Addressless: A New Internet Server Model to Prevent Network Scanning

09/27/2020
by   Shanshan Hao, et al.
0

Eliminating unnecessary exposure is a principle of server security. The huge IPv6 address space enhances security by making scanning infeasible, however, with recent advances of IPv6 scanning technologies, network scanning is again threatening server security. In this paper, we propose a new model named addressless server, which separates the server into an entrance module and a main service module, and assigns an IPv6 prefix instead of an IPv6 address to the main service module. The entrance module generates a legitimate IPv6 address under this prefix by encrypting the client address, so that the client can access the main server on a destination address that is different in each connection. In this way, the model provides isolation to the main server, prevents network scanning, and minimizes exposure. Moreover it provides a novel framework that supports flexible load balancing, high-availability, and other desirable features. The model is simple and does not require any modification to the client or the network. We implement a prototype and experiments show that our model can prevent the main server from being scanned at a slight performance cost.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/19/2020

Network Reconnaissance in IPv6-based Residential Broadband Networks

Network scanning has been a widely used technique to gather information ...
research
08/20/2021

UnSplit: Data-Oblivious Model Inversion, Model Stealing, and Label Inference Attacks Against Split Learning

Training deep neural networks requires large scale data, which often for...
research
03/02/2019

The Architectural Dynamics of Encapsulated Botnet Detection (EDM)

Botnet is one of the numerous attacks ravaging the networking environmen...
research
08/19/2021

Secure Decision Forest Evaluation

Decision forests are classical models to efficiently make decision on co...
research
10/16/2019

Network Scanning and Mapping for IIoT Edge Node Device Security

The amount of connected devices in the industrial environment is growing...
research
12/08/2022

Re-purposing Perceptual Hashing based Client Side Scanning for Physical Surveillance

Content scanning systems employ perceptual hashing algorithms to scan us...
research
11/21/2019

Anonymizing Masses: Practical Light-weight Anonymity at the Network Level

In an era of pervasive online surveillance, Internet users are in need o...

Please sign up or login with your details

Forgot password? Click here to reset