[afnog] Africacert opinion on cybersecurity threat Intelligence

sm+afrinic at elandsys.com sm+afrinic at elandsys.com
Sun Sep 27 13:12:43 UTC 2026


Hi Logan,
At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
>Yes. This can be used as data feed to update IP blocklists which are
>maintained by Cybersecurity
>Threat Intel companies.

I commented about the topic yesterday while I was discussing about 
email: 
https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk 
The usual companies in the vicinity don't sell those services because 
they don't see much value in it.  Those which sell threat 
intelligence services usually re-brand an existing product from a 
foreign company.

There is some code at https://www.elandsys.com/r/09740  You will have 
to make some changes to the code to get it to do what you want.  You 
can also try this (set the variable to the one in code first):

sh -c 'curl -sL "$url" | awk -F"|" '\''/afrinic\|.*\|ipv4/ 
{split($4,a,"."); ip=(a[1]*16777216)+(a[2]*65536)+(a[3]*256)+a[4]; 
print ip, ip+$5-1}'\'' | sort -n | awk '\''NR==1{prev_end=$2; next} 
{gap_start=prev_end+1; gap_end=$1-1; if(gap_start<=gap_end && 
(gap_end-gap_start+1)>=256) { s=gap_end-gap_start+1; printf 
"%d.%d.%d.%d - %d.%d.%d.%d (%d IPs)\n", int(gap_start/16777216)%256, 
int(gap_start/65536)%256, int(gap_start/256)%256, gap_start%256, 
int(gap_end/16777216)%256, int(gap_end/65536)%256, 
int(gap_end/256)%256, gap_end%256, s}; prev_end=$2}'\'''

>I'm not sure I fully understand this statement. Can you please elaborate ?

One side works on the clock while the other side waits for the 
adversary to go off the clock to run its operation.  If you are 
interested in, for example, fraud or advanced persistent threats, 
you'll need to be schedule your operation around the perceived 
threats.  You would also have to look for other information if you 
are doing an analysis.

Regards,
S. Moonesamy 




More information about the afnog mailing list