How much traffic do I get from North Korea anyway?
blog.benjojo.co.uk
blog.benjojo.co.uk
That seems to be a major aspect. There are hundreds of VPN services. They compete on many dimensions, such as speed, security, not retaining any logs, and the number of server locations. And some of them have insane numbers of server locations.
Anyway, I've been look it this issue for a while, using ping services (such as asm.ca.com, maplatency.com and ping.pe). For HMA and VyprVPN, only about half of the servers seem to be located where claimed. And HMA claims to have one in North Korea ;)
Some
https://keybase.pub/mirimir/HMA-Vancouver.png
Anything below the blue line is physically impossible. Notable is the horizontal banding.
https://keybase.pub/mirimir/HMA-Vancouver-rev.png
Or to have a typo in the x title, but so it goes.
HMA (Avast) claims that fnj-kp.prcdn.net is in Manpo, North Korea. MaxMind now reports that two of its IPs (5.62.61.64 and 5.62.61.65) are in Prague, Czechia. And the third (5.62.56.160) in Seattle, WA, US. But ipinfo.io still reports North Korea for all three.
But peering is complicated. There are two ISPs in Zurich, for example, with ~25 msec rtt between them, but ~5 msec ping to other nearby cities. They just don't speak directly it seems.
AS, standing for Autonomous System, is like an ISP's name. BGP spreads routing information by rumor. For example, I start the rumor that I can route to IP addresses in 1.2.3.0/24, and tell my peer ISPs. They tell their peers I told them... etc. To prevent rumors from going in circles, you keep a record of every ISP in the path of spreading the rumor, and call it the AS path. (Otherwise you could never retract the rumor, as it would go in circles. BGP speakers do not accept rumors that they themselves are in the path of. (Except in cases of dirty hacks, but then only a finite number of times.))
This article describes fraudulent AS paths attached to (as I understood it) IP ranges that were legitimately owned by the people advertising them to Hurricane Electric. This is like you telling Hurricane Electric that I (the North Korean ISP) told you that I can route to 1.2.3.0/24, an IP address range you own, even though I told you no such thing and we are not even peers.
__=$(exec sed -n '/^4.31.198.44 /!d;=;q' /etc/hosts);
test ${#__} -gt 0||
echo 4.31.198.44 www.ietf.org >> /etc/hosts
http://www.ietf.org/rfc/rfc2650.txtAvast, NFOrce, etc. can update their BGP routing information with a routing registry probably by just sending an email with some authentication details. Apparently the veracity of provided information is not checked. The information then gets propagated to a shared routing registry database offered to the public for free by a handful of registries via WHOIS.
The blog author suggests that the inaccuracies in Maxmind may originate from fake information in WHOIS.
http://www.eecs.qmul.ac.uk/~steve/papers/geolocation-ccr-11....
This paper discusses accuracy of GeoIP databases. It concludes they are between 96-98% accurate at the country-level. Maybe the database compilers would use delay measurement for the 2-4% if the inaccuracies follow some pattern, e.g. they are consitently associated with particular countries. Maybe they already use this method. I don't know.
The IP addresses in the blog, and the idea of fake VPN exit nodes, were discussed previously: http://blog.trendmicro.com/trendlabs-security-intelligence/a...
Including North Korea? :)
Ping services with many probes:
Also, you can also have your attack derive from Russia. Russia (the government or a Russian hacker group) doesn't have to be behind the attack for it to look like its sourced from Russian internet space.