How device misconfiguration drives TCP traffic to parts of 1.0.0.0/8 -- an initial investigation

نویسندگان

  • Mattia Rossi
  • Grenville Armitage
  • Geoff Huston
چکیده

The Internet community is near the ‘bottom of the barrel’ for unallocated IPv4 address prefixes. Network 1.0.0.0/8 was allocated in January 2010 for use on the public Internet, despite being unofficially utilised in various ways for many years. Recent work has revealed this prefix to be quite ‘dirty’, with significant levels of public UDP and TCP traffic already inbound to certain parts of 1.0.0.0/8. By running a simplified honeypot on 1.1.1.0/24 and 1.2.3.0/24 for two days in March 2010 we have elicited new insights into the nature of the TCP traffic polluting these prefixes. Our honeypot replied to inbound TCP SYN packets with a SYN-ACK, thereby eliciting a variety of subsequent response packets from sources actively trying to connect into 1.1.1.0/24 or 1.2.3.0/24 space. By analyzing captured packet payloads, sequences, retransmission patterns and burst rates within such TCP flows, we find that most TCP traffic into these prefixes is caused by some form of misconfiguration rather than malice, and we discuss the possible causes for these misconfigurations.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Formal Semantics and Automated Verification for the Border Gateway Protocol

Traffic is routed across the Internet by Autonomous Systems, or ASes, such as ISPs, corporations, and universities. To route traffic reliably and securely, ASes must configure their Border Gateway Protocol (BGP) routers to implement policies restricting how routing announcements can be used and exchanged with other ASes. It is challenging to correctly implement BGP policies in lowlevel configur...

متن کامل

The Chaotic Nature of TCP Congestion Control

In this paper we demonstrate how TCP congestion control can show chaotic behavior. We demonstrate the major features of chaotic systems in TCP/IP networks with examples. These features include unpredictability, extreme sensitivity to initial conditions and odd periodicity. Previous work has shown the fractal nature of aggregate TCP/IP traffic and one explanation to this phenomenon was that traf...

متن کامل

Control of Multipath TCP and Optimization of Multipath Routing in the Internet

There are moves in the Internet architecture community to add multipath capabilities to TCP, so that end-systems will be able to shift their traffic away from congested parts of the network. We study two problems relating to the design of multipath TCP. (i) We investigate stochastic packet-level behaviour of some proposed multipath congestion control algorithms, and find that they do not behave...

متن کامل

Application of Azolla for 2, 4, 6-Trichlorophenol (TCP) Removal from Aqueous Solutions

Background & Aims of the Study: The 2, 4, 6-Trichlorophenol (TCP) is a phenolic compound which it can produce adverse effects on human and environment. Therefore, the removal of these compounds is necessary. The aim of this study is the investigation of TCP removal by using Azolla filiculoides biomass. Materials & Methods: The Azolla biomass was dried in the sunlight, and...

متن کامل

کارایی زئولیت طبیعی اصلاح شده در حذف 6،4،2 تری کلروفنل از محلول‌های آبی

Abstract Introduction: Many industries such as manufacturers of pesticides, paints and pharmaceutics  produce large amounts of 2,4,6-Trichlorophenol (TCP). Due to its high toxicity and environmental pollution TCP is classified as a leading hazardous compound. The aim of this study was to investigate the TCP removal by using zeolite (clinoptilolite) modified with surfactants from the aqu...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011