• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

Detecting IPv6 network scan with DNS backscatter

Research Project

Project/Area Number 18H03237
Research Category

Grant-in-Aid for Scientific Research (B)

Allocation TypeSingle-year Grants
Section一般
Review Section Basic Section 60060:Information network-related
Research InstitutionNational Institute of Informatics

Principal Investigator

Fukuda Kensuke  国立情報学研究所, アーキテクチャ科学研究系, 准教授 (90435503)

Project Period (FY) 2018-04-01 – 2021-03-31
Project Status Completed (Fiscal Year 2020)
Budget Amount *help
¥17,160,000 (Direct Cost: ¥13,200,000、Indirect Cost: ¥3,960,000)
Fiscal Year 2020: ¥5,070,000 (Direct Cost: ¥3,900,000、Indirect Cost: ¥1,170,000)
Fiscal Year 2019: ¥5,850,000 (Direct Cost: ¥4,500,000、Indirect Cost: ¥1,350,000)
Fiscal Year 2018: ¥6,240,000 (Direct Cost: ¥4,800,000、Indirect Cost: ¥1,440,000)
Keywordsインターネット / DNS / スキャン / セキュリティ / ネットワークスキャン / バックスキャッター / IPv6
Outline of Final Research Achievements

Full network scans to the IPv4 whole address space are handy and easy due to its address size. However, random scans to IPv6 address space are not feasible and also hard to detect in current passive network sensors. In this work, we design, implement, and evaluate a new framework to detect IPv6 scans, called DNS backscatter. DNS backscatter relies on DNS queries triggered by targets when scanners send scan packets to them. Our results demonstrate that the DNS backscatter can detect network-wide IPv6 scans more effectively than existing techniques (e.g., darknet, backbone traffic analysis).

Academic Significance and Societal Importance of the Research Achievements

本課題では,ネットワーク上で起こるIPv6ネットワークスキャンを中央集権的なDNSへのクエリをルールベースの識別器を用いることで検出する技術を確立した.この技術により,局所的なネットワーク監視をネットワーク中で大規模に行う必要なく,root DNSへのクエリの観測のみから検出できることから,全インターネットで起こりうる大規模ネットワークスキャンを検出することが原理的に可能となった.ネットワーク管理者・運用者は提案手法を用いることで自ネットワークでの異常検出が容易となると期待できる.

Report

(4 results)
  • 2020 Annual Research Report   Final Research Report ( PDF )
  • 2019 Annual Research Report
  • 2018 Annual Research Report
  • Research Products

    (12 results)

All 2020 2019 2018 Other

All Int'l Joint Research (2 results) Journal Article (7 results) (of which Int'l Joint Research: 4 results,  Peer Reviewed: 6 results,  Open Access: 2 results) Presentation (3 results) (of which Int'l Joint Research: 1 results,  Invited: 1 results)

  • [Int'l Joint Research] 南カリフォルニア大学(米国)

    • Related Report
      2019 Annual Research Report
  • [Int'l Joint Research] 南カリフォルニア大学(米国)

    • Related Report
      2018 Annual Research Report
  • [Journal Article] Towards detecting DNSSEC validation failure with passive measurements2020

    • Author(s)
      K.Fukuda, Y.Yoneya, T.Mitamura
    • Journal Title

      Proceedings of IEEE/IFIP ANNET2020

      Volume: 2020 Pages: 1-6

    • DOI

      10.1109/noms47738.2020.9110466

    • Related Report
      2020 Annual Research Report
    • Peer Reviewed
  • [Journal Article] HUMAN - Hierarchical Clustering for Unsupervised Anomaly Detection and Interpretation2020

    • Author(s)
      P.Mulinka, P.Casas, K.Fukuda, L.Kencl
    • Journal Title

      Proceedings of NoF 2020

      Volume: 2020 Pages: 132-140

    • DOI

      10.1109/nof50125.2020.9249194

    • Related Report
      2020 Annual Research Report
    • Peer Reviewed / Int'l Joint Research
  • [Journal Article] WhatsThat? On the Usage of Hierarchical Clustering for Unsupervised Detection & Interpretation of Network Attacks2020

    • Author(s)
      P.Mulinka, K.Fukuda, P.Casas, L.Kencl
    • Journal Title

      Proceedings of IEEE European Symposium on Security and Privacy Workshops

      Volume: 2020 Pages: 574-583

    • DOI

      10.1109/eurospw51379.2020.00084

    • Related Report
      2020 Annual Research Report
    • Peer Reviewed / Int'l Joint Research
  • [Journal Article] Toward Detecting IoT Device Traffic in Transit Networks2020

    • Author(s)
      Guannan Hu and Kensuke Fukuda
    • Journal Title

      Proceedings of ICAIIC2020

      Volume: 0 Pages: 525-530

    • Related Report
      2019 Annual Research Report
    • Peer Reviewed
  • [Journal Article] Who Knocks at the IPv6 Door?: Detecting IPv6 Scanning,2018

    • Author(s)
      K.Fukuda, J.Heidemann
    • Journal Title

      Proceedings of ACM IMC 2018

      Volume: - Pages: 231-237

    • DOI

      10.1145/3278532.3278553

    • Related Report
      2018 Annual Research Report
    • Peer Reviewed / Open Access / Int'l Joint Research
  • [Journal Article] Robust Peer to Peer Mobile Botnet Detection by Using Communication Patterns2018

    • Author(s)
      S.Mongkollusksamee, V.Visoottiviseth, K.Fukuda
    • Journal Title

      Proceedings of AINTEC 2018

      Volume: - Pages: 38-45

    • DOI

      10.1145/3289166.3289172

    • Related Report
      2018 Annual Research Report
    • Peer Reviewed / Open Access / Int'l Joint Research
  • [Journal Article] 大規模IPv6アドレス収集手法の検討2018

    • Author(s)
      新津雄大,小林諭,福田健介,江崎浩
    • Journal Title

      電子情報通信学会 インターネットアーキテクチャ研究会

      Volume: - Pages: 1-8

    • Related Report
      2018 Annual Research Report
  • [Presentation] IPv6エイリアス空間検出を考慮したハニーネットの検討2019

    • Author(s)
      小林日向, 小林諭,福田健介,江崎浩
    • Organizer
      電子情報通信学会インターネットアーキテクチャ研究会
    • Related Report
      2019 Annual Research Report
  • [Presentation] Detecting large-scale network scanners in IPv4/IPv6 networks2019

    • Author(s)
      Kensuke Fukuda
    • Organizer
      Proceedings of FDSE/ACOMP 2019
    • Related Report
      2019 Annual Research Report
    • Int'l Joint Research / Invited
  • [Presentation] Collecting a large number of IPv6 addresses2018

    • Author(s)
      Y.Aratsu, S.Kobayashi, K.Fukuda, H.Esaki
    • Organizer
      Internet Conference 2018
    • Related Report
      2018 Annual Research Report

URL: 

Published: 2018-04-23   Modified: 2022-01-27  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi