[afnog] Africacert opinion on cybersecurity threat Intelligence

Loganaden Velvindron loganaden at gmail.com
Sun Sep 27 19:32:43 UTC 2026


On Sun, 27 Sept 2026, 17:13 , <sm+afrinic at elandsys.com> wrote:

> Hi Logan,
> At 03:49 AM 27-09-2026, Loganaden Velvindron wrote:
> >Yes. This can be used as data feed to update IP blocklists which are
> >maintained by Cybersecurity
> >Threat Intel companies.
>
> I commented about the topic yesterday while I was discussing about
> email:
> https://mailarchive.ietf.org/arch/msg/last-call/PNeohgq7WjMhmILJbeuj-bF3yWk
> The usual companies in the vicinity don't sell those services because
> they don't see much value in it.  Those which sell threat
> intelligence services usually re-brand an existing product from a
> foreign company.
>

In a tightly regulated environment or "corporate" environment, putting a
linux or bsd box to parse a database file from an RIR is very difficult.

Auditors will come and ask: is the linux box certified, do we have a
support contract, has the script you wrote been tested and vetted
internally. Compliance can make some things "difficult."

If the rir provides this as a csv or json file,
There are less issues and the addition of the csv feed becomes a CAB item
which has a strong business justification. The rir is considered the
authoritative source which is trusted.





> There is some code at https://www.elandsys.com/r/09740  You will have
> to make some changes to the code to get it to do what you want.  You
> can also try this (set the variable to the one in code first):
>
> sh -c 'curl -sL "$url" | awk -F"|" '\''/afrinic\|.*\|ipv4/
> {split($4,a,"."); ip=(a[1]*16777216)+(a[2]*65536)+(a[3]*256)+a[4];
> print ip, ip+$5-1}'\'' | sort -n | awk '\''NR==1{prev_end=$2; next}
> {gap_start=prev_end+1; gap_end=$1-1; if(gap_start<=gap_end &&
> (gap_end-gap_start+1)>=256) { s=gap_end-gap_start+1; printf
> "%d.%d.%d.%d - %d.%d.%d.%d (%d IPs)\n", int(gap_start/16777216)%256,
> int(gap_start/65536)%256, int(gap_start/256)%256, gap_start%256,
> int(gap_end/16777216)%256, int(gap_end/65536)%256,
> int(gap_end/256)%256, gap_end%256, s}; prev_end=$2}'\'''
>
> >I'm not sure I fully understand this statement. Can you please elaborate ?
>
> One side works on the clock while the other side waits for the
> adversary to go off the clock to run its operation.  If you are
> interested in, for example, fraud or advanced persistent threats,
> you'll need to be schedule your operation around the perceived
> threats.  You would also have to look for other information if you
> are doing an analysis.
>
> Regards,
> S. Moonesamy
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.afnog.org/pipermail/afnog/attachments/20260927/b7e19d4e/attachment.html>


More information about the afnog mailing list