发表机构
Nankai University(南开大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过365天纵向测量暴露的Ollama端点,发现其持久、增长且高度集中,并揭示云基础设施中反复出现的不安全部署实践。
AI 中文摘要
自托管大型语言模型(LLM)服务正成为互联网服务的一个独特类别,但我们对其在公共互联网上的部署如何出现和变化仍知之甚少。我们提出了从2025年2月至2026年2月对暴露的Ollama端点(端口11434)进行的365天纵向测量,结合每日主动探测与GeoIP/ASN富化、PTR和443端口主机观测以及生存分析。在362个观测日和约480万次IP×日观测中,152,137个累计IP中有26.4%仅出现一天;在选定的五个CVE中,仅有0.43%-2.90%的低于修复版本的IP原地升级;前五个国家/地区占加权观测的70%以上;云和托管提供商主导了顶级ASN。这些结果将暴露的Ollama表征为一个结构性暴露面:持久、增长且高度集中。同时,旧版本、常见模型选择、云和托管ASN、PTR类别以及TLS证书模式在全年中仍然可见,表明云基础设施中反复出现的不安全部署实践以及提供商级缓解措施的潜在覆盖范围。
英文摘要
Self-hosted large language model (LLM) serving is emerging as a distinct category of Internet service, but we still know little about how these deployments appear and change on the public Internet. We present a 365-day longitudinal measurement of exposed Ollama endpoints (port 11434) from February 2025 to February 2026, combining daily active probing with GeoIP/ASN enrichment, PTR and port-443 host observations, and survival analysis. Across 362 observation days and approximately 4.8 million IP$\times$day observations, 26.4% of the 152,137 cumulative IPs appear for a single day; across five selected CVEs, only 0.43-2.90% of below-fix IPs upgraded in place; the top five countries/regions account for over 70% of weighted observations; and cloud and hosting providers dominate the top ASNs. These results characterize exposed Ollama as a structural exposure surface: persistent, growing, and heavily concentrated. At the same time, old versions, common model choices, cloud and hosting ASNs, PTR categories, and TLS certificate patterns remain visible across the year, indicating recurring insecure deployment practices in cloud infrastructure and the potential reach of provider-level mitigation.
CommentsAccepted at the 2026 ACM Internet Measurement Conference (IMC 2026), Karlsruhe, Germany, October 12-16, 2026