I.T.S. TRAFFIC ANALYSIS · RECORDED SCENARIOS

Can you spot an attack?

Attack evidence does not have one shape. One scenario is dominated by a single source; another becomes visible only after separate IPs, locations, client signatures, and UTC time slots are correlated.

Two evidence viewsRecorded source attributesUTC chronology

DIFFERENT SIGNAL SHAPES

Three ways the evidence becomes visible.

SCENARIO 01

One source overwhelms the comparison.

The concentration is visible immediately: one IP accounts for the dominant request burst, route spread, connection count, and absence of verified human interaction.

Recorded traffic evidence with one source IP dominating a five-minute request interval
Concentrated evidence: request volume is enough to expose the anomaly.
SCENARIO 02

No source receives visual priority.

Volume is removed from the foreground. The evidence appears through the relationship between public source IPs, countries, reported agents, probed routes, and neighboring UTC observations.

Distributed correlation view connecting problematic source IPs from multiple countries without a request-volume spike chart
Distributed evidence: correlation carries more information than bar height.
SCENARIO 03

Cadence exposes the burst.

A second-level view reveals the arrival rhythm, the exact maximum, and the targeted routes without repeating the broader source comparison.

Compact per-second request chart for the concentrated attack peak, with thin bars and probed-route examples
Second-level evidence: twelve UTC seconds shown with narrow request bars.

REQUESTS BY SOURCE IP

Two scales, two useful readings.

Both views use the same source IPs and exact request counts. Only the bar scale changes: linear preserves absolute concentration, while logarithmic expands lower-volume sources for comparison.

ABSOLUTE SCALE

Linear request comparison

0–631 requests
VISIBILITY SCALE

Logarithmic request comparison

Values remain exact

SOURCE DETAIL · SNAPSHOT

Recorded problematic-source evidence.

Public network sources only. City and country are approximate IP-derived locations; the User Agent is the value reported by the client.

Source IPRequestsReported User AgentCityCountryFirst observed (UTC)

Snapshot captured August 1, 2026. A source appears here only after exceeding the repeated-probing criterion used for this analysis.

GEOGRAPHIC CORRELATION

Request volume across resolved locations.

Bubble area is proportional to recorded requests. Sources resolving to the same approximate location are aggregated so overlapping IPs remain visible.

North Atlantic map of 30 recorded source IPs aggregated into 12 approximate locations, with bubble area proportional to 3,744 recorded requests
IP-derived geography is approximate. Sources without a resolved city are positioned at country level and marked with blue dashed bubbles.