<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stopthehacker.com &#187; AS</title>
	<atom:link href="http://www.stopthehacker.com/tag/as/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stopthehacker.com</link>
	<description>Jaal, LLC</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Profiling Autonomous Systems Hosting Blacklisted Websites</title>
		<link>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/</link>
		<comments>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 21:16:06 +0000</pubDate>
		<dc:creator>anirban</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AS]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[malicious websites]]></category>

		<guid isPermaLink="false">http://www.stopthehacker.com/?p=898</guid>
		<description><![CDATA[An Autonomous Systems or AS is a routing construct that represents a group of networks under the control of an organization (credit for edit :Max@badwarebusters.org). These form the &#8220;structure&#8221; of the Internet. These organizations can be thought of as web-hosting companies, large Internet-based companies or resellers of bandwidth and IP addresses. These are usually large [...]]]></description>
			<content:encoded><![CDATA[<p>An Autonomous Systems or AS is a routing construct that represents a group of networks <em>under  the control of</em> an organization (<em>credit for edit :Max@<a href="http://www.badwarebusters.org" target="_blank">badwarebusters.org</a></em>). These form the &#8220;structure&#8221; of the Internet. These organizations can be thought of as web-hosting companies, large Internet-based companies or resellers of bandwidth and IP addresses. These are usually large organizations for whom simply getting an Internet connection and hosting a company for their website is not enough.</p>
<p>In recent months, the trend of benign websites being affected by code injection clearly show that attacks to inject malware into unsuspecting websites is on the rise. It is important to understand the profile of the ASes which are actually providing transit to infected websites hosted within their systems. Since each AS provides bandwidth and resources supporting the downloading of malware to computers which belong to unsuspecting visitors of a compromised website. ASes, more specifically hosting companies and other network operators (rather than ASes) should play a pivotal role in addressing compromised websites.</p>
<p>At StopTheHacker.com, we have conducted extensive experiments to analyze and profile over 20,000 ASes to identify which ASes are the worst offenders in terms of hosting Blacklisted websites.  We have used <a href="http://www.google.com/tools/firefox/safebrowsing/index.html" target="_blank">Google safebrowsing</a> data, also accessible via <a href="http://stopbadware.org/reports/asn/" target="_blank">StopBadware.org</a>, (which sources data from Google and <a href="http://www.sunbeltsoftware.com" target="_blank">Sunbelt</a>)to identify and trend which ASes are responsible for the proliferation of badware on the Internet. We have correlated AS size with <a href="http://www.caida.org/research/topology/#asrank" target="_blank">data</a> available from <a href="http://www.caida.org" target="_blank">CAIDA</a> to determine whether larger ASes are more at fault or not.</p>
<p><strong>We present some brief results below:</strong></p>
<ol>
<li>The average percentage of blacklisted websites in
<ul>
<li>Top 10 ASes (according to number of sites noted by Google) is 3.5%</li>
<li>ASes with Ranks 11-23 (according to number of sites noted by Google) is 3.75%</li>
<li>ASes with Ranks 24-40 (according to number of sites noted by Google) is 5.01%</li>
</ul>
</li>
<li>The AS with the highest percentage of blacklisted sites, is AS 16557 (Colo Solutions, Inc.), with close to 60% of 10,000 sites blacklisted.</li>
<li>The Top 50 ASes, which host more than 10,000 sites each and have at least 6% of websites blacklisted, host 151,000 blacklisted sites, combined.</li>
</ol>
<p><strong>Interesting observations:</strong></p>
<ol>
<li>AS 16557 (Colo Solutions, Inc.), is well known for popping up on blacklists related to peer-to-peer networks [<a href="http://www.cs.ucr.edu/~anirban/Anir-networking07.pdf" target="_blank">Is someone tracking P2P users</a>]. <em>It seems that this AS, which is not really concerned about P2P traffic emanating from within its systems, traffic which is potentially used to exchange copyrighted material, is also not interested in paying attention to malware infected websites hosted within its networks.</em></li>
<li>AS 15169 (Google Inc.), had 590734 sites analyzed and 6046 of them were found to contain malware.</li>
<li>AS 14173 (Photobucket), had zero sites infected out of 399424 sites analyzed.</li>
<li>The Largest AS (Level 3 Communications) according to connection degree, see <a href="http://www.caida.org" target="_blank">CAIDA&#8217;s AS listing</a>, was hosting 571 infected sites out of 136305 sites analyzed by Google.</li>
<li>AS 7018 (AT&amp;T), was hosting 97 infected sites out of 7947 sites analyzed by Google.</li>
<li>AS 701 (Verizon), was hosting 117 infected sites out of 7248 sites analyzed by Google.</li>
<li>AS 1239 (Sprint), was hosting 117 infected sites out of 3958 sites analyzed by Google.</li>
</ol>
<h3>Making Sense of the Results</h3>
<p>Below we present some graphs to highlight the percentage of blacklisted websites hosted by the top few ASes. Note that all AS rankings below are based on the number of websites analyzed by Google. An AS with rank 1 hosts more websites, analyzed by Google than an AS with rank 2.</p>
<div class="gallery">
<div id="attachment_912" class="wp-caption aligncenter" style="width: 310px"><a rel="attachment wp-att-912" href="http://www.stopthehacker.com/wp-content/uploads/2010/01/greater-than-10k-and-greater-than-6-percent.jpeg" title="ASes hosting greater than 10,000 sites and with moe than 6% of them Blacklisted"><img class="size-medium wp-image-912" title="ASes hosting greater than 10,000 sites and with moe than 6% of them Blacklisted" src="http://www.stopthehacker.com/wp-content/uploads/2010/01/greater-than-10k-and-greater-than-6-percent-300x139.jpg" alt="Nearly 50 ASes host at least 600 blacklisted sites each" width="300" height="139" /></a><p class="wp-caption-text">Nearly 50 ASes host at least 600 blacklisted sites each</p></div>
<div id="attachment_903" class="wp-caption aligncenter" style="width: 310px"><a rel="attachment wp-att-903" href="http://www.stopthehacker.com/wp-content/uploads/2010/01/top-10-as.jpeg" title="Percentage of blacklisted sites hosted by the 10 largest ASes "><img class="size-medium wp-image-903" title="Percentage of blacklisted sites hosted by the 10 largest ASes " src="http://www.stopthehacker.com/wp-content/uploads/2010/01/top-10-as-300x206.jpg" alt="Top 10 ASes host lage percentages of blacklisted sites" width="300" height="206" /></a><p class="wp-caption-text">Top 10 ASes host lage percentages of blacklisted sites</p></div>
</div>
<p><span id="more-898"></span></p>
<h3>ASes hosting more than 10,000 sites (each having more than 6% infected sites)</h3>
<p>Below follows the list of ASes, which host more than 10,000 sites each. Of those, at least 6% (600) are blacklisted by Google. Perhaps more attention needs to be focused on fighting malware from within these ASes. There are quite a few prominent web-hosting companies in this list. Note that all ASes below are ranked based on the number of websites analyzed by Google. An AS which appears earlier in the list hosts more websites, analyzed by Google than an AS which appears later on in the list.</p>
<pre class="brush: plain; title: ; notranslate">
ASN             Name
21844           ThePlanet.com Internet Services, Inc.
4837            CNC
11798           Bluehost Inc. US
4812            CABLENETSWISS-HITTNAU Cablenetswiss	CH
26347           New Dream Network, LLC	US
29629           INETWORK-AS IEUROP AS	FR
32244           Liquid Web, Inc.	US
16265           LEASEWEB LEASEWEB AS	NL
3786            LGDACOM LG DACOM Corporation	KR
3595            Global Net Access, LLC	US
32392           Ecommerce Corporation	US
32613           iWeb Technologies Inc.	CA
4847            CNIX
33182           HostDime.com, Inc.	US
21788           Network Operations Center Inc.	US
38356           TIMENET BeiJing Sincerity-times Network Technology Project Ltd.	CN
15244           Lunar Pages	US
25074           INETBONE-AS INET-People Provider Services	DE
25532           MASTERHOST-AS .masterhost autonomous system	RU
30496           Colo4Dallas LP	US
12824           HOMEPL-AS home.pl autonomous system	PL
9929            CNCNET-CN China Netcom Corp.	CN
28753           NETDIRECT AS NETDIRECT Frankfurt, DE
11388           Peer 1 Dedicated Hosting	US
9121            TTNET TTnet Autonomous System	TR
13237           LAMBDANET-AS European Backbone of LambdaNet	EU
9931            CAT-AP The Communication Authoity of Thailand, CAT	TH
46475           Limestone Networks, Inc.	US
29671           SERVAGE Servage GmbH	DE
15685           Casablanca INT Autonomous system	CZ
39392           SUPERNETWORK-AS SuperNetwork s.r.o.	CZ
8342            RTCOMM-AS RTComm.RU Autonomous System	RU
34104           TELETEK-AS TELETEK TELEKOMINIKASYON HIZMETLERI A.S	TR
42910           SADECEHOSTING-COM Sadecehosting-Com	TR
8358            INTERWARE-AS InterWare Autonomus System	HU
25653           FortressITX	US
26277           A+ Hosting, Inc.	US
12363           DADA-AS DADA S.p.a.	IT
23352           Server Central Network	US
17964           DXTNET Beijing Dian-Xin-Tong Network Technologies Co., Ltd.	CN
24400           CMNET-V4SHANGHAI-AS-AP Shanghai Mobile Communications Co.,Ltd.	CN
30176           Priority Colo	CA
4750            CSLOXINFO-ISP-AS-AP CSLOXINFO Public Company Limited.	TH
32181           GigeNET	US
27823           Dattatec.com	AR
16557           Colo Solutions, Inc.	US
5617            TPNET Polish Telecom's commercial IP network	PL
39561           AGAVA Agava JSC AS number	RU
19318           NEW JERSEY INTERNATIONAL INTERNET EXCHANGE LLC	US
9848            GNGAS Enterprise Networks	KR
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.stopthehacker.com/2010/01/01/profiling-autonomous-systems-hosting-blacklisted-websites/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

