arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.21903cs.CRcs.NI

清理NTP池:检测和缓解源自NTP的IPv6扫描

Cleaning the NTP Pool: Detecting and Mitigating NTP-Sourced IPv6 Scanning

Erik Rye, Robert Beverly

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对低功率实体利用NTP池获取IPv6客户端地址进行恶意活动的问题,开发方法识别此类行为及相关实体,通过查询NTP池服务器并监测后续活动,找出不良服务器,推动NTP池运营商和相关公司改进,保障网络安全。

中文摘要 AI 辅助

IPv6客户端地址的短暂性和随机性给依赖互联网范围扫描或侦察的攻击带来了实际挑战,对手必须先找到客户端的IPv6地址。此前有研究表明低功率实体可加入基于志愿者的NTP池获取大量活跃IPv6客户端地址。本文开发了一种方法,不仅能严格识别此类IPv6地址获取行为及相关实体,还能描述这些实体对地址的后续操作。通过用唯一IPv6客户端地址查询全球互联网的所有NTP池服务器,并监测和关联后续针对这些地址的活动,识别出22个NTP池服务器参与了利用收集到的地址进行侦察、端口扫描等活动。之后与NTP池运营商及相关公司沟通,NTP池将系统集成到监测基础设施中移除不良服务器,公司也改变运营政策变得更透明并提供明确退出机制。

英文摘要

The ephemeral and random nature of IPv6 client addresses presents a practical challenge to attacks that depend on Internet-wide scanning or reconnaissance - the adversary must first find the client's IPv6 address. While a well-positioned passive adversary can potentially harvest some active IPv6 client addresses, such power is typically reserved for e.g., large CDNs or Internet exchange points. In contrast, prior work has shown the ease with which a low-power entity can join the volunteer-based NTP Pool and harvest large quantities of active IPv6 client addresses. In this work, we develop a methodology to not only rigorously identify such IPv6 address harvesting and the entities gathering addresses, but also characterize what these entities subsequently do with the addresses. Specifically, we query all NTP Pool servers across the global Internet over the course of one year using unique IPv6 client addresses, and monitor and correlate any later activity targeting these addresses. In sum, we identify 22 NTP Pool servers, within 4 primary clusters, that are part of larger monitoring infrastructures that utilize the gathered addresses for reconnaissance, port scanning, and service and vulnerability enumeration. To better understand the legal and ethical gray area of such behavior, we engage with both the NTP Pool operators and a cybersecurity insurance firm running one of the harvesting and scanning clusters. We are in discussions with the NTP Pool to integrate our system into their monitoring infrastructure to remove such NTP servers, and the cybersecurity insurance firm changed its operational policy to be more transparent and provide clear opt-out mechanisms.

发表机构

  • Johns Hopkins University(约翰斯·霍普金斯大学)
  • San Diego State University(圣地亚哥州立大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑