We have been running an experiment last year, From May 2017 to October 2017, to monitor how blacklisted IP addresses used by snort evolve over time. We observed a sharp decrease in the number of blacklisted IPs around 21 June 2017. This is also complemented by our study using suricata IDS. Could anyone suggest, as to what exactly happened around that time which caused this sharp decrease in the no. of blacklisted IP addresses.

City,University of London