Inferring Internet server IPv4 and IPv6 address relationships
MetadataShow full item record
While IPv6 is finally experiencing non-trivial deployment, IPv4 and IPv6 are expected to co-exist for the foreseeable future, implying dual-stacked devices, and protocol interdependence. We develop and deploy a system for characterizing the association between IPv4 and IPv6 addresses ("siblings") within network server infrastructure, with specific forcus on Internet DNS and web servers. We develop two novel techniques for finding DNS resolver sibling groups, one passive and one active. For 674k observed (IPv4, IPv6) address pairs, we find that 34% of the addresses are one-to-one, i.e. appear in no other pair. Yet there are also complex cases, where distributed DNS resolution creates interconnected series of nameserver address pairs that can span continents and autonomous systems, compexity confirmed using active probing. We then describe a targeted method to actively interrogate candidate (IPv4, IPv6) pairs to determine if they are assigned to the same device. We find that the IPv4 and IPv6 addresses of Internet servers frequently belong to different interfaces, machines, and even autonomous systems Our results have important implications on network resilience, security, geolocation and performance measurement.
Showing items related by title, author, creator and subject.
Pitts, James Edward (Monterey, California. Naval Postgraduate School, 1992-12);The end of the Cold War has brought about significant changes in the international and national security environments that present tremendous implications for the U.S. military. The strategic threat of global nuclear war ...
Arthur Berger; Nicholas Weaver; Beverly, Robert; Larry Campbell (2013);The modern Domain Name System (DNS) provides not only resolution, but also enables intelligent client routing, \eg for Content Distribution Networks (CDNs). The adoption of IPv6 presents CDNs the opportunity to utilize ...
Beverly, Robert; Berger, Arthur (2015);We present, validate, and apply an active measurement tech- nique that ascertains whether candidate IPv4 and IPv6 server addresses are “siblings,” i.e., assigned to the same physical machine. In contrast to prior efforts ...