Monday, October 3, 2011

Why so many attacks from China? (my guess)

I know a few web admins who say that their websites always get attacked by Chinese IP addresses and I have read a few articles saying that this is also the case. But here are a few things I have thought about but I have not seen any article that explains this, so I will explain it here. China has about 450 million (probably more now) Internet users, with US only having 300 million users. Most of these 450 million users use Windows XP (and about 80% of that is a pirated version of Windows that does not get software updates). So my assumption is that China probably has the highest number of infected computers, therefore many attackers could be routing their attacks through infected Chinese computers. Plus they also count on the fact that many Chinese users use public computers (Internet Cafe and so on) which makes it almost impossible to track down who is responsible. Most attacks these days are done through pirated/proxy nodes and it's simply natural that a Chinese IP address is the most likely IP address to get used in any attack on the internet. Most of this is assumption, based on a few "debatable" facts, so do not quote me on this.

1 comment:

  1. it turns out I finally found an article that says exactly what I just said, that's so funny. Here is the quote:

    "Much of the DDoS attack streams did appear to be originating from China. But even if a botnet based on compromised Chinese computers was the source of the attack, that does not necessarily mean that someone in China is the culprit originating it, though that is a possibility."


    http://www.networkworld.com/news/2011/100411-ddos-voip-251553.html

    ReplyDelete