{
  "schema": "sosec.open-ip-threat-intelligence.public-ledger.v1",
  "frozen_at": "2026-07-25T23:58:00+08:00",
  "status_refreshed_at": "2026-07-27T12:00:00+08:00",
  "article_slug": "open-ip-threat-intelligence-feed-census",
  "purpose": "A sanitized public evidence ledger for the SOSEC open IP threat-intelligence census. It publishes the measured population, aggregate set results, control-collision totals, freshness observations, action-scoped policy compilation, deterministic fault injection, decision logic, and evidence limits without publishing potentially malicious address material, downloaded feed bodies, credentials, or private traffic.",
  "research_scope": {
    "inclusion_rule": "IP or CIDR threat, attack, abuse, malicious-infrastructure, scanner, anonymity, routing-risk, and aggregate products obtainable without an individual commercial contract",
    "boundary_date": "2026-07-25",
    "catalog_candidate_records": 503,
    "distinct_endpoints_or_files": 332,
    "http_urls_after_consolidation": 318,
    "selected_distinct_network_urls": 130,
    "network_attempts": 133,
    "commit_pinned_local_files": 6,
    "analyzed_records": 139,
    "parseable_ip_datasets": 105,
    "exact_ipv4_datasets": 99,
    "excluded_from_exact_ipv4_union": [
      "domain-only products",
      "URL-only products",
      "hash-only products",
      "CIDR coverage counted separately",
      "IPv6 products without a comparable population experiment",
      "commercial data obtained under an individual contract"
    ]
  },
  "retrieval_result": {
    "http_200_attempts": 109,
    "authentication_404_rate_limit_transport_or_other_failures": 24,
    "successful_responses_that_delivered_html_instead_of_ip_data": 3,
    "parseable_network_datasets": 99,
    "parseable_local_datasets": 6,
    "interpretation": "Retrieval success describes the purposive queue on the boundary date; it is not a random-sample estimate for all 318 URLs."
  },
  "exact_ipv4_membership": {
    "per_source_deduplicated_memberships": 8433954,
    "union_addresses": 5702621,
    "duplicate_memberships": 2731333,
    "duplicate_membership_rate": 0.32384964,
    "single_source_addresses": 4695398,
    "single_source_share_of_union": 0.82337543,
    "maximum_dataset_frequency_for_one_address": 37,
    "current_aggregate_cohort": {
      "datasets": 19,
      "memberships": 1286587,
      "union_addresses": 806156,
      "duplicate_membership_rate": 0.3734
    },
    "current_c2_cohort": {
      "datasets": 8,
      "duplicate_membership_rate": 0.1253,
      "single_source_share": 0.8859
    },
    "attack_source_duplicate_membership_rate": 0.3844,
    "current_outbound_aggregate_duplicate_membership_rate": 0.5089
  },
  "decision_relevant_products": [
    {
      "job": "routing-level malicious network ranges",
      "default": "Spamhaus DROP and DROPv6",
      "action": "bidirectional perimeter rejection of listed prefixes",
      "clock": "publisher daily review and removal",
      "withdrawal": "remove when the linked Spamhaus SBL record leaves DROP",
      "current_status_check": "Official product, JSON endpoints, free-use boundary, daily reevaluation, and removal semantics remained published on 2026-07-26."
    },
    {
      "job": "current broad public-community botnet C2",
      "default": "ThreatFox recent botnet_cc",
      "action": "short-lived outbound IP:port control and separate DNS or proxy control for domains",
      "clock": "three-day query window with a 72-hour local validity",
      "withdrawal": "publisher removal or local expiry",
      "current_status_check": "The official Community API still requires an Auth-Key, supports get_iocs with a one-to-seven-day first_seen window, expires records older than six months, and may require paid enhanced access for commercial use on 2026-07-26."
    },
    {
      "job": "protocol-response-validated botnet C2",
      "default": "Feodo Tracker recommended",
      "action": "outbound destination blocking when active records exist",
      "clock": "five-minute generation and five-to-fifteen-minute retrieval",
      "withdrawal": "active-set removal or short local expiry",
      "current_status_check": "The official FAQ still described the tracked datasets as empty on 2026-07-26; a valid empty set therefore publishes zero rules."
    },
    {
      "job": "protocol-specific inbound observation",
      "default": "DataPlane signal matching an actually exposed service",
      "action": "alert, throttle, or challenge",
      "clock": "one-to-seven-day local window",
      "withdrawal": "expiry, source removal, license change, or failed local contribution test"
    },
    {
      "job": "high-volume inbound scan context",
      "default": "DShield Top 20 plus selected GreyNoise Community lookups",
      "action": "shadow, throttle, challenge, and analyst enrichment",
      "clock": "DShield three-day observation window and current GreyNoise lookup result",
      "withdrawal": "expiry or local evidence that the signal adds no unique correct event",
      "current_status_check": "GreyNoise documentation still listed 10 unauthenticated lookups per day and 50 combined Community API or Visualizer searches per week for eligible free accounts on 2026-07-26."
    },
    {
      "job": "open-source threat-intelligence management",
      "default": "MISP when collaboration, event relationships, sharing scope, and access control justify a TIP",
      "action": "preserve events, attributes, lineage, tags, warninglists, decay, action, and TTL",
      "withdrawal": "use a lighter versioned store when the operating model has only a few enforcement lines"
    }
  ],
  "measured_product_observations": {
    "spamhaus_drop_snapshot": {
      "distinct_ipv4_prefixes": 1669,
      "distinct_ipv6_prefixes": 91,
      "approximate_ipv4_address_coverage": 14900000
    },
    "threatfox_recent_snapshot": {
      "rows": 4302,
      "botnet_c2_rows": 3332,
      "ip_port_values": 2400,
      "domains": 818,
      "urls": 114,
      "botnet_c2_rows_with_last_seen": 3032,
      "distinct_recent_ipv4": 1741,
      "distinct_recent_ipv4_inside_drop_ranges": 169
    },
    "dshield_snapshot": {
      "listed_ipv4_networks": 20,
      "networks_intersecting_scanner_control": 14
    },
    "aggregate_examples": [
      {
        "product": "IPInsights",
        "exact_ipv4": 651035,
        "observation": "The snapshot completely contained IPsum L1, L2, and L3."
      },
      {
        "product": "Bitwire outbound",
        "exact_ipv4": 173859,
        "also_in_inbound": 158817,
        "containment_rate": 0.9135
      },
      {
        "product": "Recent C2",
        "exact_ipv4": 15355,
        "inside_published_aws_ranges_rate": 0.4254,
        "thirty_day_additions": 334,
        "thirty_day_removals": 0
      },
      {
        "product": "PacketsDatabase",
        "hours_since_last_pinned_data_change": 3806.52,
        "observation": "The pinned file still contained public DNS addresses."
      }
    ]
  },
  "control_collision_totals": {
    "cloud_range_memberships": 738407,
    "known_service_memberships": 173403,
    "shared_service_memberships": 89223,
    "scanner_control_memberships": 242090,
    "crawler_memberships": 810,
    "interpretation": "A collision identifies policy risk. It can represent a malicious tenant, compromised service, legitimate measurement, shared infrastructure, or copied upstream data; it is not a measured false-positive rate."
  },
  "freshness_observations": {
    "as_of": "2026-07-25T07:39:33Z",
    "hours_since_latest_data_change": {
      "ShadowWhisperer Threats": 0.66,
      "Data-Shield": 1.56,
      "ThreatFox mirror": 1.81,
      "Bitwire": 2.68,
      "ReportedIP": 3.01,
      "ziyad": 3.18,
      "Recent C2": 18.65,
      "PacketsDatabase": 3806.52
    },
    "content_churn": {
      "ThreatFox mirror one day": {
        "added": 56,
        "removed": 248
      },
      "ThreatFox mirror ninety days": {
        "added": 6739,
        "removed": 15639
      },
      "Data-Shield one day": {
        "added": 1860,
        "removed": 1766
      },
      "Recent C2 thirty days": {
        "added": 334,
        "removed": 0
      }
    }
  },
  "admission_and_exit_logic": {
    "hard_gates": [
      "license covers the intended use",
      "the product's action semantics support the proposed control",
      "observation and distribution time are sufficiently complete",
      "the root observer and withdrawal path are known",
      "candidate rules pass owned-address, partner, critical-SaaS, authorized-scanner, public-DNS, and shared-infrastructure controls"
    ],
    "evidence_strength_scale": [
      "missing",
      "publisher assertion",
      "pinned sample",
      "historical measurement",
      "sustained local result"
    ],
    "default_exit_test": "Remove a source from production after thirty consecutive days without a unique correct event, when it only duplicates another source, when rights stop covering use, when withdrawal exceeds the validity window, or when business exceptions continue to grow."
  },
  "operational_replay": {
    "schema": "sosec.open-ip-threat-intelligence.operational-replay.v1",
    "replay_anchor": "2026-07-25T07:30:48Z",
    "executed_and_reviewed_at": "2026-07-27T12:00:00+08:00",
    "method": {
      "mode": "offline policy compilation and deterministic failure injection",
      "input_boundary": "Eight frozen product artifacts, ten first-party public-network controls, and one commit-pinned scanner control",
      "question_answered": "Whether each frozen source can be transformed into the report's proposed direction, protocol, action, and expiry without silently accepting malformed or stale input",
      "question_not_answered": "Threat-detection precision, recall, and business false-positive rate require independent local traffic, asset context, and adjudicated outcomes",
      "control_collision_meaning": "A collision is a deployment-risk control, not an adjudicated false-positive label."
    },
    "verified_input_artifacts": [
      {
        "name": "Spamhaus DROP IPv4 JSON",
        "bytes": 102035,
        "sha256": "a6cf8d58d5979555cf3962705c6d4f1385932f26479366b071e1da53f451f2c9"
      },
      {
        "name": "Spamhaus DROP IPv6 JSON",
        "bytes": 5915,
        "sha256": "8c19165d4371a6b9cd26a17cc1cfe35927f0d771d85fba96a3ec0adb37481180"
      },
      {
        "name": "ThreatFox official recent CSV",
        "bytes": 999688,
        "sha256": "ef64046735a4fb2d223abe5e9ab11da9621b5c2af3a9c0802d25b4bd54716f62"
      },
      {
        "name": "Feodo recommended IP list",
        "bytes": 503,
        "sha256": "7c72fe807208617db78267d93ec45b2ef020c7cbcd2127b271d57a659f300bd8"
      },
      {
        "name": "DataPlane SSH password auth",
        "bytes": 1205485,
        "sha256": "7ef054777efcbf1c9e23ebf176ae76f35cb76cbd1c491f6897da7079a7a493b1"
      },
      {
        "name": "DShield recommended block list",
        "bytes": 2127,
        "sha256": "713f12ee7a61b316bc262deadb1bad84a9d5bca22e589a6d30756d29b4b339ed"
      },
      {
        "name": "FireHOL Level 1",
        "bytes": 73122,
        "sha256": "753aa9e65fd04a579bf2fcd445d0acef8089a52912d0156c195856de4610f0fa"
      },
      {
        "name": "IPsum Level 1",
        "bytes": 1572732,
        "sha256": "ba009e20d3b36d33d19624b2393ae3d6130eec8f076dc675d6ea51948d385e23"
      }
    ],
    "control_boundary": {
      "first_party_network_snapshots_verified": 10,
      "scanner_control_sha256": "cca20995fa148dfd211c35cb04456d541fc169e10675035e9d3982ba97b5fb7d",
      "classes": [
        "shared cloud",
        "known service",
        "shared service",
        "known crawler",
        "commit-pinned scanner"
      ]
    },
    "policy_compilation": [
      {
        "source": "Spamhaus DROP/DROPv6",
        "input": {
          "ipv4_prefixes": 1669,
          "ipv6_prefixes": 91,
          "drop_v4_metadata_records": 1670
        },
        "output": {
          "bidirectional_edge_deny_prefixes": 1760
        },
        "key_control_collisions": {
          "cloudflare_prefixes": 2,
          "cloudflare_overlapping_ipv4_addresses": 1024,
          "scanner_prefixes": 5,
          "scanner_overlapping_ipv4_addresses": 217
        },
        "decision": "Admit to hard block with owned-address, partner, CDN, and critical-SaaS path controls."
      },
      {
        "source": "ThreatFox recent botnet_cc",
        "input": {
          "rows": 4302,
          "raw_botnet_cc_rows": 3332
        },
        "compiler": {
          "window_hours": 72,
          "minimum_confidence": 75,
          "eligible_rows": 3204,
          "outbound_ip_port_rules": 2317,
          "dns_domain_rules": 777,
          "proxy_url_rules": 110,
          "distinct_ipv4_in_ip_port_rules": 1686,
          "distinct_ipv4_inside_drop": 167,
          "distinct_ipv4_outside_drop": 1519,
          "outside_drop_share": 0.90094899
        },
        "key_control_collisions_by_distinct_ipv4": {
          "aws": 35,
          "github_service": 16,
          "google_cloud": 14,
          "google_public": 14
        },
        "decision": "Admit as scoped outbound IP:port, DNS-domain, and proxy-URL controls with 72-hour expiry."
      },
      {
        "source": "Feodo recommended",
        "input": {
          "syntactically_valid_ipv4_rows": 1,
          "snapshot_updated_at": "2026-03-04T14:28:39Z",
          "age_hours_at_replay": 3425.04
        },
        "output": {
          "outbound_deny_ipv4": 0
        },
        "key_control_collisions": {
          "aws_exact_ipv4": 1
        },
        "decision": "Quarantine the stale row and publish zero active rules."
      },
      {
        "source": "DataPlane SSH password auth",
        "input": {
          "distinct_ipv4": 11450
        },
        "output": {
          "hard_block_rules": 0,
          "ssh_observation_keys": 11450
        },
        "key_control_collisions": {
          "google_public": 152,
          "github_service": 114,
          "aws": 13,
          "scanner": 4
        },
        "decision": "Use for shadow, alert, throttle, or challenge on exposed SSH only."
      },
      {
        "source": "DShield Top 20",
        "input": {
          "ipv4_prefixes": 20,
          "ipv4_address_coverage": 5120
        },
        "output": {
          "hard_block_rules": 0,
          "inbound_shadow_or_throttle_scopes": 20
        },
        "key_control_collisions": {
          "scanner_prefixes": 14,
          "scanner_overlapping_ipv4_addresses": 3401,
          "scanner_coverage_share": 0.66425781
        },
        "decision": "Observe or throttle matching inbound services."
      },
      {
        "source": "FireHOL Level 1 comparison baseline",
        "input": {
          "objects": 4588,
          "ipv4_address_coverage": 611303425
        },
        "output": {
          "unconditional_default_deny_rules": 0
        },
        "key_control_collisions": {
          "cloudflare_prefixes": 2,
          "cloudflare_overlapping_ipv4_addresses": 1024,
          "scanner_prefixes": 16,
          "scanner_overlapping_ipv4_addresses": 3023
        },
        "decision": "Retain as a catalog; require per-upstream lineage, action, and expiry."
      },
      {
        "source": "IPsum Level 1 comparison baseline",
        "input": {
          "distinct_ipv4": 110687
        },
        "output": {
          "unconditional_default_deny_rules": 0
        },
        "key_control_collisions": {
          "scanner": 13061,
          "aws": 2961,
          "github_service": 2489,
          "google_public": 3198,
          "google_common_crawler": 43
        },
        "decision": "Retain for hunting, consensus, and source study."
      }
    ],
    "fault_injection": {
      "passed": 6,
      "total": 6,
      "cases": [
        {
          "case": "pinned hash mismatch",
          "outcome": "rejected",
          "active_generation_changed": false
        },
        {
          "case": "HTTP 200 with HTML body",
          "outcome": "rejected",
          "active_generation_changed": false
        },
        {
          "case": "truncated DROP NDJSON",
          "outcome": "rejected",
          "active_generation_changed": false
        },
        {
          "case": "ThreatFox field drift",
          "outcome": "rejected",
          "active_generation_changed": false
        },
        {
          "case": "timestamp regression",
          "outcome": "rejected",
          "active_generation_changed": false
        },
        {
          "case": "current valid empty active set",
          "outcome": "accepted with zero compiled rules",
          "active_generation_changed": true
        }
      ],
      "rejected_candidates_changed_active_generation": false,
      "valid_empty_compiled_rules": 0,
      "active_generation_changed_only_after_valid_accept": true,
      "lifecycle_replay": {
        "passed": 4,
        "total": 4,
        "cases": [
          {
            "case": "valid candidate followed by injected health failure",
            "candidate_gate": "accepted",
            "candidate_became_active": true,
            "previous_generation_restored": true
          },
          {
            "case": "ThreatFox refresh failure followed by clock advance",
            "refresh_failed_at": "2026-07-25T08:30:48Z",
            "active_generation_preserved": true,
            "active_rules_after_refresh_failure": 3204,
            "all_rules_checked_expired_at": "2026-07-28T07:34:38Z",
            "active_rules_after_expiry": 0
          },
          {
            "case": "DROP last-known-good 48-hour boundary",
            "deadline": "2026-07-27T07:30:48Z",
            "state_one_second_before": "automatic_last_known_good",
            "state_at_deadline": "operator_decision_required"
          },
          {
            "case": "valid empty generation followed by stale Feodo candidate",
            "stale_candidate_outcome": "rejected",
            "empty_generation_preserved": true,
            "active_rules": 0
          }
        ]
      }
    },
    "publication_status": {
      "current_claim": "Reproducible cross-sectional measurement and deployment-gate replay",
      "longitudinal_paper_requirements": [
        "preregistered 90-to-180-day repeated collection",
        "fixed missing-sample handling",
        "independent adjudicated labels from ISP, enterprise, and cloud-hosting environments",
        "metrics stratified by asset class and proposed action",
        "time to first correct hit, unique correct events, legitimate impact, removal survival, and analyst labor",
        "paired uncertainty intervals over shared events"
      ]
    }
  },
  "evidence_limits": [
    "The market sample was purposive and did not retrieve every consolidated URL.",
    "The union experiment covered exact IPv4 only; CIDR coverage and IPv6 require separate measurement.",
    "Public control sets do not reveal the tenant, process, session, or business outcome behind an address.",
    "Git history measures publication history and cannot reconstruct every sensor observation time.",
    "A real false-positive rate requires local traffic, asset context, adjudicated incidents, and remediation outcomes.",
    "The operational replay tests artifact integrity, parser conformance, action compilation, expiry, and rollback; it does not measure threat-detection efficacy.",
    "A single frozen cross-section cannot estimate record survival, removal propagation, or longitudinal source stability.",
    "Potentially malicious addresses, downloaded feed bodies, credentials, raw responses, and private traffic are intentionally absent from this public ledger."
  ]
}
