Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse Zones

Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse Zones
复制标题

DOI:
10.1109/sp.2018.00027
复制
发表时间:
2018-05
期刊:
2018 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Kevin Borgolte;S. Hao;T. Fiebig;Giovanni Vigna
Kevin Borgolte;S. Hao;T. Fiebig;Giovanni Vigna
中科院分区:
其他
文献类型:
--
作者:
Kevin Borgolte;S. Hao;T. Fiebig;Giovanni Vigna

文献摘要

被引文献

相似文献

近年来,安全研究已广泛使用了详尽的互联网扫描,因为它们可以对互联网的整体安全状况提供重大见解,而ZMAP使扫描整个IPv4地址空间实用。但是,IPv4地址空间已经耗尽,并且不可避免的是唯一接受的长期解决方案IPv6的转换。反过来,为了更好地了解连接到Internet的设备的安全性,包括特别是物联网设备,必须在安全评估和扫描中包括IPv6地址。不幸的是,在整个IPv6地址空间中迭代实际上是不可行的,因为它比IPv4地址空间大2^96倍。因此,必须在扫描之前对活动主机进行枚举。没有它,我们将来将无法调查与Internet连接设备的整体安全性。在本文中,我们引入了一种新型技术,通过行走DNSSEC签名的IPv6反向区域来列举IPv6地址空间的活跃部分。随后,通过扫描枚举的地址,我们发现了重大的安全问题:敏感数据的暴露以及对主机的错误控制访问,例如通过管理接口访问路由基础架构,所有这些都可以通过IPV6访问。此外,从我们对通过IPv6和IPv4访问双堆栈主机之间的差异的分析,我们假设根本原因是机器会自动且默认情况下对全球可路由的IPv6地址进行操作。这种做法使受影响的系统管理员似乎不知道,因为各自的服务几乎总是适当地保护通过IPv4未经授权的访问。我们的发现表明(i)列举活动的IPv6主机是实际的,没有违反共同信念的优先网络位置,(ii)目前,Active IPv6主机的安全仍然落后于IPv4主机的安全状态,以及(iii)(iii)(iii)意外的IPv6连接是不知道系统管理员的主要安全问题。
Security research has made extensive use of exhaustive Internet-wide scans over the recent years, as they can provide significant insights into the overall state of security of the Internet, and ZMap made scanning the entire IPv4 address space practical. However, the IPv4 address space is exhausted, and a switch to IPv6, the only accepted long-term solution, is inevitable. In turn, to better understand the security of devices connected to the Internet, including in particular Internet of Things devices, it is imperative to include IPv6 addresses in security evaluations and scans. Unfortunately, it is practically infeasible to iterate through the entire IPv6 address space, as it is 2^96 times larger than the IPv4 address space. Therefore, enumeration of active hosts prior to scanning is necessary. Without it, we will be unable to investigate the overall security of Internet-connected devices in the future. In this paper, we introduce a novel technique to enumerate an active part of the IPv6 address space by walking DNSSEC-signed IPv6 reverse zones. Subsequently, by scanning the enumerated addresses, we uncover significant security problems: the exposure of sensitive data, and incorrectly controlled access to hosts, such as access to routing infrastructure via administrative interfaces, all of which were accessible via IPv6. Furthermore, from our analysis of the differences between accessing dual-stack hosts via IPv6 and IPv4, we hypothesize that the root cause is that machines automatically and by default take on globally routable IPv6 addresses. This is a practice that the affected system administrators appear unaware of, as the respective services are almost always properly protected from unauthorized access via IPv4. Our findings indicate (i) that enumerating active IPv6 hosts is practical without a preferential network position contrary to common belief, (ii) that the security of active IPv6 hosts is currently still lagging behind the security state of IPv4 hosts, and (iii) that unintended IPv6 connectivity is a major security issue for unaware system administrators.