Hacker News new | ask | show | jobs
by viraptor 4331 days ago
Couldn't find much information about that visualisation, so I have to wonder - what kind of traffic do they count? Is it only showing detected known/assumed attacks? Or does it count all connections? (i.e. does it include scans, or not)

If it includes scans - I'm surprised how few there are. (that's about as many as you'd get on 5 randomly created VMs) If it doesn't - I'm surprised how many active attacks there are.

1 comments

This. Can somebody please explain what we are looking at? For instance: what is an attack? How do they distinguish between an attack and normal traffic? It list companies. Are those ISPs? etc.