Packed to the Brim: Investigating the Impact of Highly Responsive Prefixes on Internet-wide Measurement Campaigns

Author:

Sattler Patrick1ORCID,Zirngibl Johannes1ORCID,Jonker Mattijs2ORCID,Gasser Oliver3ORCID,Carle Georg1ORCID,Holz Ralph4ORCID

Affiliation:

1. Technical University of Munich, Munich, Germany

2. University of Twente, Enschede, Netherlands

3. Max Planck Institute for Informatics, Saarbrücken, Germany

4. University of Münster, Münster, Netherlands

Abstract

Internet-wide scans are an important tool to evaluate the deployment of services. To enable large-scale application layer scans, a fast, stateless port scan (e.g., using ZMap) is often performed ahead of time to collect responsive targets. It is a common expectation that port scans on the entire IPv4 address space provide a relatively unbiased view as they cover the complete address space. Previous work, however, has found prefixes where all addresses share particular properties. In IPv6, aliased prefixes and fully responsive prefixes, i.e., prefixes where all addresses are responsive, are a well-known phenomenon. However, there is no such in-depth analysis for prefixes with these responsiveness patterns in IPv4. This paper delves into the underlying factors of this phenomenon in the context of IPv4 and evaluates port scans on a total of 161 ports (142 TCP & 19 UDP ports) from three different vantage points. To account for packet loss and other scanning artifacts, we propose the notion of a new category of prefixes, which we call highly responsive prefixes (HRPs). Our findings show that the share of HRPs can make up 70% of responsive addresses on selected ports. Regarding specific ports, we observe that CDNs contribute to the largest fraction of HRPs on TCP/80 and TCP/443, while TCP proxies emerge as the primary cause of HRPs on other ports. Our analysis also reveals that application layer handshakes to targets outside HRPs are, depending on the chosen service, up to three times more likely to be successful compared to handshakes with targets located in HRPs. To improve future scanning campaigns conducted by the research community, we make our study's data publicly available and provide a tool for detecting HRPs. Furthermore, we propose an approach for a more efficient, ethical, and sustainable application layer target selection. We demonstrate that our approach has the potential to reduce the number of TLS handshakes by up to 75% during an Internet-wide scan while successfully obtaining 99 % of all unique certificates.

Funder

Netherlands Organisation for Scientific Research

German Federal Ministry of Education and Research

German Research Foundation

Horizon 2020 Framework Programme

Publisher

Association for Computing Machinery (ACM)

Reference43 articles.

1. Uncovering network tarpits with degreaser

2. Shehar Bano , Philipp Richter , Mobin Javed , Srikanth Sundaresan , Zakir Durumeric , Steven J. Murdoch , Richard Mortier , and Vern Paxson . 2018. Scanning the Internet for Liveness. ACM SIGCOMM Computer Communication Review ( 2018 ). Shehar Bano, Philipp Richter, Mobin Javed, Srikanth Sundaresan, Zakir Durumeric, Steven J. Murdoch, Richard Mortier, and Vern Paxson. 2018. Scanning the Internet for Liveness. ACM SIGCOMM Computer Communication Review (2018).

3. Robert Beverly , William Brinkmeyer , Matthew Luckie , and Justin P . Rohrer . 2013 . IPv6 Alias Resolution via Induced Fragmentation. In Proc. Passive and Active Measurement (PAM) . Robert Beverly, William Brinkmeyer, Matthew Luckie, and Justin P. Rohrer. 2013. IPv6 Alias Resolution via Induced Fragmentation. In Proc. Passive and Active Measurement (PAM).

4. Cloudflare. 2019. It's crowded in here! https://blog.cloudflare.com/its-crowded-in-here/ Cloudflare. 2019. It's crowded in here! https://blog.cloudflare.com/its-crowded-in-here/

5. Cloudflare. 2021. Unbuckling the narrow waist of IP: Addressing Agility for Names and Web Services. https://blog.cloudflare.com/addressing-agility/ Cloudflare. 2021. Unbuckling the narrow waist of IP: Addressing Agility for Names and Web Services. https://blog.cloudflare.com/addressing-agility/

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3