Couldn't find much information about that visualisation, so I have to wonder - what kind of traffic do they count? Is it only showing detected known/assumed attacks? Or does it count all connections? (i.e. does it include scans, or not)<p>If it includes scans - I'm surprised how few there are. (that's about as many as you'd get on 5 randomly created VMs) If it doesn't - I'm surprised how many active attacks there are.