I'm setting up a small business that will be providing internet service for a niche market. We'll be offering fully unrestricted and unmonitored (as much as the law allows - and while we'd rather not we will still have the ability to capture packets if justified) internet access, and I am not sure how should we respond to abuse reports (a Google search didn't find anything relevant).
Let's say I get an e-mail about SSH bruteforce coming from one of our customer's IPs. How do I tell whether it's genuine and not a troll (log entries and even .pcaps can be faked)? How do the big ISPs do it (for those that actually care about abuse reports I mean)?
Similarly, complaints about spam e-mail, how do I check whether they're genuine before acting upon them? Is this even a problem? Have there been instances where trolls would report someone for allegedly doing bad stuff in hopes of getting them in trouble with their provider?
Am I condemned to log every single packet leaving my network or is there an industry standard solution that doesn't go to such extremes?
Regards.