Is this the wrong approach? A losing battle of whack-a-mole?
FWIW I get a not-insignificant amount of malicious traffic from AWS, Azure, and Google but I view these providers as "too big to block" - I can't blacklist large swaths of their IP space without breaking the Internet.
ecb_penguin•5h ago
You'll block some legit traffic, but the majority of normal users will not be affected.
What is the persona of your average user? Average people shopping online? None of them are connecting through weird ASNs.
Someone complaining about a VPN being blocked? It's cost-benefit, tell them tough shit.