As I reported in a recent note, I have a program that looks for illicit transit traffic over a given port based on source/destination AS, by analyzing netflow data. Walt Prue