Reserved: Dissecting Internet Traffic on Port 0

04/07/2020
by   Aniss Maghsoudlou, et al.
0

Transport protocols use port numbers to allow connection multiplexing on Internet hosts. TCP as well as UDP, the two most widely used transport protocols, have limitations on what constitutes a valid and invalid port number. One example of an invalid port number for these protocols is port 0. In this work, we present preliminary results from analyzing port 0 traffic at a large European IXP. In one week of traffic we find 74GB port 0 traffic. The vast majority of this traffic has both source and destination ports set to 0, suggesting scanning or reconnaissance as its root cause. Our analysis also shows that more than half of all port 0 traffic is targeted to just 18 ASes, whereas more than half of all traffic is originated by about 100 ASes, suggesting a more diverse set of source ASes.

READ FULL TEXT
research
03/24/2021

Zeroing in on Port 0 Traffic in the Wild

Internet services leverage transport protocol port numbers to specify th...
research
01/14/2019

Uncovering Vulnerable Industrial Control Systems from the Internet Core

Industrial control systems (ICS) are managed remotely with the help of d...
research
09/14/2015

Problem of optimization of a transport traffic at preliminary registration of queires with use of CBSMAP-model

The problem of optimization of a transport traffic at preliminary regist...
research
01/16/2018

A First Look at QUIC in the Wild

For the first time since the establishment of TCP and UDP, the Internet ...
research
06/14/2021

From Single Lane to Highways: Analyzing the Adoption of Multipath TCP in the Internet

Multipath TCP (MPTCP) extends traditional TCP to enable simultaneous use...
research
04/08/2019

New Phenomena in Large-Scale Internet Traffic

The Internet is transforming our society, necessitating a quantitative u...

Please sign up or login with your details

Forgot password? Click here to reset