Custom Search

Friday, January 1, 2010

Botnet Statistics [2009-12-31]

Happy New Year!

The United States has broken through the barrier of 100 detected bots today. I hope that in 2010, I can detect more and more bots in the US.

There is no way that Taiwan should top the chart for so long. It is really the fault of my detection system, which can only detect certain kinds of bots. As I do not own a spam-rich domain, I have no way to know if detection with greylisting is better in this regard.

Maybe I should ask some large installations of greylisting, like Texas A&M University, to share their logs? If it works, then it is very likely that I will have 10 times more bots to report!

detection period: 2009-12-31 00:00-23:59 UTC
total number of suspected botnet IPs: 3908
number of botnet IPs notified to network operators: 3455

The top 10 networks (as found in WHOIS), ordered by number of suspected botnet IPs are:

RankNetwork# of suspected botnet IPs
1HINET-NET1042
2BSNLNET563
3CHINANET-GD348
4TFN-NET166
5RCOM90
6002.558.157/0001-6287
7AR-TEAR7-LACNIC85
8TATACOMM-IN83
9002.558.134/0001-5858
10UNICOM-SD52

The top 10 countries (as defined by the 2-character country code), ordered by number of suspected botnet IPs are:

RankCountry# of suspected botnet IPs
1Taiwan1221
2India847
3China760
4Brazil318
5Argentina145
6United States102
7Russian Federation93
8Ukraine33
9Ethiopia30
10South Korea26

No comments:

Post a Comment