Address Relay under stress: Attack Characteristics and Measuring Its Effects

I wonder if it’s possible to identify the origin of this spam through the data we have. Have you thought about this or looked into it?

The connectivity-check data might show which source IPs often sent addresses with the newest timestamp?