Yet another bot IPs blocklist: longtime bot IPs

I recently published 4 blocklists that essentially focus on data center IP ranges.

However, more and more attackers operate from residential IPs.
That’s why I’ve decided to publish another blocking list that focuses on IP addresses that have been used…


This content originally appeared on / and was authored by antoinevastel.com

I recently published 4 blocklists that essentially focus on data center IP ranges.

However, more and more attackers operate from residential IPs. That’s why I’ve decided to publish another blocking list that focuses on IP addresses that have been used by bots for a long period. Because of the way this list is built, it contains both data center IP ranges, as well as residential IPs.

The list is available at the following URL: https://antoinevastel.com/data/avastel-longtime-bot-ips.txt

How is the list built?

The long time infected IPs blocklist is built daily using the last 10 weeks of data collected by the malicious bot IPs API. For each IP address, we leverage the following information:

  1. Number of events where an IP address was used by a bot;
  2. Timespan between the first and last bot detection events.

IPs are included in the list if they meet the following criteria:

  • Timespan (duration between first and last bot detection event) is > 15 days;
  • Ratio between number of events/time span is > 0.2. This second criterion helps to ensure that we have enough events to take a significant decision. It avoids overestimating the lifetime of an IP address.

False-positive disclaimer

Even though residential IPs present in this list have been used by bots for > 15 days, they may still be shared with legitimate humans. To lower the false-positive risk, you should adjust the blocking decision based on other criteria than the IP address.


This content originally appeared on / and was authored by antoinevastel.com


Print Share Comment Cite Upload Translate Updates
APA

antoinevastel.com | Sciencx (2021-11-02T00:00:00+00:00) Yet another bot IPs blocklist: longtime bot IPs. Retrieved from https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/

MLA
" » Yet another bot IPs blocklist: longtime bot IPs." antoinevastel.com | Sciencx - Tuesday November 2, 2021, https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/
HARVARD
antoinevastel.com | Sciencx Tuesday November 2, 2021 » Yet another bot IPs blocklist: longtime bot IPs., viewed ,<https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/>
VANCOUVER
antoinevastel.com | Sciencx - » Yet another bot IPs blocklist: longtime bot IPs. [Internet]. [Accessed ]. Available from: https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/
CHICAGO
" » Yet another bot IPs blocklist: longtime bot IPs." antoinevastel.com | Sciencx - Accessed . https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/
IEEE
" » Yet another bot IPs blocklist: longtime bot IPs." antoinevastel.com | Sciencx [Online]. Available: https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/. [Accessed: ]
rf:citation
» Yet another bot IPs blocklist: longtime bot IPs | antoinevastel.com | Sciencx | https://www.scien.cx/2021/11/02/yet-another-bot-ips-blocklist-longtime-bot-ips/ |

Please log in to upload a file.




There are no updates yet.
Click the Upload button above to add an update.

You must be logged in to translate posts. Please log in or register.