Zeroing in on Port 0 Traffic in the Wild

03/24/2021
by   Aniss Maghsoudlou, et al.
0

Internet services leverage transport protocol port numbers to specify the source and destination application layer protocols. While using port 0 is not allowed in most transport protocols, we see a non-negligible share of traffic using port 0 in the Internet. In this study, we dissect port 0 traffic to infer its possible origins and causes using five complementing flow-level and packet-level datasets. We observe 73 GB of port 0 traffic in one week of IXP traffic, most of which we identify as an artifact of packet fragmentation. In our packet-level datasets, most traffic is originated from a small number of hosts and while most of the packets have no payload, a major fraction of packets containing payload belong to the BitTorrent protocol. Moreover, we find unique traffic patterns commonly seen in scanning. In addition to analyzing passive traces, we also conduct an active measurement campaign to study how different networks react to port 0 traffic. We find an unexpectedly high response rate for TCP port 0 probes in IPv4, with very low response rates with other protocol types. Finally, we will be running continuous port 0 measurements and providing the results to the measurement community.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/07/2020

Reserved: Dissecting Internet Traffic on Port 0

Transport protocols use port numbers to allow connection multiplexing on...
research
08/31/2020

Likelihood-based inference for modelling packet transit from thinned flow summaries

The substantial growth of network traffic speed and volume presents prac...
research
06/25/2021

L, Q, R, and T – Which Spin Bit Cousin Is Here to Stay?

Network operators utilize traffic monitoring to locate and fix faults or...
research
02/13/2020

MUST, SHOULD, DON'T CARE: TCP Conformance in the Wild

Standards govern the SHOULD and MUST requirements for protocol implement...
research
05/08/2023

On Blowback Traffic on the Internet

This paper considers the phenomenon where a single probe to a target gen...
research
01/07/2018

TimeWeaver: Opportunistic One Way Delay Measurement via NTP

One-way delay (OWD) between end hosts has important implications for Int...

Please sign up or login with your details

Forgot password? Click here to reset