An IPv6 address fast scanning method based on local domain name association.

IF 3.9 2区 综合性期刊 Q1 MULTIDISCIPLINARY SCIENCES Scientific Reports Pub Date : 2025-04-04 DOI:10.1038/s41598-025-95680-w
Yakai Fang, Liancheng Zhang, Luyang Li, Ce Sun, Yi Guo, Hongtao Zhang, Bin Lin, Jichang Wang, Wenhao Xia
{"title":"An IPv6 address fast scanning method based on local domain name association.","authors":"Yakai Fang, Liancheng Zhang, Luyang Li, Ce Sun, Yi Guo, Hongtao Zhang, Bin Lin, Jichang Wang, Wenhao Xia","doi":"10.1038/s41598-025-95680-w","DOIUrl":null,"url":null,"abstract":"<p><p>With the increase of security issues in IPv6 networks, conducting address scanning in IPv6 networks proves beneficial for identifying potential security risks and vulnerabilities. To enhance the privacy of users' IPv6 addresses, mainstream OS (Operating System) nodes currently employ randomized interface identifiers and temporary IPv6 addresses. Additionally, since most existing IPv6 address scanning methods rely on active scanning, which makes current on-link IPv6 address scanning methods face the challenges of incomplete scan results, poor coverage across different OSs, significant impact on network performance, and the inability to promptly detect subsequently joined hosts. To this end, An IPv6 address fast scanning method based on local domain name association (FScan6), which combines active scanning and passive listening, is proposed. The active scanning module targets different OSs using distinct protocols (Browser and DNS-SD) to obtain local domain names of on-link hosts. Meanwhile, the passive listening module monitors traffic to extract local domain names of on-link hosts. Then, it employs mDNS protocol to retrieve IPv6 addresses associated with these local domain names. A typical on-link IPv6 network environment was constructed, comprising 26 versions of Windows, Apple, and Linux OSs, and FScan6 was compared with 9 IPv6 address scanning methods. The experimental results show that FScan6 outperforms existing IPv6 address scanning methods in terms of OS coverage and scanning result completeness. Specifically, regarding OS coverage, FScan6 successfully detected all IPv6 addresses across 26 different OS versions, which outperformed 9 address scanning tools and scripts by a factor of 2.89 times at most. Regarding scanning result completeness, FScan6 identified up to 54 additional IPv6 addresses at most compared to these tools and scripts. Additionally, FScan6 has a minimal impact on network performance, with the packet loss rate induced by the tool consistently remaining at 0%.</p>","PeriodicalId":21811,"journal":{"name":"Scientific Reports","volume":"15 1","pages":"11524"},"PeriodicalIF":3.9000,"publicationDate":"2025-04-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11968882/pdf/","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Scientific Reports","FirstCategoryId":"103","ListUrlMain":"https://doi.org/10.1038/s41598-025-95680-w","RegionNum":2,"RegionCategory":"综合性期刊","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
引用次数: 0

Abstract

With the increase of security issues in IPv6 networks, conducting address scanning in IPv6 networks proves beneficial for identifying potential security risks and vulnerabilities. To enhance the privacy of users' IPv6 addresses, mainstream OS (Operating System) nodes currently employ randomized interface identifiers and temporary IPv6 addresses. Additionally, since most existing IPv6 address scanning methods rely on active scanning, which makes current on-link IPv6 address scanning methods face the challenges of incomplete scan results, poor coverage across different OSs, significant impact on network performance, and the inability to promptly detect subsequently joined hosts. To this end, An IPv6 address fast scanning method based on local domain name association (FScan6), which combines active scanning and passive listening, is proposed. The active scanning module targets different OSs using distinct protocols (Browser and DNS-SD) to obtain local domain names of on-link hosts. Meanwhile, the passive listening module monitors traffic to extract local domain names of on-link hosts. Then, it employs mDNS protocol to retrieve IPv6 addresses associated with these local domain names. A typical on-link IPv6 network environment was constructed, comprising 26 versions of Windows, Apple, and Linux OSs, and FScan6 was compared with 9 IPv6 address scanning methods. The experimental results show that FScan6 outperforms existing IPv6 address scanning methods in terms of OS coverage and scanning result completeness. Specifically, regarding OS coverage, FScan6 successfully detected all IPv6 addresses across 26 different OS versions, which outperformed 9 address scanning tools and scripts by a factor of 2.89 times at most. Regarding scanning result completeness, FScan6 identified up to 54 additional IPv6 addresses at most compared to these tools and scripts. Additionally, FScan6 has a minimal impact on network performance, with the packet loss rate induced by the tool consistently remaining at 0%.

查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于本地域名关联的 IPv6 地址快速扫描方法。
随着IPv6网络中安全问题的增加,在IPv6网络中进行地址扫描有助于识别潜在的安全风险和漏洞。为了增强用户IPv6地址的隐私性,目前主流OS (Operating System)节点采用随机化接口标识符和临时IPv6地址。此外,由于现有的IPv6地址扫描方法大多依赖于主动扫描,这使得当前的链路上IPv6地址扫描方法面临着扫描结果不完整、跨不同操作系统覆盖率差、对网络性能影响较大以及无法及时检测随后加入的主机等挑战。为此,提出了一种基于本地域名关联的IPv6地址快速扫描方法(FScan6),该方法将主动扫描和被动侦听相结合。主扫描模块针对不同的操作系统,使用不同的协议(浏览器和DNS-SD)获取链路上主机的本地域名。同时,被动侦听模块对流量进行监控,提取链路上主机的本地域名。然后,利用mDNS协议检索与这些本地域名相关联的IPv6地址。构建了典型的非链路IPv6网络环境,包括Windows、Apple和Linux等26个版本的操作系统,并对FScan6与9种IPv6地址扫描方法进行了比较。实验结果表明,FScan6在操作系统覆盖率和扫描结果完整性方面都优于现有的IPv6地址扫描方法。具体来说,关于操作系统的覆盖范围,FScan6成功地检测了26个不同操作系统版本的所有IPv6地址,这比9个地址扫描工具和脚本的性能最高高出2.89倍。关于扫描结果的完整性,与这些工具和脚本相比,FScan6最多识别出54个额外的IPv6地址。此外,FScan6对网络性能的影响最小,该工具引起的丢包率始终保持在0%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Scientific Reports
Scientific Reports Natural Science Disciplines-
CiteScore
7.50
自引率
4.30%
发文量
19567
审稿时长
3.9 months
期刊介绍: We publish original research from all areas of the natural sciences, psychology, medicine and engineering. You can learn more about what we publish by browsing our specific scientific subject areas below or explore Scientific Reports by browsing all articles and collections. Scientific Reports has a 2-year impact factor: 4.380 (2021), and is the 6th most-cited journal in the world, with more than 540,000 citations in 2020 (Clarivate Analytics, 2021). •Engineering Engineering covers all aspects of engineering, technology, and applied science. It plays a crucial role in the development of technologies to address some of the world''s biggest challenges, helping to save lives and improve the way we live. •Physical sciences Physical sciences are those academic disciplines that aim to uncover the underlying laws of nature — often written in the language of mathematics. It is a collective term for areas of study including astronomy, chemistry, materials science and physics. •Earth and environmental sciences Earth and environmental sciences cover all aspects of Earth and planetary science and broadly encompass solid Earth processes, surface and atmospheric dynamics, Earth system history, climate and climate change, marine and freshwater systems, and ecology. It also considers the interactions between humans and these systems. •Biological sciences Biological sciences encompass all the divisions of natural sciences examining various aspects of vital processes. The concept includes anatomy, physiology, cell biology, biochemistry and biophysics, and covers all organisms from microorganisms, animals to plants. •Health sciences The health sciences study health, disease and healthcare. This field of study aims to develop knowledge, interventions and technology for use in healthcare to improve the treatment of patients.
期刊最新文献
Reliable and efficient solar radiation estimation with the insights of XAI. Hydro-mechanical damage modeling of water-bearing sandstone using an energy dissipation approach under triaxial stress. Assessment of content quality and reliability of short videos regarding myocardial infarction on TikTok and BiliBili: a cross-sectional study. Finding natural [Formula: see text] generation zones in Midcontinent Rift in the U.S. by identifying the geophysical signatures of a serpentinization system. Drought tolerance mechanisms across C3 and C3-C4 intermediate photosynthetic types revealed by physiological and gene expression profiling.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1