2China837
3India367
4Brazil288
5Argentina140
6United States97
7Russian Federation78
8Colombia29
9South Korea26
10Ukraine25

No comments:

Post a Comment