Eddy
11
That can explain the difference in being “scanned” often or not. And it is definatly a indication that it is not your ISP doing this. eg the sasser worm is trying to spread itself to ip-addresses which are:
50% are completely random
25% have the same first octet as the IP address of the infected host
25% have the same first and second octet as the IP address of the infected host.
Since your IP changes everytime, you also will see different amounts of “scanning”