IPv6 Hitlists at Scale: Be Careful What You Wish For
Erik C. Rye, Dave Levin
摘要
Today's network measurements rely heavily on Internet-wide scanning, employing tools like ZMap that are capable of quickly iterating over the entire IPv4 address space. Unfortunately, IPv6's vast address space poses an existential threat for Internet-wide scans and traditional network measurement techniques. To address this reality, efforts are underway to develop "hitlists" of known-active IPv6 addresses to reduce the search space for would-be scanners. As a result, there is an inexorable push for constructing as large and complete a hitlist as possible.
This paper asks: what are the potential benefits and harms when IPv6 hitlists grow larger? To answer this question, we obtain the largest IPv6 active-address list to date: 7.9 billion addresses, 898 times larger than the current state-of-the-art hitlist. Although our list is not comprehensive, it is a significant step forward and provides a glimpse into the type of analyses possible with more complete hitlists.
We compare our dataset to prior IPv6 hitlists and show both benefits and dangers. The benefits include improved insight into client devices (prior datasets consist primarily of routers), outage detection, IPv6 roll-out, previously unknown aliased networks, and address assignment strategies. The dangers, unfortunately, are severe: we expose widespread instances of addresses that permit user tracking and device geolocation, and a dearth of firewalls in home networks. We discuss ethics and security guidelines to ensure a safe path towards more complete hitlists.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- 6Loda: Pattern Filtering and Ensemble Learning for IPv6 Target Generation and ScanningXikai Sun, Fan Dang, Zihao Yang, Xinqi Jin 等INFOCOM 2025 · 被引用 16 次
- Censys: A Map of Internet Hosts and ServicesZakir Durumeric, Hudson Clark, Jeff Cody, Elliot Cubit 等SIGCOMM 2025 · 被引用 6 次
- Where Have All the Firewalls Gone? Security Consequences of Residential IPv6 TransitionErik Rye, Dave Levin, Robert BeverlyCCS 2026 · 被引用 2 次
- PlanB: Efficient Software IPv6 Lookup with Linearized B+-TreeZhihao Zhang, Lanzheng Liu, Chen Chen, Huiba Li 等NSDI 2026 · 被引用 1 次
- On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly AttacksRobert Beverly, Erik C. RyeNDSS 2026 · 被引用 1 次
它引用的顶会 Paper6
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi 等USENIX Security 2017 · 被引用 163 次
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 被引用 100 次
- 6Forest: An Ensemble Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningTao Yang, Zhiping Cai, Bingnan Hou, Tongqing ZhouINFOCOM 2022 · 被引用 49 次
- Weaponizing Middleboxes for TCP Reflected AmplificationKevin Bock, Abdulrahman Alaraj, Yair Fax, Kyle Hurley 等USENIX Security 2021 · 被引用 49 次
- Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesKevin Borgolte, Shuang Hao, Tobias Fiebig, Giovanni VignaS&P 2018 · 被引用 48 次
相关 Paper
- Search in the Expanse: Towards Active and Global IPv6 HitlistsBingnan Hou, Zhiping Cai, Kui Wu, Tao Yang 等INFOCOM 2023 · 被引用 27 次
- AddrMiner: A Comprehensive Global Active IPv6 Address Discovery SystemGuanglei Song, Jiahai Yang, Lin He, Zhiliang Wang 等USENIX ATC 2022 · 被引用 55 次
- 6Hit: A Reinforcement Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningBingnan Hou, Zhiping Cai, Kui Wu, Jinshu Su 等INFOCOM 2021 · 被引用 75 次
- Cleaning the NTP Pool: Detecting and Mitigating NTP-sourced IPv6 ScanningErik Rye, Robert BeverlyCCS 2026 · 被引用 1 次
- Pruning as Scanning: Towards Internet-Wide IPv6 Network Periphery DiscoveryTao Yang, Ling Hu, Bingnan Hou, Zhenzhong Yang 等INFOCOM 2025 · 被引用 7 次
