
Score composition
A Crime Score is a weighted correlation across independent Alliance members, each carrying a trust weight based on historical accuracy and false-positive rate, combined with confidence metadata describing how the activity was validated. An observed exploitation attempt is weighted differently from a heuristic suspicion. Nineteen members independently reporting the same address over four months is what places the score in the Critical range rather than a single flagged event.Persistence versus decay
IPv4 Crime Scores decay over time when no new activity is observed, accounting for infrastructure churn, botnet reassignment, and host remediation. This address has not decayed: it registered a new attack 26 minutes before the lookup, on top of four months of continuous activity. The combination of a long track record and current activity distinguishes an indicator warranting active blocking from one that was flagged once and has since gone quiet.Hosting provider is not a scoring input
The ASN attached to this indicator belongs to Alibaba’s US technology arm. Cloud infrastructure from major providers is regularly abused, and provenance alone is a weak signal since legitimate traffic originates from the same ASNs. The three feeds marked “Protected” in this panel — two Checkpoint deployments and one Fortinet deployment, with six more not shown — already have this indicator enforced, meaning policy was applied automatically based on the score rather than a manual review of the ASN.Proof of Value engagements surface indicators like this one already present in a client’s own traffic. Start a Proof of Value.

