While scans of the IPv4 space are ubiquitous, today little is known about scanning activity in the IPv6 Internet. In this work, we present a longitudinal and detailed empirical study on large-scale IPv6 scanning behavior in the Internet, based on firewall logs captured at some 230,000 hosts of a major Content Distribution Network (CDN). We develop methods to identify IPv6 scans, assess current and past levels of IPv6 scanning activity, and study dominant characteristics of scans, including scanner origins, targeted services, and insights on how scanners find target IPv6 addresses. Where possible, we compare our findings to what can be assessed from publicly available traces. Our work identifies and highlights new challenges to detect scanning activity in the IPv6 Internet, and uncovers that today's scans of the IPv6 space show widely different characteristics when compared to the more well-known IPv4 scans.
翻译:虽然对 IPv4 空间的扫描无处不在,但目前对 IPv6 互联网的扫描活动知之甚少。 在这项工作中,我们根据主要内容分发网络(CDN) 约230 000 个主机所采集的防火墙日志,对互联网上的大规模 IPv6 扫描行为进行了纵向和详细的实证研究。 我们开发了识别 IPv6 扫描方法,评估 IPv6 扫描活动的当前和过去水平,并研究扫描的主要特征,包括扫描源头、目标服务,以及扫描器如何找到目标 IPv6 地址的洞察力。 在可能情况下,我们将我们的调查结果与从公开可见的线索中可以评估到的东西进行比较。 我们的工作查明并强调了在检测IPv6 互联网上扫描活动的新挑战,并揭示了今天对 IPv6 空间的扫描与已知的 IPv4 扫描相比,显示出非常不同的特征。