What an IP Reputation Database Actually Contains
Address reputation is often treated as a verdict, as though a database somewhere knows that a given address is bad. What these systems actually hold is a set of observations and classifications, each with a shelf life.
Classification comes before behaviour
The most durable field is what kind of infrastructure an address range belongs to. Ranges are grouped as residential access, mobile carrier, hosting and datacentre, corporate, or educational, based on registry records and routing data.
This classification changes slowly, because it derives from how the range was allocated and who announces it. It is the part of a reputation record that can be trusted for the longest.
It is also the least judgemental part. Knowing that traffic originates from hosting infrastructure tells you the environment, not the intent of whoever is using it.
Behavioural observations are aggregated sightings
On top of classification sit records of what has been seen from that address: failed authentication attempts, requests to known-vulnerable paths, participation in coordinated request patterns, or appearance in abuse reports.
These are counted and decayed over time. An address that generated complaints months ago and nothing since should score differently from one active this morning, and decay functions encode that.
The aggregation is per address or per range rather than per user, so the record describes everything anyone behind that address did. Attribution to an individual is not something the data supports.
Anonymity service labels are a separate axis
Feeds separately flag addresses known to belong to commercial privacy networks, relay services, exit nodes and proxy providers. These labels come from enumeration of published endpoint lists and from behavioural inference.
Such a label is not a statement that traffic is abusive. Large numbers of ordinary people route through privacy services for entirely mundane reasons, including default settings on their devices.
Treating the label as a block reason is a common and costly configuration error, because the resulting false positives fall on privacy-conscious users rather than on determined abuse.
Records age faster than most teams expect
Address allocations move. A range used for hosting can be reassigned to residential broadband, and the historical behaviour recorded against it becomes actively misleading.
Dynamic assignment compounds this at the individual level, since a residential address may serve a different household each week. Behavioural history attached to it decays in accuracy very quickly.
Well-run feeds publish freshness metadata alongside each record so consumers can weight recent observations more heavily. Feeds that expose only a score hide exactly the information needed to use it well.
Reputation belongs in a score, not a gate
Because every field is either coarse or perishable, address reputation works best as one weighted input among many rather than as a standalone decision.
Used that way it is genuinely useful: it explains why an otherwise unremarkable session deserves closer inspection. Used as a gate, it becomes a mechanism for turning away legitimate visitors whose only fault is their network.