Divide, Predict, Conquer: Adaptive Internet-wide Service Discovery with Limited Seeds
Daguo Cheng, Zedong Jia, Ying Liu, Lin He, Le Gai, Chao He, Jiuzhou Zhang, Chentian Wei, Jiasheng Zhou, Zhaoan Wang, Jinlong E
Abstract
Internet-wide service discovery forms the foundation of Internet situational awareness and security research, yet it faces the challenge of identifying services across massive open ports. Existing methods, which rely heavily on extensive prior knowledge (seeds) and suffer from low efficiency, are limited to specific scenarios with small scales and few service types.To this end, we propose SPADE, an efficient Internet-wide service prediction and discovery method with adaptive and divide-and-conquer characteristics. It acquires limited seeds from target hosts through a multi-level adaptive sampling strategy, then progressively extracts two-tier service deployment features and performs multi-layer predictions in phases. This approach significantly enhances prediction performance while substantially boosting efficiency. Across 12 comparative experiments spanning three-level prediction scenarios and four datasets, SPADE achieves over 94% in both Top-1 hit rate and coverage, significantly outperforming the state-of-the-art methods, especially in scenarios where seeds are limited or even scarce. More notably, it only requires 0.15%-1% of the seeds needed by the state-of-the-art approach to surpass its performance. Furthermore, SPADE achieves a 219-805× speedup in service discovery, completing predictions within 7 minutes across all scenarios and datasets (including hundred-million-scale target hosts), while the state-of-the-art method requires ≥ 22 hours.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Predicting IPv4 services across all portsLiz Izhikevich, Renata Teixeira, Zakir DurumericSIGCOMM 2022 · 30 citations
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 63 citations
- 6Massive: An Efficient IPv6 Large-Scale Target Generation FrameworkShunlong Hao, Liancheng Zhang, Ruosi Cheng, Lanxin Cheng et al.INFOCOM 2026
- 6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningBingnan Hou, Zhiping Cai, Kui Wu, Jinshu Su et al.INFOCOM 2021 · 75 citations
- Spoki: Unveiling a New Wave of Scanners through a Reactive Network TelescopeRaphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti et al.USENIX Security 2022
