Network Reconnaissance in IPv6-based Residential Broadband Networks

12/19/2020
by   Tristan Bruns, et al.
0

Network scanning has been a widely used technique to gather information on the Internet as a whole. The transition from IPv4 to IPv6 causes traditional network scanning to become less useful. An increasing number of hosts is either IPv6-only or not publicly addressable via IPv4 due to the use of NAT, prompting a need for network scanning techniques for the IPv6-based Internet. All current approaches to IPv6 network scanning make use of hitlists (lists of IPv6 addresses to be scanned). A variety of methods for compiling hitlists have been presented, but they have a strong bias towards server hosts, and do not find addresses of client hosts – smartphones, tablets, PCs, 'smart home' devices, etc. – in a significant amount. Client hosts are the majority of devices connected to the Internet. Furthermore, when connected to a residential broadband connection, they can exchange data at substantial speeds, making them attractive targets for botnets. Scanning residential broadband networks is challenging because the active addresses are changing much more frequently than addresses of server hosts. This master's thesis aims to adapt prior IPv6 network scanning techniques to residential broadband networks. To this end, the following contributions are made: Description and evaluation of an IPv6 address space visualization method, Introduction of the NTP Pool Project as a public and passive IPv6 hitlist source detecting mostly client hosts, 'Smart Home' devices and CPEs, Description of a scanning technique for Internet access provider networks, Case study on the three major German residential broadband networks.

READ FULL TEXT

page 17

page 39

page 40

research
06/14/2016

Entropy/IP: Uncovering Structure in IPv6 Addresses

In this paper, we introduce Entropy/IP: a system that discovers Internet...
research
09/27/2020

Addressless: A New Internet Server Model to Prevent Network Scanning

Eliminating unnecessary exposure is a principle of server security. The ...
research
07/27/2023

IPv6 Hitlists at Scale: Be Careful What You Wish For

Today's network measurements rely heavily on Internet-wide scanning, emp...
research
12/08/2022

Re-purposing Perceptual Hashing based Client Side Scanning for Physical Surveillance

Content scanning systems employ perceptual hashing algorithms to scan us...
research
06/23/2020

Classifying Network Vendors at Internet Scale

In this paper, we develop a method to create a large, labeled dataset of...
research
06/28/2021

Automatically Determining a Network Reconnaissance Scope Using Passive Scanning Techniques

The starting point of securing a network is having a concise overview of...
research
12/01/2016

Comparison Between IPv4 to IPv6 Transition Techniques

The IPv4 addresses exhaustion demands a protocol transition from IPv4 to...

Please sign up or login with your details

Forgot password? Click here to reset