mandiant / GeoLogonalyzer

GeoLogonalyzer is a utility to analyze remote access logs for anomalies such as travel feasibility and data center sources.
Apache License 2.0
194 stars 59 forks source link

Bundle ASNs for ISPs together for ASN check #10

Open dmb2168 opened 5 years ago

dmb2168 commented 5 years ago

Bundle ASNs of common ISP providers together (i.e. put all AT&T ASNs into one AT&T bucket) so that if a logon session switches between two ASNs owned by the same ISP it's not treated as an anomalous change. I think this is pretty safe (at least for US based ISPs) and would greatly cut down on noise.