Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
My website gets more attacks than human visitors
3 points by tommy2970 13 hours ago | hide | past | favorite | 2 comments
I run a small self-hosted website on a Raspberry Pi 4B at home. A few weeks ago I started wondering: who actually visits a website in 2026? Not just humans. Everything. So I built a public observability dashboard on top of GoAccess that separates traffic into four categories: human visitors, search engine crawlers, AI retrieval agents, and automated attacks. The numbers from the last 17 days surprised me:

4,523 human visits 6,409 automated attack attempts Thousands of crawler requests from search engines and AI systems

The attacks aren't sophisticated. They're mostly automated scanners probing for .env files, WordPress admin panels, and cloud credentials — hitting every public IP on the internet regardless of what's actually running there. What I found more interesting was the AI agent behavior. AI retrieval agents (GPTBot, ClaudeBot, PerplexityBot, Amazonbot) behave differently from traditional search crawlers. They hit semantic files aggressively — llms.txt, sitemap.xml, JSON-LD structured data — and seem to index the knowledge graph structure of a site rather than individual pages. Within hours of publishing new content, multiple AI crawlers had already visited, apparently triggered by the sitemap update rather than any external link. A few observations I didn't expect:

Combined machine traffic consistently exceeds human traffic AI agents discovered new content faster than Google did The semantic structure exposed by the site seems almost as important as the content itself Even a Pi on a residential ISP receives constant automated scans (380+ attempts/day average)

I made the dashboard public because I think the machine side of the web is underobserved. The modern web feels less like "users visiting pages" and more like a parallel ecosystem of crawlers, AI agents, and automated systems running continuously alongside human visitors.

Two questions for HN: Are others tracking AI agents separately from traditional search crawlers? Has anyone else noticed AI retrieval systems indexing semantic structure (JSON-LD, llms.txt) faster than they index page content?

 help



I thought about tracking all this stuff for my personal server, then realized that I wouldn't bother doing anything with the knowledge anyway.

I'm curious if you're just tracking browser user agent, fingerprinting or some other method? For instance would someone using a tool to spider your site, would it be classed as an attack?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: