Lessons Learned from Operating a Large Network Telescope
Alexander Männel, Jonas Mücke, K. C. Claffy, Max Gao, Ricky K. P. Mok, Marcin Nawrocki, Thomas C. Schmidt, Matthias Wählisch
Abstract
Network telescopes (aka darknets) collect unsolicited Internet traffic (aka Internet background radiation or IBR), which includes benign and malicious scanning as well as artifacts of spoofed denial-of-service attacks and misconfigured software and hosts. Analysis of this traffic has revealed macroscopic insights into security-related events and global network dynamics such as outages. Operating a large-scale network telescope is challenging but often taken for granted, more so than in more mature scientific disciplines. We offer the first study documenting our experiences operating the UCSD Network Telescope, the largest and longest-operating network telescope supporting scientific research. We provide background on the history of the telescope, and focus on increasing operational challenges as the underlying network evolves. We develop and apply techniques to leverage third-party scanning activity to validate the integrity of the data, and to discover misconfigurations in the instrumentation. These insights are crucial for understanding measurement results, which we illustrate using concrete examples. We discuss how our findings generalize to support the expanding ecosystem of other passive techniques, such as honeypots, to track security phenomena.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7be6eed2-099b-4d89-82f6-724a09f7c42fCited by top-tier papers1
Ask how each one uses itBuilds on6
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Destination Unreachable: Characterizing Internet Outages and ShutdownsZachary S. Bischof, Kennedy Pitcher, Esteban Carisimo, Amanda Meng et al.SIGCOMM 2023 · 28 citations
- Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan EcosystemMohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce et al.USENIX Security 2018 · 22 citations
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke et al.S&P 2022 · 22 citations
- Spoki: Unveiling a New Wave of Scanners through a Reactive Network TelescopeRaphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti et al.USENIX Security 2022
Related papers
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon et al.NDSS 2017 · 81 citations
- DScope: A Cloud-Native Internet TelescopeEric Pauley, Paul Barford, Patrick D. McDanielUSENIX Security 2023
- CrossCheck: Input Validation for WAN Control SystemsAlexander Krentsel, Rishabh Iyer, Isaac Keslassy, Bharath Modhipalli et al.NSDI 2026 · 2 citations
- IMap: Fast and Scalable In-Network Scanning with Programmable SwitchesGuanyu Li, Menghao Zhang, Cheng Guo, Han Bao et al.NSDI 2022 · 14 citations
- Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured FirewallsQing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian et al.S&P 2025
