论文标题
在互联网中照亮大规模的IPv6扫描
Illuminating Large-Scale IPv6 Scanning in the Internet
论文作者
论文摘要
虽然扫描IPv4空间无处不在,但如今,对于IPv6 Internet中的扫描活动知之甚少。在这项工作中,我们介绍了一项关于互联网中大规模IPv6扫描行为的纵向和详细的经验研究,该研究基于在约23万个主要内容分布网络(CDN)的大约230,000个主机上捕获的防火墙日志。我们开发了识别IPv6扫描,评估IPv6扫描活动的当前和过去水平的方法,并研究扫描的主要特征,包括扫描仪起源,有针对性的服务以及有关扫描仪如何找到目标IPv6地址的见解。在可能的情况下,我们将我们的发现与可以从公开可用的痕迹中评估的结果进行比较。我们的工作确定并突出了在IPv6 Internet中检测扫描活动的新挑战,并且发现与更知名的IPv4扫描相比,当今对IPv6空间的扫描的特征大不相同。
While scans of the IPv4 space are ubiquitous, today little is known about scanning activity in the IPv6 Internet. In this work, we present a longitudinal and detailed empirical study on large-scale IPv6 scanning behavior in the Internet, based on firewall logs captured at some 230,000 hosts of a major Content Distribution Network (CDN). We develop methods to identify IPv6 scans, assess current and past levels of IPv6 scanning activity, and study dominant characteristics of scans, including scanner origins, targeted services, and insights on how scanners find target IPv6 addresses. Where possible, we compare our findings to what can be assessed from publicly available traces. Our work identifies and highlights new challenges to detect scanning activity in the IPv6 Internet, and uncovers that today's scans of the IPv6 space show widely different characteristics when compared to the more well-known IPv4 scans.