How to research an ASN: ownership, transit, and the space it announces
An AS number is a network's public identity on the internet, and almost everything worth knowing about a network is readable from it: who runs it, what address space it announces, who carries its traffic, and whether any of that has been quietly rearranged. Here is how to read an autonomous system end to end, and which parts to trust.
What an ASN is, and what it is not
An autonomous system is a network that announces its own address space to the rest of the internet over BGP, and an AS number, written AS15169 or just 15169, is the identifier it does that under. It is the closest thing the routing layer has to a company registration: a stable public handle you can hang every other fact on.
What it is not is proof of anything. Anyone who can get an AS number and some address space can announce it, and the name on the registration is typed in by the holder. So the number is where research starts, not where it ends. The value is in reading the several independent views of the same network and noticing where they line up and where they do not.
Identity: who the paperwork says runs it
Start with the registry record. The responsible regional internet registry publishes the holder's name and organisation, the country, the allocation and last-changed dates, and contact and abuse addresses. This is the network's account of itself, and it is worth reading for two things at once: what it says, and how well kept it is.
A serious operator tends to have tidy records, a reachable abuse contact, and a registration whose age matches the story it tells about itself. A network registered last quarter that already announces a scattered collection of unrelated blocks is not doing anything illegal, but it is a different object from a fifteen-year-old ISP, and the registration is the first place that difference shows. Note the allocation date and hold on to it; it will explain things further down.
The space it announces, and reading its quality
Next, what the AS actually announces: how many IPv4 and IPv6 prefixes, and which ones. A large transit network announces thousands, a single-purpose network a handful. The count alone tells you the rough shape; the list tells you the substance.
The more useful view is quality, not quantity. Think of the announced blocks as a grid, one cell per block, coloured by what sampling of the addresses inside has found. Some blocks come back clean, meaning they were checked and nothing turned up. Some come back flagged, meaning anonymity services or high-risk addresses live inside. And a great many come back as neither, because nobody has sampled them, which is its own colour and emphatically not the same as clean.
A network announcing two thousand prefixes will have been sampled in a handful of them. Reading the unsampled majority as clean is the single most common mistake in judging a network's space. Unsampled means unknown; only the checked blocks say anything.
What you are looking for is concentration. A flagged block here and there inside a large eyeball ISP is ordinary. A network most of whose sampled blocks come back flagged is telling you what its space is for, and the registration's tidy net name will not change that.
Transit: upstreams, downstreams, and the shape
Now read the connections, which come in two directions that mean opposite things. Upstreams are the networks seen carrying this one's traffic: its transit providers, the ones it pays or peers with to reach the rest of the internet. Downstreams are the networks seen behind it: its customers. A third bucket holds relationships the data cannot classify either way, and honest tooling keeps it separate rather than guessing.
The shape is the tell. A normal small network has a couple of upstreams and few or no downstreams. A transit provider has many downstreams. What deserves a second look is a young, small network that nonetheless announces a lot of space through a single upstream with no customers of its own: that is the profile of address space being routed for its own sake rather than to serve anyone, and it is worth asking who benefits.
Each relationship also carries a strength, a measure of how firmly it shows up across routing observations. A strong, long-standing upstream is a different fact from a weak one seen once. For a large network the full neighbour list runs to thousands and is paged rather than dumped, but the preview plus the true counts is usually enough to read the shape.
The self-declared half: PeeringDB and exchanges
Alongside what routing observes, there is what the network says about itself in PeeringDB: its type, traffic volume, geographic scope, peering policy, and the internet exchanges it claims to sit on. This is voluntary and self-reported, which makes it useful in a particular way. It is not proof, but it is a statement of intent, and a network that presents itself as a serious operator generally maintains a PeeringDB record and shows up at the exchanges it claims.
Absence is where care is needed. Plenty of entirely legitimate networks never bother with PeeringDB, so an empty record proves nothing on its own. What matters is coherence: a network claiming to be a large regional ISP with no exchange presence and no PeeringDB entry is not lying, exactly, but it is one more thing that does not line up, and research is the business of counting the things that do not line up. Note too that a missing exchange list can simply mean the exchange data was not available for that lookup, which is different from a network that genuinely peers nowhere; good tooling says which it is.
Origin history: what it has announced over time
Everything above is a snapshot. History is where a network's character actually lives, and it is the view no single current record can give you.
For each block, ask which autonomous systems have originated it and between which dates. A network that has held its space steadily for years reads very differently from one whose blocks have rotated through several unrelated origins in a short window. Origin churn is not proof of anything by itself, because legitimate transfers, acquisitions and an operator moving space between its own AS numbers all change the origin. What draws attention is churn with a shape: short holds, several unrelated origins inside a narrow window, or space that goes quiet for years and is suddenly announced again by someone new. That last pattern is worth knowing because dormant space attracts hijackers precisely because nobody is watching it.
Reputation: sampling and analyst labels
Finally, the judgement layer. Two kinds of signal sit on top of the facts, and they carry very different weight.
Sampling evidence is machine observation: what independent feeds found on addresses inside the network's blocks, rolled up to the operator level. It is broad and it is a starting point. Analyst labels are the stronger claim, because a person confirmed them with evidence: a network marked as a proxy provider, bulletproof host, or, at the other end, reviewed and found to be a legitimate operator. A responsible system keeps the two apart, shows a machine's proposal as a proposal until a human rules on it, and lets you see the reasoning rather than only the verdict. When you are attributing abuse or deciding whether to peer, that separation is the difference between a lead and a finding.
A method you can repeat
- Read the registration first, for both what it says and how well kept it is. Keep the allocation date.
- Look at the announced space as quality, not a count. Treat unsampled blocks as unknown, never as clean.
- Read the transit shape. Small and young but announcing a lot through one upstream with no customers is worth a second look.
- Weigh PeeringDB and exchange presence as coherence, not proof. Count what does not line up.
- Read the origin history of the blocks. Churn with a shape, and revived dormant space, are the patterns that matter.
- Take analyst labels as findings and machine sampling as leads, and never confuse the two.
Any AS number mentioned here can be looked up on the front page, which assembles the registration, the announced space, the transit graph, the origin history and the reputation into one report, and names the source and date behind each part.