HMap: Efficient Internet-Wide IPv6 Scanning With Dynamic Search

IF 5.4 2区 计算机科学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS
Bingnan Hou;Zhenzhong Yang;Xianzheng Meng;Xiaoyi Wang;Yifan Yang;Ling Hu;Xionglve Li;Zhiping Cai
{"title":"HMap: Efficient Internet-Wide IPv6 Scanning With Dynamic Search","authors":"Bingnan Hou;Zhenzhong Yang;Xianzheng Meng;Xiaoyi Wang;Yifan Yang;Ling Hu;Xionglve Li;Zhiping Cai","doi":"10.1109/TNSM.2026.3664795","DOIUrl":null,"url":null,"abstract":"Internet-wide scanning is integral to network measurement and security analysis, but the expansive address space of IPv6 limits existing approaches in achieving efficient global-scale scans. This study introduces HMap, an innovative IPv6 scanner that markedly improves scan efficiency and coverage through the implementation of a dynamic search (DS) technique, relying solely on IPv6 routeable BGP prefixes. DS employs a dynamic feedback-driven probing strategy that uses information from previous replies to prioritize more promising address regions in subsequent scans. In Internet-wide scans over IPv6, encompassing both ping-like and traceroute-like scans with DS, HMap has demonstrated its capability to discover 2.29 million non-alias active target addresses, 0.13 million peripheries/middleboxes, and 1.61 million router interfaces, using only million-scale probes. This represents a noteworthy improvement of 1.91 times, 1.63 times, and 12.38 times, respectively, compared to current state-of-the-art alternatives. Additionally, by utilizing an efficient target generation algorithm (TGA) that more effectively leverages seed addresses, HMap expands the non-alias active address count to 44.05 million. This coverage spans 18.97 thousand ASes with a one-hour scan at a limited probing speed of 100 Kpps. The volume of active IPv6 addresses is 4.88 times larger than the currently disclosed largest IPv6 hitlists, providing a more diverse set of IPv6 networks. Unlike prior IPv6 scan studies that preclude their use for Internet-scale security analysis, we also conduct the Internet-wide security scans of IPv6 networks, focusing on the exposed internal IPv6 devices and security-sensitive services in IPv6 routers.","PeriodicalId":13423,"journal":{"name":"IEEE Transactions on Network and Service Management","volume":"23 ","pages":"2666-2679"},"PeriodicalIF":5.4000,"publicationDate":"2026-02-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Network and Service Management","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/11397105/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

Internet-wide scanning is integral to network measurement and security analysis, but the expansive address space of IPv6 limits existing approaches in achieving efficient global-scale scans. This study introduces HMap, an innovative IPv6 scanner that markedly improves scan efficiency and coverage through the implementation of a dynamic search (DS) technique, relying solely on IPv6 routeable BGP prefixes. DS employs a dynamic feedback-driven probing strategy that uses information from previous replies to prioritize more promising address regions in subsequent scans. In Internet-wide scans over IPv6, encompassing both ping-like and traceroute-like scans with DS, HMap has demonstrated its capability to discover 2.29 million non-alias active target addresses, 0.13 million peripheries/middleboxes, and 1.61 million router interfaces, using only million-scale probes. This represents a noteworthy improvement of 1.91 times, 1.63 times, and 12.38 times, respectively, compared to current state-of-the-art alternatives. Additionally, by utilizing an efficient target generation algorithm (TGA) that more effectively leverages seed addresses, HMap expands the non-alias active address count to 44.05 million. This coverage spans 18.97 thousand ASes with a one-hour scan at a limited probing speed of 100 Kpps. The volume of active IPv6 addresses is 4.88 times larger than the currently disclosed largest IPv6 hitlists, providing a more diverse set of IPv6 networks. Unlike prior IPv6 scan studies that preclude their use for Internet-scale security analysis, we also conduct the Internet-wide security scans of IPv6 networks, focusing on the exposed internal IPv6 devices and security-sensitive services in IPv6 routers.
HMap:高效的全互联网IPv6扫描与动态搜索
互联网范围的扫描是不可或缺的网络测量和安全分析,但IPv6的广阔的地址空间限制了现有的方法,以实现有效的全球规模的扫描。本研究介绍了HMap,一种创新的IPv6扫描仪,通过实现动态搜索(DS)技术,仅依赖于IPv6路由BGP前缀,显著提高了扫描效率和覆盖范围。DS采用动态反馈驱动的探测策略,该策略使用来自先前回复的信息在后续扫描中优先考虑更有希望的地址区域。在IPv6的互联网范围扫描中,HMap已经证明了它能够发现229万个非别名活动目标地址,13万个外围/中间设备和161万个路由器接口,仅使用百万级探针。与目前最先进的替代品相比,分别提高了1.91倍、1.63倍、12.38倍。此外,通过利用更有效地利用种子地址的高效目标生成算法(TGA), HMap将非别名活动地址数量扩展到4405万。在100 Kpps的有限探测速度下,一小时的扫描覆盖范围为18.97万asa。活跃IPv6地址的数量是目前披露的最大IPv6热门列表的4.88倍,提供了更多样化的IPv6网络集。与之前的IPv6扫描研究不同,我们还对IPv6网络进行了互联网范围的安全扫描,重点关注IPv6路由器中暴露的内部IPv6设备和安全敏感服务。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
IEEE Transactions on Network and Service Management
IEEE Transactions on Network and Service Management Computer Science-Computer Networks and Communications
CiteScore
9.30
自引率
15.10%
发文量
325
期刊介绍: IEEE Transactions on Network and Service Management will publish (online only) peerreviewed archival quality papers that advance the state-of-the-art and practical applications of network and service management. Theoretical research contributions (presenting new concepts and techniques) and applied contributions (reporting on experiences and experiments with actual systems) will be encouraged. These transactions will focus on the key technical issues related to: Management Models, Architectures and Frameworks; Service Provisioning, Reliability and Quality Assurance; Management Functions; Enabling Technologies; Information and Communication Models; Policies; Applications and Case Studies; Emerging Technologies and Standards.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信
小红书