
Security teams are seeing more attacker activity from infrastructure that looks ordinary at first glance, including residential internet access, mobile services, cloud servers, and VPN services. With legitimate and malicious traffic moving through the same environments, it’s becoming harder for teams to build detection models around the long-held assumption that risky activity comes from easy-to-identify sources.
For many years, this was an adequate approach to managing internet traffic: Malicious IP addresses, high-risk geographies, Tor exit nodes, hostile autonomous systems, and bulletproof hosting providers gave security teams a way to filter traffic. Reputation feeds, deny lists, and geo-blocking helped SOC teams filter out obvious threats, allowing them to focus on higher-priority activity.
Those filters still have a place. They just can’t carry as much weight as they used to. Attackers can now route activity through infrastructure that looks familiar, trusted, and clean.
A login from a residential ISP may be an employee checking email from home. It may also be a credential stuffing attempt routed through a residential proxy pool. A connection from a major cloud provider may support a normal application workflow. It may also be command-and-control traffic staged inside infrastructure that many organizations allow every day.
Trusted Infrastructure Has Become an Evasion Layer
Attackers focus on residential networks because they are diverse, numerous, and generally difficult to block. Because so many people connect to the internet through residential ISPs, mobile hotspots, shared or public Wi-Fi, and personal devices, including IoT devices, malicious traffic can easily mix with normal traffic. By gaining access to real, changing ISP-provided IP addresses through residential proxy services, attackers can use compromised individual devices or routers as relays for their traffic.
Cloud infrastructures present a similar problem. Organizations use services such as AWS, Azure, Google Cloud, and SaaS solutions to conduct routine operations in these environments. Malicious actors are also using these infrastructures because they can set up cloud infrastructure in minutes and tear it down just as quickly.
Mobile networks introduce additional variability because mobile IPs change constantly, and carrier-grade NATs are simultaneously shared among multiple devices. Location data can also change during normal activity, making rules based on geography or improbable login locations less reliable as users, devices, and routes change throughout the day.
This creates a signal quality issue for the SOC. Analysts need to understand what they’re looking at before they can devote attention and resources to an event. An alert that lacks sufficient context about an at-risk IP address provides little support to the analyst. Without that context, the analyst is left with two poor choices. They can dismiss suspicious traffic as background noise or add broad rules that affect legitimate users and create unnecessary friction.
Automation increases risk because malicious activity can now move much more quickly, with AI tools searching large numbers of potential proxy IP addresses and adjusting apparent locations to match expected usage patterns. Attackers can also change their infrastructure faster than reputation rules can be updated, reducing the value of reputation-based signals.
How Security Teams Can Tell When a Clean IP Is Risky
Traditionally, security teams have focused on whether an IP is bad. However, a more helpful question to ask is: Does the behavior make sense in context?
For example, it may be normal for a residential IP to log in once during business hours, but unusual for that same IP to cycle through thousands of username and password combinations overnight. Similarly, it may be routine for a cloud egress address to access a public API, but if that address shows an automated cadence, unusual session behavior, or signs of unexpected infrastructure changes, it should be viewed with suspicion.
The level of risk depends on the context of the infrastructure’s use. The risk associated with a data center IP can differ significantly from that of a residential proxy exit node, VPN concentrator, or mobile carrier, since each represents a different baseline for how resources are typically accessed. Identity context is also important in determining the level of risk associated with this infrastructure. A normal user logging in from a known device would pose a significantly lower risk than a privileged user accessing sensitive resources from an unknown device.
Session behavior is where different signals about a connection come together. Static IP lookups can miss signals such as sudden ASN changes, unexpected geographic changes, unusual authentication frequency, rapid switching across multiple accounts, and automation-like patterns. A single signal may not be suspicious on its own. But when multiple weak signals are evaluated together, they can reveal a more significant pattern for an investigator to review. This change in how sessions are analyzed depends on high-quality, clean data, stronger enrichment processes, and detection logic that can compare signals.
What Context-Aware Detection Requires
Context-aware detection starts with knowing what’s behind an IP address. Teams need reliable visibility into whether an IP is tied to a VPN, proxy, hosting provider, residential proxy network, mobile carrier, anonymization service, or bot activity. That classification also needs to remain current, as these ecosystems change constantly.
Monitoring the residential proxy market is challenging because services expire, regularly rebrand, rotate downstream IP addresses, and obtain endpoints through various methods. Security teams are already burdened with incident response, investigations, detection tuning, and identity security, making it difficult to maintain accurate, up-to-date records of which type of infrastructure an IP address belongs to.
Teams can bring improved network-origin context into the systems they already use, including SIEMs, fraud detection tools, identity systems, edge protections, and access workflows. This provides teams with greater clarity into user and device locations and helps them make informed decisions without rebuilding their security environment. It also helps reduce user friction. Low-risk sessions will follow normal operations, suspicious sessions will trigger step-up authentication or investigation, and high-risk sessions will be blocked with additional clarity.
Clean Traffic Still Needs Scrutiny
Cybercriminals have adapted their attacks to the way organizations trust the internet. Ordinary-looking infrastructure gives them more time to remain undetected and more room to carry out fraud, account takeover, reconnaissance, and other attacks. Organizations need detection capabilities that reflect how people and systems interact today, with residential, mobile, VPN, SaaS, and cloud environments all part of the standard operating environment.
The question was never really whether an IP address was bad. The question was whether the behavior was legitimate. Clean infrastructure has made that distinction impossible to ignore.
Join our LinkedIn group Information Security Community!











