Publications

Identifying and differentiating acknowledged scanners in network traffic

Abstract

Acknowledged scanners are Internet scanners which engage with the community as a whole through, at the minimum through a public website. These scanners may provide a service, whether as an education institution, corporation, nonprofit or other organization and may engage in good citizen behaviors such as opt–out lists and by publishing their sources. In this paper, we describe the behavior and population of acknowledged scanners and demonstrate the difference between acknowledged scanners and other (unacknowledged) scanners. We quantitatively show acknowledged scanners, scan from a limited set of addresses, scan predictably, and most importantly the ports (and assumed vulnerabilities) that they scan for differ significantly from the targets of unacknowledged scanners. Failing to differentiate acknowledged and unacknowledged scanners impacts both research and operations, calling into …

Metadata

publication
2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW …, 2023
year
2023
publication date
2023/7/3
authors
M Patrick Collins, Alefiya Hussain, Stephen Schwab
link
https://ieeexplore.ieee.org/abstract/document/10190675/
conference
2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
pages
567-574
publisher
IEEE