Skip to content

Scoring Model

The risk score is a weighted composite of three signal categories, resulting in a value from 0 (maximum risk) to 100 (fully trusted).

Score Calculation

Total Score = (Hygiene × 0.40) + (Threat × 0.35) + (Stability × 0.25)

Each component starts at 100 and receives penalties based on detected signals.

Risk Levels

Score RangeLevelInterpretation
90-100LOWTrusted, no significant issues
70-89MEDIUMMinor concerns, monitor
50-69HIGHSignificant risk factors
0-49CRITICALKnown malicious or severely compromised

Hygiene Score (40%)

Evaluates routing best practices and protocol compliance.

SignalPenaltyDescription
RPKI Invalid-20Routes with invalid RPKI status (>1%)
Route Leaks-20Valley-free routing violations
Bogon Ads-10Advertising reserved/unallocated space
High Fragmentation-10Excessive prefix fragmentation (score >50)
Zombie ASN-15Registered but silent (0 prefixes)

Threat Score (35%)

Measures association with malicious activity.

SignalPenaltyDescription
Spamhaus Listed-30Present on DROP/EDROP lists
Botnet C2-20/host (max -40)Hosting command and control servers
High Spam Rate-15Excessive spam emission
WHOIS Entropy-10Algorithmically generated Org Name
Persistent Threats-10Repeated threat activity (>5 events in 30d)

Stability Score (25%)

Assesses operational reliability based on historical behavior.

SignalPenalty/BonusDescription
High Churn-25>2 upstream changes in 90 days
Predictive Instability-15Statistical analysis flags instability
Route Flapping-5>100 withdrawals in 7 days
Bad Neighborhood-15Avg upstream score < 50
Suspicious Upstreams-5Avg upstream score 50–69
Toxic Downstreams-20Avg downstream score < 70
DDoS Sponge-15>5 blackhole events in 7 days
Traffic Chaos-10>10 excessive prepending events in 7 days
PeeringDB Profile+5Verified peering presence
Tier-1 Upstreams+5Multiple Tier-1 transit providers

Score History

All score changes are recorded in ClickHouse with millisecond precision. The /asn/{asn}/history endpoint provides access to historical data for trend analysis.

Historical data enables:

  • Detection of score degradation over time
  • Correlation with external events
  • Predictive stability analysis

ASN Risk Intelligence Platform