dshield summarizes the top 20 attacking class C (/24) subnets over the last three days. This sounds like many false positives are included. They are not, and this is why:
dshield.org, or better
The Internet Storm Center of SANS Institute, collects firewall and IDS logs from hundreds of thousands of computers around the globe. You can submit yours too! The
dshield IP list includes only the
top 20 class-C, i.e. it always lists 5120 IPs only. The rate of change of these top 20 class-C is so high, that most of them are listed for just 15 mins. Check it. Goto to the
dshield page and take a look on the second chart (the "changes history" chart). Out of the 5120 IPs listed, about 3000 of them expire on every update.
To visualize it even better, check the
dshield_1d list. This one aggregates all IPs listed by
dshield, for 24 hours. Check its unique IPs count. 60k to 120k unique IPs pass through
dshield every day.
So, if it has a so aggressive change rate, is it useful at all? The whole idea of
dshield is to follow the storm as close as possible. And they are doing a great job accomplishing it.