DENOG

In the background a close-up, abstract photo of the Essen town hall. The text reads: DENOG 17, 9-11 Nov, Essen. At the bottom is the BENOCS logo.

Next up: DENOG 17 in Essen!

From 9-11 November, Stephan and Péter will join the German network operator community for three days of deep-dive sessions, peering discussions, and plenty of hallway networking.

They’re looking forward to catching up with familiar faces, meeting new ones, and exchanging ideas on traffic visibility, routing analytics, and interconnection efficiency and plenty more.

Peering Asia

In the background a nighttime view of Manila. The text reads: Peering Asia, 4-6 Nov, Maila. At the bottom is the BENOCS logo.

We are proud to be sponsoring Peering Asia 7 next week in Manila!

From 4-6 November, Hari and Stephan will be there connecting with peers from across the Asia-Pacific peering community. Expect plenty of good conversations about interconnection, traffic visibility, and how network analytics can make complex networks easier to understand and manage.

Meet them at the BENOCS booth to talk peering strategies, traffic data insights, and find out the latest BENOCS Analytics updates.

Or even just hit them up for a coffee (or maybe a halo-halo).

See you in Manila!

FCN 2025

Historic building in Hamburg with a clock tower, overlaid with event details for FCN 2025, September 25-26.

Next stop: Hamburg!

On September 25-26, BENOCS CTO Ingmar Poese will be at FCN2025, the Future Computing and Networking Workshop, in Hamburg.

With years of research and hands-on experience in network measurement and traffic analysis, Ingmar is looking forward to diving deep into the technical side of interconnection and traffic visibility.

Expect conversations around topics like ingress point detection, flow-based capacity planning, and how real-time analytics can uncover hidden patterns in IP networks.

If you’re in Hamburg, don’t miss Ingmar at FCN. He’ll be ready to exchange ideas, compare approaches, and discuss how data-driven insights can make networks more efficient and reliable.

Flow-based insights at BalticNOG

Péter presenting at BalticNOG 2025, promoting a session on performance measurement on September 24-25 in Vilnius.

Probes are great for spotting issues at the network edge, but how do you know what their alerts actually mean for the rest of your traffic? And how can you link those warnings back to the exact interconnect point?

At BalticNOG you will find out!

On Tuesday, September 24, at 5:00pm, Péter will share a hands-on example showing you how to:

  • Firmly map probes to their interconnect points.
  • Identify which other traffic flows are likely affected by the same problem.

It’s about turning probe alerts from isolated warnings into actionable insights that help you understand the bigger picture.

If you’re at BalticNOG, don’t miss Peter’s talk, especially if you’re curious about making flow-based monitoring more accurate, efficient, and useful.

BalticNOG

The cityscape of Vilinius at dusk. The text reads: BalticNOG, Sep 24-25, Vilnius. At the bottom the BENOCS logo.

A brand-new event on the map!

On September 24–25, Peter will be in Vilnius for the very first BalticNOG. We’re excited to see this new community form and we can’t wait to be part of the conversations around networks, interconnection, and how analytics can make traffic flows more transparent.

If you’re there, please come say hi. Peter’s looking forward to meeting peers from across the region, sharing ideas, and celebrating this kick-off edition together.

Here’s to a strong start for BalticNOG!

Performance measurement goes Flow at EPF

European Peering Forum promotional graphic with event details: date, location, and speaker Stephan from Benocs.

Ever wondered how a probe’s ‘alert’ footprint really maps to the rest of your network? Ever struggled to connect a quality degradation alert back to the exact interconnect point, and then figure out what else might be affected?

Let’s demystify that.

At EPF25 next week, Stephan will walk us through a clear, practical example of how to:

  • Map each probe precisely to its corresponding interconnect point. No guesswork, just solid mapping.
  • Then, go one step further: identify which other traffic flows are likely tangled up in the same issue.

Whether you’re refining monitoring, speeding up incident response, or just curious about making flow-level visibility actionable, this talk shows you how to turn scattered alerts into coherent, signal-rich insight.

Be sure to also stop by the BENOCS booth while you’re there. Stephan, Péter, Ingmar and Suraj look forward to welcoming you!

RONOG

A Bucharest streetscape in the background. The text reads: RONOG Sep 18, Bucharest. At the bottom the BENOCS logo.

Right after EPF 25, the conversations continue at RONOG 10 in Bucharest! 🇷🇴

On September 18, Péter will be there representing BENOCS and ready to meet the Romanian networking community to exchange thoughts on how traffic visibility and analytics can simplify network operations and improve performance.

Hit Peter up for a coffee and get all the latest updates on the BENOCS product roadmap.

EPF 2025

A grand old building flanked by trees, in the forground a field of blue flowers. The text reads: EPF, Sep 15-17, Bucharest. At the bottom the BENOCS logo.

It’s almost time for European Peering Forum 2025, this year in beautiful Bucharest!

From September 15-17, you can catch Péter, Ingmar, Suraj, and Stephan representing BENOCS at EPF 25. They’re looking forward to connecting with the peering community, diving into the latest on interconnection, and sharing ideas on how visibility into traffic flows can make networks run smoother.

If you’re attending, come find us! We’d love to talk peering strategies, network analytics, or just grab a coffee and catch up.

See you in Bucharest!

NL-ix Late Summer Drink

In the background a pier at the beach with a ferris wheel at the end of it. The text reads: NL-IX Late Summer Drink, Sep 11, Scheveningen. At the bottom is the BENOCS logo.

Sun, sea, and… networking.

On September 11, Hari and Stephan will be at the beach in Scheveningen, for the annual NL-ix Late Summer Drink. Always a great chance to catch up with peers, exchange ideas, and enjoy the unique mix of seaside vibes and serious conversations about networks.

If you’re around, come say hi and join us for a beer. We’d love to chat about traffic visibility, peering, and what’s next for network analytics.

Why Geo-IP data can mislead you and what to use instead

Screenshot of BENOCS Analytics Sankey diagram showing rouer locations

What is a Geo-IP database?

Ever wondered where your network traffic is sourcing from or going to? Many network operators today rely on Geo-IP databases to answer these questions. A geo-IP database is a collection of data that links IP addresses to their corresponding geographic locations. Geo-IP databases usually provide information such as country, region, city, ZIP code, latitude, longitude and sometimes more specific details such as ISP name and also the type of connection (either a DSL or Mobile).

There are several Geo-IP databases available such as MaxmindIP2Location, IPgeolocationIPinfo, Netacuity etc. There is a significant difference of accuracy of a commercial database compared to a free version since the features and the updates that come with it vary greatly depending on the version type.

How is IP to location mapping done?

IP to location mapping is a continuous, multi-source data enrichment process that leverages a combination of methods and data sources to assign geographic identities to IP address ranges. Some of the sources are as follows:

  1. Internet Service Provider (ISP) assignment – ISPs allocate IP addresses to users based on service areas. When an ISP assigns a range of IPs in a specific region, those IPs are mapped to that location in the geolocation database.
  2. Public registry records – Regional Internet Registries (RIRs), such as RIPE NCC, APNIC & LACNIC, maintain records of IP address allocations. These records usually identify which ISPs have been assigned specific IP blocks, often including their registered addresses.
  3. Network routing & topology –  Physical internet infrastructure and routing information help estimate locations. Data about how networks route traffic (such as trace routes) can tell where an IP is likely hosted.
  4. Data mining and user contributions – Some databases leverage information from websites when users voluntarily provide location data e.g. during account registration. This user-input is then associated with their IP addresses for added accuracy.
  5. Active geolocation techniques  Pinging an IP from multiple servers worldwide and using the response times to estimate the user’s physical location. This technique is known as multilateration and this improves accuracy to the city or postal code for some addresses.

When do you use a Geo-IP database?

Geo-IP databases are widely used for web analytics or targeted content/ads. The next time you use a Starbucks W-Fi and get an ad for a store that you just walked past, don’t be surprised. In the telecommunications world, network operators generally use Geo-IP location to optimize and manage their network. Some of the widely known use cases are:

  1. Traffic routing & load balancing Geo-IP data helps direct user traffic through the most efficient or regionally relevant routers and infrastructure, reducing latency and improving service quality.
  2. Capacity planning Understanding where users are densely concentrated enables ISPs to allocate resources, plan infrastructure upgrades and optimize peerings in regions with high demand.
  3. Anomaly detection Rapidly identifying access from unexpected geographies can flag potentially fraudulent account activity or security breaches.
  4. DDoS detection & mitigation Geo-IP can filter or block malicious traffic from specific countries or regions reducing spam and DDoS attacks.
  5. Regulatory compliance ISPs can enforce region-based policies and also fulfil legal obligations regarding customer data storage and access based on end-users’ location.

Limitations of Geo-IP databases

Let’s take the first use case – traffic routing – and look at it more closely. Geo-IP databases work reasonably well when identifying where user traffic originates from and are reliable for country-level detection and broad regional insights. However, some operators also use these databases to correlate flow data with the physical location of subnets within their own network to determine where a specific customer’s traffic is coming from. While operators typically already know where their infrastructure and customer allocations are located based on internal records, that information often lives in separate static inventories that aren’t easily integrated into flow analysis tools. As a result, they turn to Geo-IP data to fill that gap. The problem? Although the accuracy is typically high (90-99%) for country level, it drops down significantly to 43%1 for city level detection. Precision is usually better in large, urbanized areas but considerably worse in small towns or rural regions, and the databases may revert to the nearest major city sometimes missing suburbs or towns. We decided to do a small comparison of our own to run a Berlin IP address lookup on some of these databases to test the accuracy, and the results are striking.

Screenshot of ipgeolocation website
ipgeolocation predicts that the IP is from Bremen some 400km away from Berlin
Screenshot of the ipinfo website
ipinfo is the most accurate of all predicting Berlin and almost the correct district too
Screenshot from the website dbip
dbip predicted the same IP to be from Frankfurt, 550km from Berlin

There are many factors contributing to the inaccuracies. Cellular networks and mobile IPs often have much lower localization accuracy compared to broadband or Wi-Fi. Errors of tens or even hundreds of kilometers2 are common for mobile users. Secondly, the usage of VPN, proxies, carrier grade NAT and very recently Apple Private Relay further obscures the true location, resulting in greater inaccuracies. From our experience in analyzing data from 25+ networks, we often see the same IP block being used across multiple regions or cities because of the frequent change in network topologies, which results in IP block reassignment. The external databases can become outdated quite quickly and the reliability is questionable unless updates are more frequent. Lastly, the privacy regulations may restrict access to certain information, impacting the completeness or refresh rate of data, especially in strict jurisdictions. This makes it risky to rely on Geo-IP for regional-level insights, especially when misclassification can lead to wrong decisions about peering, routing, or capacity planning.

A better alternative: ingress-egress router-based geo-location

Specifically for the routing- and capacity-planning usecases, BENOCS Analytics takes a fundamentally different approach than relying on external Geo-IP databases: we use what your network actually sees.

BENOCS collects and cross-correlates data from standardized network protocols, including BGP, Flow, SNMP, IGP, and DNS, directly from the operator’s infrastructure. Leveraging our proprietary data-processing engine, we visualize this information in an intuitive multi-dimensional Sankey diagram, with up to twelve traffic dimensions, including but not limited to Source, Handover, Ingress, Egress, Nexthop, and Destination dimensions.

Screenshot from the BENOCS website showing the Sankey diagram
Six-dimensional view of the internet traffic ingressing and egressing an operator's network

This visualization allows you to trace the full journey of a packet, from where the traffic is sourcing from (Source AS) to where it terminates (Destination AS) – all grounded in your actual routing and flow data, not approximations.

Flow data is collected at the ingress interface of all internet-facing edge routers. When combined with BGP information, we can infer the forwarding path, including the corresponding egress routers, both of which are displayed within the Sankey’s respective dimensions.

To take it even further, BENOCS enables you to tag and group these routers by city, country, region, or custom groupings, making traffic analysis geographically meaningful and accurate.

Screenshot from BENOCS Analytics showing the Taggin & Grouping feature
Grouping ingress routers by city, region, or vendor

This gives you a precise and actionable view of traffic exchange between locations in your network. You’re not relying on a third-party’s guess: you’re seeing real, topologically and geographically grounded data from your own routers. Why settle for outdated or inaccurate geolocation databases when your network already holds the truth? And also, the geo-location of an IP might be very different than the location of your egress-router, which is the last point your network sees this packet.

Screenshot of BENOCS Analytics Sankey diagram showing rouer locations

When accuracy matters, trust your network

Geo-IP databases offer a convenient, quick-glance view of where traffic might be coming from, and for many applications, that’s good enough. But when you’re a network operator responsible for making high-stakes decisions about traffic engineering, capacity planning, or routing optimization, “good enough” simply isn’t.

As we’ve seen, Geo-IP data can be outdated, inaccurate at city-level, and increasingly unreliable due to VPNs, mobile networks, and evolving topologies. It’s a blunt tool for what should be a precise task.

At BENOCS, we believe that your network already contains the most reliable source of truth. By analyzing real-time BGP, Flow, and IGP data directly from your own routers, we empower you to see not just where your traffic might be coming from but where it actually enters and exits your infrastructure. With this ground-truth visibility, you gain clarity, confidence, and control over your network’s geographic traffic flows – no guesswork required.

So the next time you’re questioning where your traffic comes from, don’t ask a third-party database. Ask your network. It knows.

References:

  1. Should we trust the geolocation databases to geolocate routers- https://blog.apnic.net/2017/11/03/trust-geolocation-databases-geolocate-routers/
  2. Location accuracy of commercial IP address Geolocation Databases- https://itc.ktu.lt/index.php/ITC/article/view/14451