Custom Search

Sunday, December 20, 2009

Botnet Statistics [2009-12-19]

After I utilize the data collected on the new detection system, the number of detected bots rose suddenly, and then took a sharp downfall. Now network operators seems to respond very fast upon my notifications. It is very good that my system seems to work, but I was wondering, is its own effectiveness going to drive itself into extinction, just like the (now gone) ORDB (Open Relay DataBase)?

detection period: 2009-12-19 00:00-23:59 UTC
total number of suspected botnet IPs: 2974
number of botnet IPs notified to network operators: 2768

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1172
2BSNLNET341
3AR-TEAR7-LACNIC99
4CHINANET-GD94
5002.558.157/0001-6273
6RCOM70
7TATACOMM-IN54
8TFN-NET48
9UNICOM-SD43
10APOL-NET42

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1267
2India527
3China388
4Brazil259
5Argentina154
6Russian Federation62
7South Korea28
8United States26
9Colombia24
10Ukraine22

No comments:

Post a Comment