Abuse reporting based on whois

If the source ips are spoofed, what purpose do they do other than
consume bandwidth.

I believe the senders are script kiddies probing for know ports that
backdoors, spyware or Trojans are know to use.

> My ipfilter firewall is blocking  35 to 150 un-solicited inbound
> port packets per minute coming from all over the world. I have an
> dynamic IP address assigned by my ISP, so I know the senders are
> scanning an whole subnet range of IP address for the ports they
> interested in.  I have to pay for this background packet noise in
> bandwidth usage surcharges.  I decided to research and try to
> an process to report this abuse to the ISP's who own the source IP
> address that is scanning the whole subnet ranges of IP address I
> belong to.

A significant part of those scans have spoofed source addresses.
Unless you complete a three-way handshake (for TCP scans only, of
course) and thus validate the source address, your observations are
probably not worth reporting.

