Not Registered? Sign Up Now!
myNetWatchman Privacy Statement

Log in for advanced features

E-mail:

Password:

 
  Remember Me

mNW Reports  FAQ: mNW Reports






(Registered Users Only)


Look Up Incidents by IP Address

 

 

What is myNetWatchman?

The primary issue in internet security is not that hackers troll the Internet, but rather that the Internet is chock full of insecure systems which are easily compromised, providing means for hackers to perform untraceable, indirect attacks. The only profound way to improve Internet security is to reduce the number compromised systems and minimize the amount of time that a system remains in a compromised state. (Click here to learn more about the myNetWatchman Vision.) myNetWatchman achieves its goals through:

  • Security Event Aggregator
  • Centralized, web-based firewall log analyzer
  • Fully automated abuse escalation/management system

How does myNetWatchman Work?

Step 1

Internet users and companies throughout the world install our Agent software to automatically relay their firewall log events to our central analysis server. (Click here to see myNetWatchman's Privacy Policy.)

The current agent network (Updated: 7/8/2008 10:15:30 PM -0400):

Active Agents U.S. States Covered Countries Covered Event Records Processed (last 24 hrs)

305

34

34

976023

Step 2

Log events with the same source IP addresses are organized into incidents. All IP addresses are automatically backtraced and the responsible domain is identified. This allows you to see ALL events that orginated from a particular source IP address — even activity reported by OTHER agents.

Step 3

Depending on the target service and the number of agents that report a given source IP, the myNetWatchman mailBot automatically sends alert e-mails to the responsible party. Basically you don't need to lift a finger...everything from collecting the data to backtracing to sending an e-mail escalation is all done for you.

Currently we send 500-1000 alert e-mails per day (10,000+ during Code Red). Often the alerts are sent within 60 seconds of when an agent logs an event. This is essential as it helps us inform system administrators (who have usually been compromised themselves) fast enough so that they can take action before serious damage is done.

Top Escalations in last 24 hours: (Updated:7/9/2008 2:15:32 AM UTC)

Responsible DomainEscalation Count
chinanet.cn.net 93
one.at 42
bell.ca 40
outremer-telecom.fr 35
verizon.net 35

ISP Ratings: High Volume (> 125 Incidents/Week)

Responsible DomainIncidents/WeekAvg. Duration (Days)
matav.net 17334.39
arcor.net 17726.37
proxad.net 73423.29
tpnet.pl 16421.13
outremer-telecom.fr 17420.8
bellsouth.net 32020.41
comcast.net 31018.99
shaw.ca 100118.61
charter.net 28216.61
cnc-noc.net 31316.17

ISP Ratings: Medium Volume (25 - 124 Incidents/Week)

Responsible DomainIncidents/WeekAvg. Duration (Days)
inktomi.com 9589.14
eunet.yu 6063.15
eli.net 3733.62
astercity.net 2932.35
wideopenwest.com 4132.22
tm.net.my 6729.36
telus.com 2928.61
andara.com 2727.87
allstream.com 2927.76
pseb.org.pk 3126.44

ISP Ratings: Small Volume (5 - 24 Incidents/Week)

Responsible DomainIncidents/WeekAvg. Duration (Days)
jaring.my 5110.12
scnresearch.com 24103.73
orange.sk 686.1
shrubbery.net 977.3
newedgenetworks.com 573.87
bctelco.com 1671.73
hondutel.hn 566.72
tck.ru 564.86
multikabel.nl 752.2
integratelecom.com 1051.45

Step 4

We receive responses back from about 25-30% of the escalations we send. All of the response information, often with candid details on how the system was compromised and what steps were taken, is all recorded in the incident detail. Many ISPs do process and act upon our alerts, but unfortunately they don't have the automated systems to provide e-mail confirmation of their efforts... but rest assured that most alerts ARE acted upon.

In addition to the global reports you see listed to the left. Agents that contribute data also get a Sample personal report page where you can see an analysis of just the events that you reported.

As an added bonus active agents also receive our IPWatch service which gives you the ability to track your current IP address from anywhere. This is very handy if you have a dynamic IP address and need to connect to your personal web server or remote access program from a remote location.

In summary, think of myNetWatchman as a centralized firewall log analyzer and escalation system that adds a global perspective to your event data--something that no standalone product can achieve.

Our software and services are free for individual use. Simply register and download.

We are currently piloting our security abuse management services for organizations, ISPs, and managed service providers. Anyone interested in participating in our pilot program should contact Lawrence Baldwin at (email link removed to prevent spamming).