Skip to content

Autonomous System

AS22

Last fetched

AS22 is operated by DNIC-AS-00022 - Navy Network Information Center (NNIC), registered in US, and announces 7 prefixes to 1 BGP neighbour. AS22 has a reputation score of 13.4 (NEUTRAL); 1 of its 139,520 announced IPv4 addresses appear on threat feeds.

Nutrition Label

WHISPER CANON · AS22Routing diversity4.5/10Peering density1.2/10MOAS conflict✓ noneThreat-feed listings—WHOIS transparency—Resolver footprint—canon.whisper.security/asn/22

Routing footprint

Announced prefixes
7
BGP neighbours
1
RPKI ROAs
0
MOAS conflicts
0
CAIDA AS-rank
13,260
Customer-cone ASNs
1
Facilities
0
Internet exchanges
0
Customer degree
0
Peer degree
0
Provider degree
1

Upstreams

The networks that most often share an observed BGP path with AS22.

Blast radius

Announced IPv4 addresses
139,520
Threat-listed addresses
1
Threat density
0.0007 %
Routed prefixes
5

How much of the internet this network is responsible for, and how much of that address space currently appears on a threat feed. Coverage: computed.

Peering ecosystem

A sample of 1 of this network’s 1 BGP neighbours.

Reputation

13.4reputation score (NEUTRAL)

AS22 (DNIC-AS-00022 - Navy Network Information Center (NNIC), US) has a reputation score of 63.3 (NEUTRAL).

Threat density
90.0/100
Graph metrics
30.0/100
Historical behaviour
85.0/100
Prefix age
20.0/100

These are reputation signals about the network as a whole, not a threat-feed verdict about a specific address.

Registration

RIR
ARIN
Registered
Mon, 30 Jul 1984 04:00:00 GMT

This is the abuse contact WhisperGraph holds for the network.

Threat-feed evidence

Related pages

Pivot from AS22 into the prefixes, peers and country it routes for.

Queries

This ASN's full card — routing footprint, peers, conflicts and RIR facts.


MATCH (a:ASN {name: $asn})
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (a)-[:HAS_COUNTRY]->(co:COUNTRY)
OPTIONAL MATCH (a)-[:REGISTERED_BY]->(org:ORGANIZATION)
WITH a,
     collect(an.name) AS operatorNames,
     collect(co.name) AS countries,
     collect(org.name) AS organizations
OPTIONAL MATCH (a)-[:ROUTES]->(prefix:ANNOUNCED_PREFIX)
WITH a, operatorNames, countries, organizations,
     collect(prefix.name)[0..25] AS samplePrefixes
OPTIONAL MATCH (a)-[:BGP_NEIGHBOR]-(peer:ASN)
OPTIONAL MATCH (peer)-[:HAS_NAME]->(peern:ASN_NAME)
WITH a, operatorNames, countries, organizations, samplePrefixes,
     collect({asn: peer.name, operator: peern.name})[0..25] AS samplePeers
OPTIONAL MATCH (a)<-[:CONFLICTS_WITH]-(conflict:ANNOUNCED_PREFIX)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers,
     collect(conflict.name)[0..25] AS sampleConflicts
OPTIONAL MATCH (a)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts,
     collect(DISTINCT sig.name) AS signals
OPTIONAL MATCH (a)-[:IX_MEMBER]->(ix:INTERNET_EXCHANGE)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals,
     collect({id: ix.id, name: ix.name})[0..25] AS sampleExchanges
OPTIONAL MATCH (a)-[:AS_PRESENT_AT]->(fac:FACILITY)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals, sampleExchanges,
     collect({id: fac.id, name: fac.name})[0..25] AS sampleFacilities
OPTIONAL MATCH (roa:ROA)-[:ROA_AUTHORIZES_ORIGIN]->(a)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals, sampleExchanges, sampleFacilities,
     collect({prefix: roa.prefix, maxLength: roa.maxLength})[0..10] AS sampleRoas
CALL { WITH a MATCH (a)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS prefixCount }
CALL { WITH a MATCH (a)-[:BGP_NEIGHBOR]-(n:ASN) RETURN count(n) AS peerCount }
CALL { WITH a MATCH (a)<-[:CONFLICTS_WITH]-(c:ANNOUNCED_PREFIX) RETURN count(c) AS conflictCount }
CALL { WITH a MATCH (a)-[:ROA_AUTHORIZES_ORIGIN]-(r:ROA) RETURN count(r) AS roaCount }
CALL { WITH a MATCH (a)-[:AS_PRESENT_AT]->(f:FACILITY) RETURN count(f) AS facilityCount }
CALL { WITH a MATCH (a)-[:IX_MEMBER]->(x:INTERNET_EXCHANGE) RETURN count(x) AS ixpCount }
RETURN a.name AS name,
       a.rir AS rir,
       a.orgName AS orgName,
       a.asRank AS asRank,
       a.coneAsns AS coneAsns,
       a.conePrefixes AS conePrefixes,
       a.coneAddresses AS coneAddresses,
       a.registrationDate AS registrationDate,
       a.reputationScore AS reputationScore,
       a.reputationCategory AS reputationCategory,
       a.overallThreatLevel AS overallThreatLevel,
       a.abuseEmail AS abuseEmail,
       a.hijackPostureScore AS hijackPostureScore,
       a.hijackOriginMismatchCount AS hijackOriginMismatchCount,
       a.routeLeakCount AS routeLeakCount,
       a.routeLeakTypes AS routeLeakTypes,
       a.degreeCustomer AS degreeCustomer,
       a.degreePeer AS degreePeer,
       a.degreeProvider AS degreeProvider,
       operatorNames, countries, organizations,
       samplePrefixes, samplePeers, sampleConflicts,
       signals, sampleExchanges, sampleFacilities, sampleRoas,
       prefixCount, peerCount, conflictCount, roaCount, facilityCount, ixpCount
Run yourself →

The five networks that most often share this ASN's observed BGP paths.


MATCH (a:ASN {name: $asn})<-[:BGP_PATH]-(b:BGP_PATH_OBSERVATION)
WITH b LIMIT 200
MATCH (b)-[:BGP_PATH]->(up:ASN)
WHERE up.name <> $asn
WITH up.name AS asn, count(*) AS observations
ORDER BY observations DESC
LIMIT 5
RETURN asn, observations
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.