Custom Search

Friday, December 18, 2009

Botnet Statistics [2009-12-17]

I should write some scripts to automatically combine numbers from both detection systems. Manual calculation is error-prone. Taiwan's numbers are taken from the new detection system, while other countries' numbers are taken from the old one.

detection period: 2009-12-17 00:00-23:59 UTC
total number of suspected botnet IPs: 3477
number of botnet IPs notified to network operators: 3266

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1024
2APOL-NET593
3TFN-NET307
4BSNLNET218
5CHINANET-GD140
6002.558.157/0001-6291
7AR-TEAR7-LACNIC57
8RCOM42
9UNICOM-SD38
10002.558.134/0001-5832

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1927
2China430
3India344
4Brazil268
5Argentina102
6Russian Federation78
7Colombia25
8Ukraine23
9United States18
10Thailand18

No comments:

Post a Comment