Scanning the IPv6 Internet: Towards a Comprehensive Hitlist

Scanning the IPv6 Internet: Towards a Comprehensive Hitlist
复制标题

扫描 IPv6 互联网:获取全面的攻击列表

DOI:
10.17487/rfc7217
复制
发表时间:
2016
期刊:
ArXiv
影响因子:
--
通讯作者:
G. Carle
G. Carle
中科院分区:
--
文献类型:
--
作者:
Oliver Gasser;Quirin Scheitle;S. Gebhard;G. Carle

文献摘要

被引文献

相似文献

主动网络测量是更好地理解互联网的重要组成部分。虽然ipv4范围内的扫描现在很容易实现,但随机主动探测在IPv6互联网上是不可行的。因此,我们提出了一种混合方法来生成用于扫描的IPv6地址列表:首先,我们从被动流量数据中提取IPv6地址。其次,我们利用公开可用的资源,如rDNS数据来收集更多的IPv6地址。第三,我们从几个有利位置进行跟踪路线测量,以获得额外的地址。我们对收集的IPv6地址执行多个主动测量,并评估随时间推移的响应率。我们广泛比较所有IPv6地址源。在四周的时间里,我们总共发现了1.5亿个唯一的IPv6地址。我们的热门列表涵盖了72%的已公布的前缀和84%的自治系统。最后,针对不同的扫描类型,给出了最大化源效率的具体建议。
Active network measurements constitute an impor- tant part in gaining a better understanding of the Internet. Although IPv4-wide scans are now easily possible, random active probing is infeasible in the IPv6 Internet. Therefore, we propose a hybrid approach to generate a hitlist of IPv6 addresses for scanning: First, we extract IPv6 addresses from passive flow data. Second, we leverage publicly available resources such as rDNS data to gather further IPv6 addresses. Third, we conduct traceroute measurements from several vantage points to obtain additional addresses. We perform multiple active measurements on gathered IPv6 addresses and evaluate response rates over time. We extensively compare all IPv6 address sources. In total we found 150M unique IPv6 addresses over the course of four weeks. Our hitlist covers 72% of announced prefixes and 84% of Autonomous Systems. Finally, we give concrete recommendations to maximize source efficiency for different scan types.