LZR: Identifying Unexpected Internet Services

01/12/2023
by   Liz Izhikevich, et al.
0

Internet-wide scanning is a commonly used research technique that has helped uncover real-world attacks, find cryptographic weaknesses, and understand both operator and miscreant behavior. Studies that employ scanning have largely assumed that services are hosted on their IANA-assigned ports, overlooking the study of services on unusual ports. In this work, we investigate where Internet services are deployed in practice and evaluate the security posture of services on unexpected ports. We show protocol deployment is more diffuse than previously believed and that protocols run on many additional ports beyond their primary IANA-assigned port. For example, only 3 services run on ports 80 and 443, respectively. Services on non-standard ports are more likely to be insecure, which results in studies dramatically underestimating the security posture of Internet hosts. Building on our observations, we introduce LZR ("Laser"), a system that identifies 99 identifiable unexpected services in five handshakes and dramatically reduces the time needed to perform application-layer scans on ports with few responsive expected services (e.g., 5500 recommendations for future studies.

READ FULL TEXT

page 4

page 8

page 10

page 11

research
03/02/2023

Predicting IPv4 Services Across All Ports

Internet-wide scanning is commonly used to understand the topology and s...
research
10/19/2022

Illuminating Large-Scale IPv6 Scanning in the Internet

While scans of the IPv4 space are ubiquitous, today little is known abou...
research
07/02/2020

Sorry, Shodan is not Enough! Assessing ICS Security via IXP Network Traffic Analysis

Modern Industrial Control Systems (ICSs) allow remote communication thro...
research
09/13/2021

A [in]Segurança dos Sistemas Governamentais Brasileiros: Um Estudo de Caso em Sistemas Web e Redes Abertas

Whereas the world relies on computer systems for providing public servic...
research
03/25/2021

Quantifying the efficacy of childcare services on women employment

Women are set back in the labor market after becoming mother. Intuitivel...
research
08/02/2018

Shepherd: Enabling Automatic and Large-Scale Login Security Studies

More and more parts of the internet are hidden behind a login field. Thi...
research
07/05/2022

Challenges in Adapting ECH in TLS for Privacy Enhancement over the Internet

Security and Privacy are crucial in modern Internet services. Transport ...

Please sign up or login with your details

Forgot password? Click here to reset