Entropy/IP: Uncovering Structure in IPv6 Addresses

06/14/2016
by   Pawel Foremski, et al.
0

In this paper, we introduce Entropy/IP: a system that discovers Internet address structure based on analyses of a subset of IPv6 addresses known to be active, i.e., training data, gleaned by readily available passive and active means. The system is completely automated and employs a combination of information-theoretic and machine learning techniques to probabilistically model IPv6 addresses. We present results showing that our system is effective in exposing structural characteristics of portions of the IPv6 Internet address space populated by active client, service, and router addresses. In addition to visualizing the address structure for exploration, the system uses its models to generate candidate target addresses for scanning. For each of 15 evaluated datasets, we train on 1K addresses and generate 1M candidates for scanning. We achieve some success in 14 datasets, finding up to 40 generated addresses to be active. In 11 of these datasets, we find active network identifiers (e.g., /64 prefixes or `subnets') not seen in training. Thus, we provide the first evidence that it is practical to discover subnets and hosts by scanning probabilistically selected areas of the IPv6 address space not known to contain active hosts a priori.

READ FULL TEXT
research
12/19/2020

Network Reconnaissance in IPv6-based Residential Broadband Networks

Network scanning has been a widely used technique to gather information ...
research
07/18/2018

FRVM: Flexible Random Virtual IP Multiplexing in Software-Defined Networks

Network address shuffling is one of moving target defense (MTD) techniqu...
research
09/19/2022

Rusty Clusters? Dusting an IPv6 Research Foundation

The long-running IPv6 Hitlist service is an important foundation for IPv...
research
08/05/2020

6VecLM: Language Modeling in Vector Space for IPv6 Target Generation

Fast IPv6 scanning is challenging in the field of network measurement as...
research
03/02/2023

Predicting IPv4 Services Across All Ports

Internet-wide scanning is commonly used to understand the topology and s...
research
07/27/2023

IPv6 Hitlists at Scale: Be Careful What You Wish For

Today's network measurements rely heavily on Internet-wide scanning, emp...
research
06/05/2018

Clusters in the Expanse: Understanding and Unbiasing IPv6 Hitlists

Network measurements are an important tool in understanding the Internet...

Please sign up or login with your details

Forgot password? Click here to reset