Scanning the IPv6 Internet: Towards a Comprehensive Hitlist
Scanning the IPv6 Internet: Towards a Comprehensive Hitlist
复制标题
扫描 IPv6 互联网:获取全面的攻击列表
DOI:
10.17487/rfc7217
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
G. Carle
中科院分区:
文献类型:
--
作者:
Oliver Gasser;Quirin Scheitle;S. Gebhard;G. Carle
Active network measurements constitute an impor- tant part in gaining a better understanding of the Internet. Although IPv4-wide scans are now easily possible, random active probing is infeasible in the IPv6 Internet. Therefore, we propose a hybrid approach to generate a hitlist of IPv6 addresses for scanning: First, we extract IPv6 addresses from passive flow data. Second, we leverage publicly available resources such as rDNS data to gather further IPv6 addresses. Third, we conduct traceroute measurements from several vantage points to obtain additional addresses. We perform multiple active measurements on gathered IPv6 addresses and evaluate response rates over time. We extensively compare all IPv6 address sources. In total we found 150M unique IPv6 addresses over the course of four weeks. Our hitlist covers 72% of announced prefixes and 84% of Autonomous Systems. Finally, we give concrete recommendations to maximize source efficiency for different scan types.