Does anyone know where we can get more information about the stats behind this slide:
https://twitter.com/AlecMuffett/status/730773970383982592
The slide says:
1:11,500 non-Tor IPs contained malicious requests 1:380 Tor exit nodes contained malicious requests
The way it's worded, it sounds like they're saying "1/11500 of the non-Tor IP addresses we saw sent malicious requests, and 1/380 of the Tor exit node IP addresses we saw sent malicious requests", but I'm finding that hard to believe, since 1/380 of the Tor exit node IP addresses is ~3 IP addresses. It's unlikely that all malicious Tor traffic was confined to 3 exit nodes. (But interesting if true.)
Were they perhaps being a little loose and really meant "1/11500 TCP connections coming from non-Tor IP addresses, and 1/380 TCP connections coming from Tor exit nodes, contained malicious requests"?
Thanks,
- Ian