Unveiling IPv6 Scanning Dynamics: A Longitudinal Study Using Large Scale Proactive and Passive IPv6 Telescopes

📅 2025-08-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the dynamic nature and traceability challenges of IPv6 scanning in operational ISP networks. We conduct the first large-scale empirical investigation by deploying an active IPv6 telescope integrated with passive traffic monitoring, systematically collecting and analyzing over 600 million unsolicited scan packets across 1,900 autonomous systems. Our methodology innovatively combines IPv6 address-space probing, AS-level mapping, and multi-dimensional protocol-stack feature analysis to empirically infer scanning source address discovery mechanisms and target selection strategies. We identify six characteristic scanning source classes, validate the discriminative power of five core network features, and uncover the target-generation strategies—and their longitudinal evolution—of mainstream scanners (e.g., ZMap, Masscan). These findings establish a critical empirical foundation for IPv6 threat detection, attribution, and defense.

Technology Category

Application Category

📝 Abstract
We introduce new tools and vantage points to develop and integrate proactive techniques to attract IPv6 scan traffic, thus enabling its analysis. By deploying the largest-ever IPv6 proactive telescope in a production ISP network, we collected over 600M packets of unsolicited traffic from 1.9k Autonomous Systems in 10 months. We characterized the sources of unsolicited traffic, evaluated the effectiveness of five major features across the network stack, and inferred scanners' sources of target addresses and their strategies.
Problem

Research questions and friction points this paper is trying to address.

Analyzing IPv6 scan traffic dynamics using proactive telescopes
Characterizing sources of unsolicited IPv6 traffic globally
Evaluating target address strategies of IPv6 scanners
Innovation

Methods, ideas, or system contributions that make the work stand out.

Developed proactive IPv6 scan traffic tools
Deployed largest-ever IPv6 proactive telescope
Analyzed 600M packets from 1.9k ASes
🔎 Similar Papers
No similar papers found.
Hammas Bin Tanveer
Hammas Bin Tanveer
University of Iowa
StarlinkIPv6Internet censorshipNetwork Security
W
Wai Sun Chan
Akamai Technologies/Hong Kong Polytechnic University, Cambridge, United States
Ricky K. P. Mok
Ricky K. P. Mok
CAIDA/UCSD
QoEDASHInternet measurement
S
Sebastian Kappes
Max Planck Institute for Informatics, Saarbrücken, Germany
Philipp Richter
Philipp Richter
Principal Research Scientist at Akamai
Internet Measurement
Oliver Gasser
Oliver Gasser
IPinfo
Internet MeasurementsNetwork SecurityIPv6DNS
J
John Ronan
Walton Institute, South East Technological University, Waterford, Ireland
A
Arthur Berger
Akamai Technologies/MIT, Cambridge, United States
K
kc Claffy
CAIDA, La Jolla, United States