What does an IP address in a threat-intelligence or reputation report prove?¶
title: "What does an IP address in a threat-intelligence or reputation report prove?" card_id: "IP-106" status: "complete" source_document: "https://docs.google.com/document/d/1otd-rvgiOwwe0ZfR_DsAKPl1HHd37RkyD5cQswtn4fI/edit?usp=drivesdk"
What does an IP address in a threat-intelligence or reputation report prove?¶
A threat-intelligence report describes an IP address as malicious, suspicious, a botnet node or part of a particular service. What does that prove?
It proves that the reporting source applied that label, based on information and rules that need to be understood.
The source may have observed scanning, spam, malware traffic, failed logins or connections to known infrastructure. It may combine several feeds, accept third-party reports or calculate a score. The underlying activity could be recent, historic, repeated or represented by a single observation.
Find out what the label actually means. When was the address observed? What behaviour triggered the classification? Was the source looking at packets, completed sessions, submitted reports or another provider’s assessment? How confident is it, and when was the entry last updated?
IP addresses can be shared and reassigned. A poor reputation created by one customer may later affect another. A VPN, hosting service or compromised device may carry traffic for many unrelated users. A label attached to the address doesn’t automatically transfer to the current subscriber, device or person.
Use the report to generate and prioritise enquiries. It may support the possibility that infrastructure was being used as a proxy, that a system was compromised, or that events across several cases deserve comparison. Where the information matters, seek the underlying observations and preserve the report as it appeared at the relevant time.
Check independent sources, but don’t mistake repetition for corroboration. Several products may all reproduce the same original feed. Agreement can be useful, but you need to know whether the sources are genuinely independent.
Avoid writing that the address “is malicious” as though an address has intent. Say who classified it, what category they used, the relevant date and the known basis or limitations.
The report may provide useful intelligence about past activity associated with an address. On its own, it doesn’t prove that the event you’re investigating was malicious, that the same actor was involved, or that the current account holder or user was responsible.