The Invisible Army: Why IP Reputation Fails Against the Rotation Economy
Imported from official source
Attackers route malicious traffic through ordinary home internet connections — and to a reputation feed, the source IP is indistinguishable from a legitimate user's connection. GreyNoise analyzed 4 billion sessions over 90 days and found that 39% of unique IPs targeting the edge come from residential address space. 78% vanish after just 1–2 sessions, before any reputation system can flag them. The report documents why detection must shift from where the traffic comes from to what it is doing.
This version
- Version
- 1 of 1
- Recorded
- September 20, 2026 19:52
- Change
- Initial
- Content hash
91638414fb3fefd06140859106cce487- All versions
- Revision history