Aggressive Internet-Wide Scanners: Network Impact and Longitudinal Characterization

05/12/2023
by   Aniket Anand, et al.
0

Aggressive network scanners, i.e., ones with immoderate and persistent behaviors, ubiquitously search the Internet to identify insecure and publicly accessible hosts. These scanners generally lie within two main categories; i) benign research-oriented probers; ii) nefarious actors that forage for vulnerable victims and host exploitation. However, the origins, characteristics and the impact on real networks of these aggressive scanners are not well understood. In this paper, via the vantage point of a large network telescope, we provide an extensive longitudinal empirical analysis of aggressive IPv4 scanners that spans a period of almost two years. Moreover, we examine their network impact using flow and packet data from two academic ISPs. To our surprise, we discover that a non-negligible fraction of packets processed by ISP routers can be attributed to aggressive scanners. Our work aims to raise the network community's awareness for these "heavy hitters", especially the miscreant ones, whose invasive and rigorous behavior i) makes them more likely to succeed in abusing the hosts they target and ii) imposes a network footprint that can be disruptive to critical network services by incurring consequences akin to denial of service attacks.

READ FULL TEXT
research
10/11/2021

Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope

Large-scale Internet scans are a common method to identify victims of a ...
research
04/20/2020

Tracemax: A Novel Single Packet IP Traceback Strategy for Data-Flow Analysis

The identification of the exact path that packets are routed on in the n...
research
03/20/2019

Sundials in the Shade: An Internet-wide Perspective on ICMP Timestamps

ICMP timestamp request and response packets have been standardized for n...
research
08/15/2023

Understanding DNS Query Composition at B-Root

The Domain Name System (DNS) is part of critical internet infrastructure...
research
03/12/2023

On Batching Acknowledgements in C-V2X Services

Cellular Vehicle-to-Everything (C-V2X) is a frontier in the evolution of...
research
02/22/2023

How Ready Is DNS for an IPv6-Only World?

DNS is one of the core building blocks of the Internet. In this paper, w...
research
07/09/2019

ICLab: A Global, Longitudinal Internet Censorship Measurement Platform

Researchers have studied Internet censorship for nearly as long as attem...

Please sign up or login with your details

Forgot password? Click here to reset