Hi Alessandro



On Thu, 30 Jul 2026, 13:57 Alessandro Vesely, <vesely@tana.it> wrote:
On Thu 30/Jul/2026 01:38:48 +0200 denis walker wrote:
> # Article 1: For the purposes of RIPE Address Policy, "Network Abuse" is defined
> by the technical threat classifications maintained under the European Union
> Cybercrime framework (specifically DDoS, malware hosting, phishing networks and
> systemic spam botnet distribution).


Hm...  most automatic abuse reports I send are about dictionary attacks.  They
don't seem to be included in the four categories you mention.  Yet, they are
very common and presumably indicate an 0wned host, so I think it's useful to
report them.  Isn't it?

So maybe: 

Article 1
1.1 For the purposes of RIPE Address Policy, "Network Abuse" is defined, as a base line, by the technical threat classifications maintained under the European Union Cybercrime framework (specifically DDoS, malware hosting, phishing networks and systemic spam botnet distribution).

1.2 The following items are also included: 
- dictionary attacks

This could be updated over time. Or to avoid updating the policy every time a new threat emerges it could refer to a list maintained by the RIPE NCC on behalf of the community. 

Cheers
Denis



Best
Ale
--