dstiles - 9:41 pm on Sep 14, 2013 (gmt 0)
I take a few random IP scans using umit. If x samples return no open ports then it's probably DSL, although occasionally I get a false report for a cloud using this technique. NOTE: A single scan on an IP taken from a "security" log is not conclusive as virus-contaminated IPs usually show open unless the computer has been switched off.
Probably a secondary indication for people in the US is that EU-area DSL machines are usually turned off during your "daylight" hours. Not sure how this applies to china - I'm not that good at time zoneds. :)
I've heard it said that IP scans are evil and anti-social but in my book if someone hits my server with a blockable access then fair game.