Welcome to Leurre.com!
| Figure 1: Attacks per protocol. Click here for an up to date interactive full scale figure |
Figure 2: Attacks per port sequence. Click here for an up to date interactive full scale figure |
| Figure 3: Backscatter attacks per country. Click here for an up to date interactive full scale figure |
Figure 4: Attacks per country & port sequence. Click here for an up to date interactive full scale figure |
Click on any of the previous four pictures to launch an applet enabling you to see:
- the type of protocols used to launch attacks (Figure 1)
- the sequence of ports probed by attackers (Figure 2)
- the countries where victims of DDoS are located (Figure 3)
- the relationship between attacking countries and types of attack (Figure 4)
All figures are based on the last 30 days of data collected in more
than 30 different countries, covering the 5 continents. The Project page explains you
how to host one of them and offers a graph showing the exact
number of platforms that were up and running during the last 30 days.
By becoming a partner, you can get access to the whole
dataset we have accumulated for the last 3 years as well as tools, like these applets, we have developed for analysis purposes.
The project
In order to get a more realistic picture of the attacks happening on the Internet as well as their root causes (ie organized crime vs script kiddies) using unbiased quantitative data, we have deployed (and keep deploying) for more than 3 years now a worldwide distributed set up of identical honeypots in many different countries and we centralize all their tcpdump files in a database that all partners have access to for free. As of today, we have around 50 platforms running in almost 30 different countries covering the 5 continents.




