Below is a chart showing unacknowledged SYNs (i.e. nothing on my network returned a SYN ACK) sent to my home network over a period of 6 days, for the top 25 autonomous systems. The TCP SYNs are unacknowledged because they’re for services I don’t run or sourced from address space I intentionally block due to a history of nefarious activity.
Pretty easy to see that the far and away worst offenders are cloud and hosting providers on U.S. soil. Let’s do some basic arithmetic for just the top offending AS, Amazon’s AS 16509. I saw 47,094 unwanted TCP SYNs over a span of 6 days. That’s 47,094 in 8,640 minutes, which is an average of 5.45 per minute. In other words, just from one Amazon AS, I see an undesired connection attempt every 11 seconds on average.
I personally find this very disappointing. As I’ve posted before, my home web site is a tiny personal web site, mostly for my own use. It sees a TINY amount of legitimate traffic. My home network happens to be heavily instrumented, so I can see what’s going on. What I see gets worse each year. As of today, I’m blocking access to my web server from 17.51% of the publicly routable IPv4 unicast address space (about 698 million IPv4 addresses). This makes me sad, but it’s the current reality of keeping the garbage traffic away. 🙁
