I am trying to get real figures on how much blaster scanning is going on to
my network, but I don't have enough information. I am seeing 2200 packets
per minute average (for TCP 135, 137-139) on my ingress points. As I'm
advertising a /19 that's around .27 RCP and netbios packets per IP address
per second being sent to my IP range.
I haven't done a long-term look at RCP and netbios traffic on the web so I
have no way to determine how much is blaster generated, does anyone have
baseline information on the amount of RCP and netbios packets were on the
web before blaster was propagated? Alternatively, has anyone worked out the
% of blaster scan as opposed to "normal" background RCP and netbios traffic?