Internet Geolocation and Evasion
نویسندگان
چکیده
Internet geolocation technology (IP geolocation) aims to determine the physical (geographic) location of Internet users and devices. It is currently proposed or in use for a wide variety of purposes, including targeted marketing, restricting digital content sales to authorized jurisdictions, and security applications such as reducing credit card fraud. This raises questions about the veracity of claims of accurate and reliable geolocation, and the ability to evade geolocation. We begin with a state-of-the-art survey of IP geolocation techniques and limitations, and examine the specific problems of (1) approximating a physical location from an IP address; and (2) approximating the physical location of an end client requesting content from a web server. In contrast to previous work, we consider also an adversarial model: a knowledgeable adversary seeking to evade geolocation. Our survey serves as the basis from which we examine tactics useful for evasion/circumvention. The adversarial model leads us to also consider the difficulty of (3) extracting the IP address of an end client visiting a server. As a side-result, in exploring the use of proxy servers as an evasionary tactic, to our surprise we found that we were able to extract an end-client IP address even for a browser protected by Tor/Privoxy (designed to anonymize browsing), provided Java is enabled. We expect our work to stimulate further open research and analysis of techniques for accurate and reliable IP geolocation, and also for evasion thereof. Our work is a small step towards a better understanding of what can, and cannot, be reliably hidden or discovered about IP addresses and physical locations of Internet users and machines.
منابع مشابه
On the Evasion of Delay-Based IP Geolocation
We explain a newly found vulnerability that allows circumvention of commonly used delay-based geolocation techniques that use ping or traceroute to sample delays. Attacks may leverage the echo request/reply type of the ICMP protocol. ICMP’s echo request/reply protocol does not specify a mechanism to measure the delays between network nodes. Consequently, different implementations exist on diffe...
متن کاملLeveraging Buffering Delay Estimation for Geolocation of Internet Hosts
Geolocation techniques aim at determining the geographic location of an Internet host based on its IP address. Currently, measurement-based geolocation techniques disregard the buffering delays that may be introduced at each hop along the path taken by probe packets. To fill this gap, we propose the GeoBuD (Geolocation using Buffering Delay estimation) approach. Although the network delay and t...
متن کاملInternet Host Geolocation Based On Probabilistic Latency Models
The robust and scalable growth of the Internet has allowed value added services that provide enhanced user experience. Offering information based on geographic location to Internet users is one of the newest and notable advancements. Finding the geographical location of the user on the Internet, commonly referred to as geolocation, is one of the challenging problems currently addressed by the r...
متن کاملFinding and Analyzing Evil Cities on the Internet
IP Geolocation is used to determine the geographical location of Internet users based on their IP addresses. When it comes to security, most of the traditional geolocation analysis is performed at country level. Since countries usually have many cities/towns of different sizes, it is expected that they behave differently when performing malicious activities. Therefore, in this paper we refine g...
متن کاملNetwork measurement based modeling and optimization for IP geolocation
1389-1286/$ see front matter 2011 Elsevier B.V doi:10.1016/j.comnet.2011.08.011 ⇑ Corresponding author. E-mail addresses: [email protected] (Z. Don edu (R.D.W. Perera), [email protected] (R. Chand stevens.edu (K.P. Subbalakshmi). IP geolocation plays a critical role in location-aware network services and network security applications. Commercially deployed IP geolocation databases may provid...
متن کامل