India beats The Netherlands to win a World Cup final

happygeek 0 Tallied Votes 295 Views Share

I am told, by those who follow the sport, that the Netherlands soccer team stands a pretty good chance of lifting the FIFA 2010 World Cup trophy. The bad news for any Netherlands fans is that their side has already been defeated by India, in the World Cup of security that is.

A SecureWorks study analysed the locations of attempted cyber attacks on its global client-base between January and June this year, and then compared this with the total number of active PCs in each country to produce a league table that determines which of the top 16 countries based on active computer counts had the lowest number of attempted cyber attacks originating from within its borders. The results might surprise you.

India were the clear winners with just 52 attacks per 1000 computers originating from within its borders. The Netherlands came in second with 57 attacks, just beating off some stiff competition from Germany (78) and Brazil (89) with all other countries not managing to break the under one hundred attacks barrier. France came fifth with 106 while the UK was sixth on 107, but the USA put in a shameful performance to finish at the bottom of the table on an astonishing 1,660 attempted attacks per thousand computers. China is often seen as one of the bad guys when it comes to launching cyber-attacks , but only finished tenth with just 201 attacks per 1000. Meanwhile Russia, the other infamous bad guy, didn't do so well by ending up only two places above the United States with a score of 520. Who separated Russia and the US, do I hear you ask? That would be South Korea with a poor 795 attacks per 1000 computers.

"The statistics show that a substantial number of vulnerable computers in countries worldwide have been compromised and are being used as bots to launch cyber attacks " said Jon Ramsey, CTO for SecureWorks, adding "the reasons for the difference in number of attempted attacks per country could comprise many things - this ranges from the overall Internet speeds in a country and how proactive the ISPs are in protecting their clients to general user education on security. The ratio of Windows, Mac and Linux users in a country will also make a big difference.

Dani AI

Generated

called out an eye‑catching SecureWorks league table. The headline is useful for starting a conversation, but the raw ranking alone should not be taken as a definitive measure of national “safety.” Vendor telemetry, geolocation, and normalization choices can dramatically change how those numbers should be read.

Key methodological caveats to keep in mind: IP addresses do not always map cleanly to the physical origin of an attacker (VPNs, proxies, NAT, and registrar/hosting addresses can mislead geolocation). Trusted geolocation providers document these limitations and confidence measures. Passive darknet and vendor sensors give excellent visibility into certain kinds of malicious activity, but they represent a subset of global behavior and depend on where sensors and customers are located. Finally, any per‑device or per‑population normalization depends on how “active” devices were counted and the study timeframe — small changes there change rankings. (support.maxmind.com)

Suggested checklist for analysts and network operators when a vendor report raises concern:

  • review the vendor’s methodology (data sources, definition of “active” machines, time window);
  • correlate with internal telemetry (NetFlow, Zeek/IDS logs, endpoint EDR) rather than relying on a single report;
  • hunt for C2/scan indicators and unusual outbound connections; block problematic outbound ports and apply egress filtering;
  • patch and remove persistence on infected endpoints; use sinkhole/blacklist feeds and share findings with the ISP or CERT.

For policy or research uses, treat single-vendor rankings as one signal among many and prefer studies that disclose data sources and limitations. For broader context on measurement challenges and how to interpret comparative cyber metrics, see the CAIDA work on Internet Background Radiation and recent policy analyses on cybersecurity metrics and their limits. (www-old.caida.org)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.