Even malicious servers need a break over the holidays; or is it?
Below was what I observed on the 24th of December 2020, Christmas Eve, a drastic drop in port scan traffic originating from “Russia”.
As you can see in the graph below, port scan traffic was dropping gradually from the 20th to the 23 of December 2020 before that drastic drop on the 24th of December 2020.
Is there any other explanation to the drastic drop in port scan traffic other than being the end-of-year holidays?
The other reason would be ISPs blocking traffic from those IPs due to customer complaints.