【24h】

On Reconnaissance with IPv6: A Pattern-Based Scanning Approach

机译:使用IPv6进行侦查:基于模式的扫描方法

获取原文
获取外文期刊封面目录资料

摘要

Today's capability of fast Internet-wide scanning allows insights into the Internet ecosystem, but the on-going transition to the new Internet Protocol version 6 (IPv6) makes the approach of probing all possible addresses infeasible, even at current speeds of more than a million probes per second. As a consequence, the exploitation of frequent patterns has been proposed to reduce the search space. Current patterns are manually crafted and based on educated guesses of administrators. At the time of writing, their adequacy has not yet been evaluated. In this paper, we assess the idea of pattern-based scanning for the first time, and use an experimental set-up in combination with three real-world data sets. In addition, we developed a pattern-based algorithm that automatically discovers patterns in a sample and generates addresses for scanning based on its findings. Our experimental results confirm that pattern-based scanning is a promising approach for IPv6 reconnaissance, but also that currently known patterns are of limited benefit and are outperformed by our new algorithm. Our algorithm not only discovers more addresses, but also finds implicit patterns. Furthermore, it is more adaptable to future changes in IPv6 addressing and harder to mitigate than approaches with manually crafted patterns.
机译:如今,快速的Internet范围内扫描功能可以洞悉Internet生态系统,但是持续过渡到新的Internet协议版本6(IPv6)使探测所有可能的地址的方法变得不可行,即使当前速度超过一百万每秒的探测次数。结果,已经提出了利用频繁模式来减小搜索空间。当前模式是手工制作的,并且基于管理员的有根据的猜测。在撰写本文时,它们的适当性尚未评估。在本文中,我们首次评估了基于模式的扫描的概念,并结合了三个实际数据集使用了实验设置。此外,我们开发了一种基于模式的算法,该算法可自动发现样本中的模式并根据其发现结果生成要扫描的地址。我们的实验结果证实,基于模式的扫描是IPv6侦查的一种有前途的方法,但是,当前已知的模式的益处有限,并且被我们的新算法所超越。我们的算法不仅发现更多地址,而且发现隐式模式。此外,与采用手工模式的方法相比,它更适应IPv6寻址的未来变化,并且更难于缓解。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号