On Thu, 26 Oct 2006 17:07:32 +0200, Florian Weimer <fw@deneb.enyo.de> wrote:
* Steven M. Bellovin:
As you note, the 20-25% figure (of addresses) has been pretty constant for quite a while. Assuming that subverted machines are uniformly distributed (a big assumption)
I doubt this assumption about distribution is valid. At least over here, consumer-grade ISPs (think DSL with dynamic IP addresses) apply ingress filters, while real ISPs don't. If you're lucky, you get egress filters at some border routers, but it's not standard at all. Customer-facing interfaces are generally unfiltered.
Those are good points. It would be interesting to look at the raw AS data and see what classes of organizations were represented. Unfortunately, that data is not publicly available, according to the FAQ for that project. --Steven M. Bellovin, http://www.cs.columbia.edu/~smb