POSTER: Two-Phase Scanning in IPv6 - First Observations from a Reactive IPv6 Network Telescope

Publikation: Beitrag in Buch/Konferenzbericht/Sammelband/GutachtenBeitrag in KonferenzbandBeigetragenBegutachtung

Beitragende

Abstract

Scanning is prevalent on the Internet. Researchers, commercial services as well as malicious actors probe the Internet regularly and with high intensity. Stateless TCP SYN scanning has been established as an efficient approach to explore the IPv4 service landscape within minutes. The huge IPv6 address space renders this impossible. In this poster, we analyze 18 months of IPv6 SYN scanning using the reactive network telescope Spoki, which responds to TCP SYN packets. In case of two-phase scans, it engages in TCP handshakes initiated in a second phase. Spoki has been successful in identifying malicious scanning behavior in IPv4 and found a stable share of ≈ 75% irregular TCP SYNs, which typically characterize a first, stateless scanning phase. On the IPv6 Internet, the share of irregular TCP SYNs has not saturated but fluctuates on a 30 days average between 20% and 80%. Fewer scanners return after an irregular SYN and returns happen significantly later than in IPv4, which may indicate larger address traversals that delay the second phase.

Details

OriginalspracheEnglisch
TitelACM SIGCOMM Posters and Demos '25: Proceedings of the ACM SIGCOMM 2025 Posters and Demos
Herausgeber (Verlag)ACM New York, NY, USA
Seiten103-105
Seitenumfang3
ISBN (elektronisch)979-8-4007-2026-0
PublikationsstatusVeröffentlicht - 10 Sept. 2025
Peer-Review-StatusJa

Konferenz

Titel39th annual conference of the ACM Special Interest Group on Data Communication
KurztitelACM SIGCOMM 2025
Veranstaltungsnummer39
Dauer8 - 11 September 2025
Webseite
BekanntheitsgradInternationale Veranstaltung
OrtSão Francisco Convent
StadtCoimbra
LandPortugal

Externe IDs

ORCID /0000-0002-3825-2807/work/192045156
Scopus 105018201471

Schlagworte

Fächergruppen, Lehr- und Forschungsbereiche, Fachgebiete nach Destatis

Ziele für nachhaltige Entwicklung

Schlagwörter

  • Network Telescope, IPv6, Scanners