[afnog] Africacert opinion on cybersecurity threat Intelligence
sm+afrinic at elandsys.com
sm+afrinic at elandsys.com
Sun Sep 27 13:12:43 UTC 2026
Hi Logan,
At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
>Yes. This can be used as data feed to update IP blocklists which are
>maintained by Cybersecurity
>Threat Intel companies.
I commented about the topic yesterday while I was discussing about
email:
https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk
The usual companies in the vicinity don't sell those services because
they don't see much value in it. Those which sell threat
intelligence services usually re-brand an existing product from a
foreign company.
There is some code at https://www.elandsys.com/r/09740 You will have
to make some changes to the code to get it to do what you want. You
can also try this (set the variable to the one in code first):
sh -c 'curl -sL "$url" | awk -F"|" '\''/afrinic\|.*\|ipv4/
{split($4,a,"."); ip=(a[1]*16777216)+(a[2]*65536)+(a[3]*256)+a[4];
print ip, ip+$5-1}'\'' | sort -n | awk '\''NR==1{prev_end=$2; next}
{gap_start=prev_end+1; gap_end=$1-1; if(gap_start<=gap_end &&
(gap_end-gap_start+1)>=256) { s=gap_end-gap_start+1; printf
"%d.%d.%d.%d - %d.%d.%d.%d (%d IPs)\n", int(gap_start/16777216)%256,
int(gap_start/65536)%256, int(gap_start/256)%256, gap_start%256,
int(gap_end/16777216)%256, int(gap_end/65536)%256,
int(gap_end/256)%256, gap_end%256, s}; prev_end=$2}'\'''
>I'm not sure I fully understand this statement. Can you please elaborate ?
One side works on the clock while the other side waits for the
adversary to go off the clock to run its operation. If you are
interested in, for example, fraud or advanced persistent threats,
you'll need to be schedule your operation around the perceived
threats. You would also have to look for other information if you
are doing an analysis.
Regards,
S. Moonesamy
More information about the afnog
mailing list