Lune

USENIX ATC2022Top-tier venue

AddrMiner: A Comprehensive Global Active IPv6 Address Discovery System

Guanglei Song, Jiahai Yang, Lin He, Zhiliang Wang, Guo Li, Chenxin Duan, Yaozhong Liu, Zhongxiang Sun

2022Year
55Citations
3Top-tier citations

Abstract

Fast Internet-wide scanning is essential for network situational awareness and asset evaluation. However, the vast IPv6 address space makes brute-force scanning infeasible. Although state-of-the-art techniques have made effective attempts, these methods do not work in seedless regions, while the detection efficiency is low in regions with seeds. Moreover, the constructed hitlists with low coverage cannot truly represent the active IPv6 address landscape of the Internet.

This paper introduces AddrMiner, a systematic and comprehensive global active IPv6 address probing system. We divide the IPv6 address space regions into three kinds according to the number of seed addresses to discover active IPv6 addresses from scratch, from few to many. For the regions with no seeds, we present AddrMiner-N , leveraging an organization association strategy to mine active addresses. It fills the gap of address probing in seedless regions and finds active addresses covering 86.4K IPv6 prefixes announced by BGP, accounting for 81.6% of the probed announced prefixes. For the regions with few seeds, we propose AddrMiner-F , utilizing a similarity matching strategy to probe active addresses further. The hit rate of active address probing is improved by 70%-150% compared to existing algorithms. Moreover, for the regions with sufficient seeds, we present AddrMiner-S to generate target addresses based on reinforcement learning dynamically. It nearly doubles the hit rate compared to the state-of-the-art algorithms. Finally, we deploy AddrMiner and discover 2.1 billion active IPv6 addresses, including 1.7 billion de-aliased active addresses and 0.4 billion aliased addresses, through continuous probing for 13 months. We would like to further open the door of IPv6 measurement studies by publicly releasing AddrMiner and sharing our data.

AddrMiner naturally works in all announced prefix spaces and enables comprehensive active IPv6 address probing in different scenarios by corresponding algorithms to gradually discover active IPv6 addresses from scratch, from few to many.

Contributions. We make the following contributions:

• We present an active IPv6 address probing method, AddrMiner-N . It fills the gap of address probing in the seedless address space regions and discovers active IPv6 addresses covering 86.4K prefixes announced by BGP, accounting for 81.6% of all announced prefixes.

• We propose an active IPv6 address probing method, AddrMiner-F , which can further discover active IPv6 addresses in address space regions with few seeds. It can find 70%-150% more active addresses than AddrMiner-N and the state-of-the-art algorithms.

• We present an efficient active IPv6 address probing method, AddrMiner-S , which can efficiently perform active IPv6 address probing in address space regions with sufficient seeds. Compared with state-of-the-art algorithms, the results show AddrMiner-S improves the hit rate of active addresses from 28.9% to 56.3%.

• We originally design and implement a global active IPv6 address probing system and discover 2.1 billion active IPv6 addresses, including 1.7 billion de-aliased active addresses and 0.4 billion aliased addresses, through continuous running AddrMiner for 13 months. The developed code and continuously probed active addresses are made publicly available at: https://github.com/AddrMiner/AddrMiner

In this section, we briefly introduce the background of IPv6 addresses and discuss the characteristics of IPv6 addresses. IPv6 addresses are 128 bits long. IPv6 unicast addresses consist of a global routing prefix, a local subnet identifier, and an interface identifier (IID). We represent IPv6 addresses in a human-readable text format using eight groups of four hexadecimal characters, each group having 16 bits in total, separated by a colon (":"). We refer to each hexadecimal character (corresponding to the four bits

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers3

Ask how each one uses it

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines