```html ```
top of page

DugganUSA Launches Predictive Puckering: ISP-Level Subnet Blocking at $0/Year

  • Writer: Patrick Duggan
    Patrick Duggan
  • Oct 25, 2025
  • 3 min read

Updated: Aug 11

# DugganUSA Launches Predictive Puckering: ISP-Level Subnet Blocking at $0/Year


**Minneapolis, MN – October 26, 2025** – DugganUSA LLC today announced **Predictive Puckering**, a breakthrough threat intelligence capability that automatically blocks entire /24 subnets when repeat offender ISPs are detected. The system achieved **129× force multiplication** (4 observed malicious IPs → 516 total IPs protected) at **$0 additional cost**.


What We Actually Built (With Real Numbers)



**Traditional Approach:** Block individual malicious IPs as they're discovered

**Predictive Puckering:** Block entire /24 subnets when 2+ IPs from same ISP are malicious


**First Production Run (October 26, 2025 04:20 UTC):**

- Malicious IPs detected: 14 (AbuseIPDB confidence score ≥75%)

- Repeat offender ISPs identified: 2 (TECHOFF SRV LIMITED, 1337 Services GmbH)

- Individual IPs blocked: 4

- Subnets blocked: 2 (/24 ranges = 512 IPs)

- **Total protection: 516 IPs from 4 observed threats**

- **Force multiplication: 129×**

- **Cost: $0** (uses existing Cloudflare IP Lists)


The Technical Implementation



ISP Pattern Detection





Automated Subnet Blocking





Why This Matters



**The Problem:** Malicious actors rotate through IP addresses within their ISP's allocated ranges. Traditional IP blocking plays whack-a-mole.


**Our Solution:** When we see 2+ malicious IPs from the same ISP, we block their entire /24 subnet preemptively.


**Real Impact:**

- TECHOFF operates across 5+ IP addresses (that we've seen)

- Traditional blocking: Block 5 IPs individually

- Predictive Puckering: Block 256+ IPs in one operation

- Next malicious IP from TECHOFF? Already blocked.


Technical Architecture



1. **Threat Intelligence Enrichment**

- Cloudflare Analytics API (visitor IPs)

- AbuseIPDB (abuse confidence scores, ISP attribution)

- VirusTotal (malware correlation)

- Local caching (compliance evidence)


2. **ISP Correlation Engine**

- Automatic ISP name normalization (handles TECHOFF_SRV_LIMITED vs TECHOFF SRV LIMITED)

- Pattern detection threshold: 2+ malicious IPs = repeat offender

- /24 subnet calculation from IP octets


3. **Automated Blocking**

- Cloudflare IP Lists (scales to 1,000 entries per list)

- CIDR notation support (/24 subnets)

- Single firewall rule blocks entire list

- Azure Table Storage (Hall of Shame forensic logging)


What We're NOT Saying



- ❌ "AI-powered" (it's pattern matching and subnet math)

- ❌ "Machine learning" (it's if statements and regular expressions)

- ❌ "Proprietary algorithms" (it's open source in our repo)

- ❌ Pricing withheld (it's literally $0, uses existing Cloudflare)


What We ARE Saying



- ✅ 129× force multiplication measured in production

- ✅ 100% of costs disclosed ($0 incremental)

- ✅ Source code available (enterprise-extraction-platform repo)

- ✅ Live logs published (proof of execution)


Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →

- ✅ 95% confidence cap (we guarantee 5% bullshit exists)


Availability



**Predictive Puckering is live in production** as of October 26, 2025. The system runs automatically every 6 hours or on container startup.


**Who can use this:**

- Anyone with Cloudflare (Free plan supports IP Lists)

- Anyone with AbuseIPDB API access (free tier: 1,000 queries/day)

- Anyone who can run Node.js in a container


**Cost to replicate:**

- Cloudflare: $0/month (Free plan)

- AbuseIPDB: $0/month (free tier sufficient for <1000 visitors/day)

- Azure Container Apps: ~$77/month (or any Docker host)

- **Total: ~$77/month** (vs typical enterprise SIEM: $2.8M/year)


Known Limitations



1. **ISP name variations** - Now normalized, but edge cases exist

2. **False positives possible** - Entire subnet blocked if ISP is compromised

3. **Manual review required** - No automatic unblocking yet

4. **Cloudflare Free plan limits** - 1,000 entries per IP List

5. **95% confidence cap** - We admit uncertainty exists


What's Next



1. **ASN-based blocking** - Block by Autonomous System Number instead of /24

2. **Allowlist support** - Prevent blocking of known-good subnets

3. **Time-based expiration** - Auto-unblock after X days without new reports

4. **Geographic correlation** - Country + ISP patterns for higher precision


About DugganUSA



DugganUSA LLC is a Minnesota-based cybersecurity platform that believes in radical transparency, honest metrics, and $0 threat intelligence. We publish our source code, our costs, and our failures. We cap confidence scores at 95% because we guarantee at least 5% bullshit exists in any complex system.


**Contact:** Patrick Duggan, Founder

**Platform:** www.dugganusa.com

**Cost:** $77/month (everything included)




Appendix: Live Production Logs (October 26, 2025 04:20 UTC)








**Philosophy:** Show your work. Publish your logs. Admit your limitations. Charge honest prices.


**The High Road:** Arctic Wolf feeds a lot of families. We're not competing with them. We're showing what's possible at $77/month with radical transparency.



The cheapest, fastest, most accurate threat feed on the internet.

275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.


Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=dugganusa-launches-predictive-puckering-isp-level-subnet-blocking-at-0-year



 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page