Custom Search

Saturday, December 19, 2009

Botnet Statistics [2009-12-18]

After 8 hours of mental exercise, I have finished writing the needed scripts to combine data from both the old and new detection systems. Hope there is not too many bugs in my scripts. From now on, data presented here will be the combined result. With those scripts in hand, building more detection systems will not take too much effort.

detection period: 2009-12-18 00:00-23:59 UTC
total number of suspected botnet IPs: 3560
number of botnet IPs notified to network operators: 3326

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1078
2BSNLNET404
3TFN-NET253
4APOL-NET248
5CHINANET-GD140
6002.558.157/0001-62118
7AR-TEAR7-LACNIC94
8RCOM58
9TATACOMM-IN51
10002.558.134/0001-5842

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1589
2India587
3China468
4Brazil351
5Argentina152
6Russian Federation77
7Colombia27
8Thailand22
9Ethiopia22
10Ukraine21

No comments:

Post a Comment