6 ms·
Here’s what you find when you scan the entire Internet in an hour
- w_larsen 13y agoreading the article, it might seem that it's some sort of futuristic technology, but it's been used since 2002 (scanrand) the downside of stateless portscanning is that you are trading speed for false negatives.
- danielrhodes 13y agoProbably why it's used as a statistical tool rather than a security tool.
- gruseom 13y agothe downside of stateless portscanning is that you are trading speed for false negatives That's interesting. Could you explain this in a bit more detail? Unless I missed it, the thread from yesterday didn't discuss this.
- groby_b 13y agoSince it's stateless, all info is encoded in the outgoing packet. If the outgoing packet (or the reply to it) is lost, it will look exactly the same as if the server didn't respond - after all, the scanning tool has no local state, and thus can't track if an address has been pinged/re-ping it. The port map is entirely drawn based on incoming packets.
- gruseom 13y agoThanks! I get it now. Good explanation.
- perbu 13y agoI don't know how they progress through the IP space, but couldn't they simply solve this by doing it in a deterministic manner? At progress N they should easily be able to tell that A has been scanned. Iterating three times through the IP space all IPs that haven't answered should have gotten the connection attempts.
- hmsimha 13y agoThat might introduce the same overhead that maintaining state does in the first place. It sounds like they're sending out at least a million requests per second.
- sebcat 13y agoThis can't be stressed enough. It's not all about bandwidth, packet loss is very real.
- fla 13y agointernet != the web
- trstowell 13y agoWhat's the distinction in this context?
- fla 13y agoThe article's title is misleading. It speaks about the web mostly, not the internet (wich you can't scan in an hour btw).
- guard-of-terra 13y agoYou can. You can send an IP packed to every host in the internet and hopefully recieve a reply. That us the internet scanning.
- gargoiler00 13y agoI think he meant scanning all ports, UDP+TCP+ICMP etc etc
- guard-of-terra 13y agoThat's meaningless. That's like claiming you didn't really visit a country until you looked under every trash can.
- fla 13y agoThere is a sweet spot between looking in every trash can and visiting only one of the biggest cities :)
- guard-of-terra 13y agoI'm not sure there is. I'm not sure one can be truly sure he scanned the Internet before impersonating every host. Can't know anything before trying out the inside of every skin. After all, what would you know, as a traveller, about simple lives of local people?
- pbrumm 13y agoThis looks like the code for the project https://github.com/zmap/zmap
- DanBC 13y ago> ZMap is capable of performing a complete scan of the IPv4 address space in under 45 minutes, approaching the theoretical limit of gigabit Ethernet. Are they scanning all ports, or a subset, or just one?
- jnbiche 13y agoJust one in the 45 minutes quoted. It's still impressive.
- andrewljohnson 13y agoThread from yesterday linking to the actual lib: https://news.ycombinator.com/item?id=6226105 https://news.ycombinator.com/item?id=6226105
- dmckeon 13y agoPeople willing to exploit insecure sites may be able to scan faster - legality is a different issue. http://census2012.sourceforge.net/paper.html http://census2012.sourceforge.net/paper.html Starting with one device and assuming a scan speed of ten IP addresses per second, it [the scanner] should find the next open device within one hour. The scan rate would be doubled if we deployed a scanner to the newly found device. ... We did this in the least invasive way possible .... I wonder if/when attaching a widely accessible and easily exploitable device will be considered illegal (attractive nuisance, negligence, public nuisance, contribution to a crime)? To leap to a car analogy, if a driver leaves the keys in a vehicle ignition, and the vehicle is stolen and used to commit some other crime, does the driver face criminal penalties or civil liability? Should a computer vendor or user who neglects to secure their systems or network face penalties or liability? Should external entities do wide scans to encourage better security? I think that a "name and shame" approach aimed at vendors who ship or install insecure-by-default systems could be effective.
- guard-of-terra 13y agoYou should not be criminally liable for something that was merely caused by your actions. http://en.wikipedia.org/wiki/Strict_liability_%28criminal%29 http://en.wikipedia.org/wiki/Strict_liability_%28criminal%29
- UVB-76 13y agoI'd be interested to see how these, apparently rather frequent, port scanning exercises are being factored into 'attempted cyperattack' statistics.
- dsuth 13y agoNew scanning technique shows sharp increase in internet scans!
- jnazario 13y agoreminds me of dscan, originally from about 2003 or so, which itself was built around the time of scanrand. https://github.com/dugsong/dscan https://github.com/dugsong/dscan
- sirsar 13y agoThere's no timezone on the Time of Day chart. Any good guesses?
- goodcanadian 13y agoEastern time. From the article: In any event, the best time to scan the Internet, at least from Michigan, seems to be early in the morning.