USENIX Security2022Top-tier venue
Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope
Raphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti, Thomas C. Schmidt, Matthias Wählisch
Abstract
Large-scale Internet scans are a common method to identify victims of a specific attack. Stateless scanning like in ZMap has been established as an efficient approach to probing at Internet scale. Stateless scans, however, need a second phase to perform the attack, which remains invisible to network telescopes that only capture the first incoming packet and is not observed as a related event by honeypots. In this work, we examine Internet-wide scan traffic through Spoki, a reactive network telescope operating in real-time that we design and implement. Spoki responds to asynchronous TCP SYN packets and engages in TCP handshakes initiated in the second phase of two-phase scans. Because it is extremely lightweight it scales to large prefixes where it has the unique opportunity to record the first data sequence submitted within the TCP handshake ACK. We analyze two-phase scanners during a three months period using globally deployed Spoki reactive telescopes as well as flow data sets from IXPs and ISPs. We find that a predominant fraction of TCP SYNs on the Internet has irregular characteristics. Our findings also provide a clear signature of today's scans as: (i) highly targeted, (ii) scanning activities notably vary between regional vantage points, and (iii) a significant share originates from malicious sources.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Lessons Learned from Operating a Large Network TelescopeAlexander Männel, Jonas Mücke, K. C. Claffy, Max Gao et al.SIGCOMM 2025 · 9 citations
- Censys: A Map of Internet Hosts and ServicesZakir Durumeric, Hudson Clark, Jeff Cody, Elliot Cubit et al.SIGCOMM 2025 · 6 citations
- Cleaning the NTP Pool: Detecting and Mitigating NTP-sourced IPv6 ScanningErik Rye, Robert BeverlyCCS 2026 · 1 citation
- DScope: A Cloud-Native Internet TelescopeEric Pauley, Paul Barford, Patrick D. McDanielUSENIX Security 2023
- MORP4: A Dynamic Network TelescopeIliana Xygkou, Jithin Kallukalam Sojan, Dhruv Rauthan, Feng Zhu et al.NSDI 2026
Builds on3
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 63 citations
Related papers
- Detecting Probe-resistant ProxiesSergey Frolov, Jack Wampler, Eric WustrowNDSS 2020
- Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the WildHammas Bin Tanveer, Rachee Singh, Paul Pearce, Rishab NithyanandUSENIX Security 2023
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon et al.NDSS 2017 · 81 citations
- SymTCP: Eluding Stateful Deep Packet Inspection with Automated Discrepancy DiscoveryZhongjie Wang, Shitong Zhu, Yue Cao, Zhiyun Qian et al.NDSS 2020
- Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesKevin Borgolte, Shuang Hao, Tobias Fiebig, Giovanni VignaS&P 2018 · 48 citations
