Monthly report

ASN Risk Report

Autonomous systems ranked by a 0–100 risk score built from last month's honeypot observations.

August 2026 ASN risk report

methodology 2.0 · window 2026-08-01 → 2026-08-31 · 3,228 autonomous systems scored

3,228
ASNs scored
30.7
Median score
46.4
90th percentile
87.7
Top score
614 0-9
272 10-19
664 20-29
952 30-39
528 40-49
147 50-59
39 60-69
10 70-79
2 80-89
0 90-100

Top 5 by risk score

Real rows from this month's report — the ASN number and operator name are withheld. Sign in to see who they are and the full ranking of 3,228.

# ASN Entity Score Pctl Observed IPs
1 AS••••• █████████ 87.7 100 967
2 AS••••• █████████ 87.3 99.9 1,054
3 AS••••• █████████ 77.3 99.9 1,881
4 AS••••• █████████ 76.6 99.9 230
5 AS••••• █████████ 76.3 99.8 479

Sign in to view the full report →

What the report tells you

Every autonomous system observed by the HoneyDB sensor network during the month is scored from 0–100, so you can see which networks are genuinely hostile relative to their size — not just which ones are biggest. A large consumer ISP with thousands of noisy subscribers is a different problem from a small hosting network where a large share of its address space is attacking sensors.

  • Density (weight 0.45) — observed attacking IPs as a share of the network's announced IPv4 space, log-scaled.
  • Magnitude (weight 0.25) — how many distinct IPs were seen, log-scaled.
  • Persistence (weight 0.15) — the share of the month's days the network was active.
  • Breadth (weight 0.15) — how many distinct honeypot services its hosts probed, which separates a scanning farm from one compromised host.

The four are combined as a weighted geometric mean, so a network cannot score highly on one dimension alone.

Signed-in users get the full ranking with every underlying metric, month-over-month movement, and known internet scanners tagged so you can filter research traffic out — plus the whole dataset through the API.

See the full ASN risk report

Sign in to rank every scored network, track month-over-month movement, and pull the dataset from the API.

Sign in to view the report → See the API