论文标题

在黑暗的发现IPv6地址发现和扫描策略中发光

Glowing in the Dark Uncovering IPv6 Address Discovery and Scanning Strategies in the Wild

论文作者

Tanveer, Hammas Bin, Singh, Rachee, Pearce, Paul, Nithyanand, Rishab

论文摘要

在这项工作中,我们确定了Internet上IPv6扫描仪的扫描策略。我们通过进行受控实验来利用大型且未使用的 /56 IPv6子网,对IPv6扫描仪的行为提供了独特的观点。我们通过托管与Internet上与IPv6功能的服务器进行直接或间接联系的应用程序,有选择地使扫描仪可见的子网部分可见。通过仔细的实验​​设计,我们减轻了隐藏变量对发送给我们 /56子网的扫描的影响,并在IPv6主机活动类型和它们引起的扫描仪关注之间建立因果关系。我们表明IPv6主机活动,例如Web浏览,NTP池中的会员资格和TOR网络中的会员资格,会导致扫描仪向我们的子网发送大量的主题IP扫描和反向DNS查询。 DNS扫描仪将其扫描集中在地址空间的狭窄区域,其中我们的应用程序托管了,而IP扫描仪则大致扫描整个子网。即使在我们的子网接收中的主机活动之后,我们也会观察到持续的残留扫描到先前托管应用程序的地址空间的部分

In this work we identify scanning strategies of IPv6 scanners on the Internet. We offer a unique perspective on the behavior of IPv6 scanners by conducting controlled experiments leveraging a large and unused /56 IPv6 subnet. We selectively make parts of the subnet visible to scanners by hosting applications that make direct or indirect contact with IPv6- capable servers on the Internet. By careful experiment design, we mitigate the effects of hidden variables on scans sent to our /56 subnet and establish causal relationships between IPv6 host activity types and the scanner attention they evoke. We show that IPv6 host activities e.g., Web browsing, membership in the NTP pool and Tor network, cause scanners to send a magnitude higher number of unsolicited IP scans and reverse DNS queries to our subnet than before. DNS scanners focus their scans in narrow regions of the address space where our applications are hosted whereas IP scanners broadly scan the entire subnet. Even after the host activity from our subnet subsides, we observe persistent residual scanning to portions of the address space that previously hosted applications

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源