Hi Soda,

I would tend to agree with your statement...and that's how it should work...but...

I think they're looking at it from the perspective that the ISP is responsible :

1. to provide a ' secure ' service

2. in order to provide that ' secure service ' they must ensure against ' malicious traffic on their network '

and...

3. even though they are ' not ' responsible for the problem...they must ensure that their own system is not being a open road relaying the problem to other systems...

Your analogy would be better if you were comparing an ISP with the safety of the ' vehicles ' of the Chicago Transit Authority...which they do have the responsibility to keep safe and secure and well-kept for public transportation....the question would then become :
Does the Chicago Transit Authority have an obligation to it's customers to provide safe vehicles for them to travel on?

Eg