Router Analysis

An analysis of the log files from my ADSL router, the router records DOS and Port Scans, with the originating IP address. In order to analysis the results I looked at the total number of attacks, looked at whether there were DOS or Port Scan. For the recorded IP addresses I identified the number of unique IP and then lookup the country of issuing the IP address registration.

2013


I have now completed 12 months of collecting the log files from my ADSL router and moving into the second year of data collection. I will be looking at how 2013 data matches up against the 2012 data on a month per month basis.




April 2013

20122013
CountrySource IPsAttacksCountrySource IPsAttacks
Turkey2525
7575
China1366
434
USA997
215
France324
211
United Kingdom211
11
Japan210Russia11

March 2013

20122013
CountrySource IPsAttacksCountrySource IPsAttacks
Turkey7171Turkey5858
China240United States13134
United Kingdom229Germany325
Germany113France221
Russia11United Kingdom24



Azerbaijan22



Russia16

February 2013

20122013
CountrySource IPsAttacksCountrySource IPsAttacks
Turkey5252Turkey6666
Netherlands116United States27
Ukraine22Azerbaijan22
China12Ukraine11
France11


Egypt11


South Africa11


United Kingdom11



January 2013

20122013
CountrySource IPsAttacksCountrySource IPsAttacks
Turkey7979Turkey3939
South Africa33China157
United States110Germany66
Hong Kong11Switzerland66
Thailand11United States66
Switzerland11United Kingdom16



Yearly Totals


There were a total of 4966 incidents recorded in the log files of my ADSL router during 2012, these came from 666 different IP addresses. These came from 24 different countries, the top 10 countries for IP address origins are listed below in decreasing order of IP address origins.

Turkey 474
China 130
United States 18
South Africa 8
United Kingdom 6
Azerbaijan 4
France 4
Germany 3
Japan 3
Ukraine 2

Summary


Month
No Attacks
DOS
Port Scans
Unique IP
Unique Countries
Dec 2012
70
69
1
65
3
Nov 2012
43
38
5
20
4
Oct 2012
63
54
9
24
4
Sep 2012
21
21
0
21
3
Aug 2012
50
50
0
36
5
Jul 2012
2960
2960
0
80
4
Jun 2012
393
392
1
98
5
May 2012
804
804
0
65
4
Apr 2012
234
234
0
54
6
Mar 2012
156
129
27
77
5
Feb 2012
76
74
2
60
9
Jan 2012
96
94
2
86
6



December 2012

CountrySource IPsNo of attack from country
Turkey6363
Canada16
South Africa11




November 2012

CountrySource IPsNo of attack from country
USA220
Turkey1616
Germany16
Azerbaijan11





October 2012

CountrySource IPsNo of attack from country
USA629
Turkey1616
Saudi Arabia112
Germany16



September 2012

CountrySource IPsNo of attack from country
Turkey1919
Japan11
Malaysia11




August 2012

CountrySource IPsNo of attack from country
Turkey2727
UK26
China515
South Africa11
Greece11





July 2012


CountrySource IPsNo of attack from country
China592938
Turkey1919
Sweden12
South Africa11






June 2012


CountrySource IPsNo of attack from country
China22318
Turkey7272
Azerbaijan22
South Africa11
Cyprus11



May 2012


CountrySource IPsNo of attack from country
China26783
Turkey1919
India11
Pakistan11




Apr 2012


Country Source IPs No of attack from country
Turkey 26 26
China 13 66
USA 9 97
France 3 18
Japan 2 10
UK 2 11




Mar 2012
Country Source IPs No of attack from country
Turkey 71 73
China 2 40
UK 2 29
Germany 1 13
Russia 1 1



27 attempts from a single UK address
27 attempts from a single Chinese address
13 attempts from another Chinese address
13 attempts from a single German address

Feb 2012

Country Source IPs No of attack from country
Turkey 52 53
Ukraine 2 1
France 1 1
China 1 2
Egypt 1 1
South Africa 1 1
UK 1 1
Netherlands 1 16


16 of the attacks came from the same IP address in the Netherlands

Jan 2012

Country Source IPs No of attack from country
Turkey 79 63
South Africa 3 3
Hong Kong 1 1
Switzerland 1 1
USA 1 10
Thailand 1 1

10 of the attacks came from the same IP address in the USA

No comments:

Post a Comment