IPv6 hitlist service improves finding targets over 10 years
IPv6 Hitlist Service: Lessons Learned From 10 Years of Operation
Networking and Internet Architecture
Summary
Finding devices on the Internet using IPv6 addresses is harder because there are so many possible addresses. The authors discuss a service that collects known IPv6 addresses to help researchers and engineers find targets more easily. Over 10 years, this service has collected addresses covering most networks that use IPv6 traffic. They studied how well the service reflects real-world use and how different people use the data. The paper shares lessons learned and advice for working with this IPv6 address list.
What this means in practice
- •For network operators: Identify active IPv6 addresses within their networks by comparing against the hitlist to improve monitoring and troubleshooting.
- •For security teams: Use the hitlist data to find responsive IPv6 hosts for security assessments and vulnerability scanning.
Authors
Oliver Gasser, Lion Steger, Patrick Sattler, Johannes Zirngibl
Abstract
After becoming an Internet Draft more than 30 years ago, IPv6 has seen an increase in deployment and use in the past years. As measurements in the IPv6 Internet require new approaches due to the vastly larger address space, hitlists have come along as one possible source for finding IPv6 targets. One of the most prominent hitlists is provided by the IPv6 Hitlist Service. In this paper, we share insights from 10 years of operations of the IPv6 Hitlist Service: We show different evolutions of the service, highlighting important changes along the way. To better understand the representativeness of the hitlist, we perform a coverage analysis using real-world traffic data from a major central European ISP and Tier-1 network, finding that at least one address is known to the IPv6 Hitlist Service for 87.1 % of ASes and 56.5 % of /48 prefixes originating IPv6 traffic. We also share results from a conducted user survey and analyze users accessing the IPv6 Hitlist Service, finding diverse use cases and access patterns across time (e.g., one-off vs. continuous downloads) and available data (e.g., all vs. responsive addresses). Finally, we provide best practice recommendations when working with the hitlist and share lessons learned during its 10-year operation.