首页> 外文会议>IFIP Networking Conference >The Curious Case of Port 0
【24h】

The Curious Case of Port 0

机译:端口0的奇怪案例

获取原文

摘要

In order to direct network traffic towards applications, transport layer protocols such as TCP and UDP add the notion of a port number. A share of these numbers is registered for well-known services such as a web or mail, while some is left to be dynamically assigned by the OS to client connections. A special case is port 0 which is reserved but was never assigned. Traffic from and to port 0 is unusual, because it should not occur in the wild. As port 0 is unassigned, there is no common service listing for connections here. Furthermore, operating systems usually interpret the request to open port 0 as the request to allocate and open any currently unused port. Thus, traffic from and to port 0 should not occur, because no application should listen there and applications cannot send from port 0. In practice, we do however see traffic from and to port 0, which indicates that someone makes the effort to bypass the normal operating system network stack to create these unusual packets. As a corner case of network protocols, the aspect of port 0 has basically never been thoroughly investigated. In this paper, we analyze network traffic collected through a /15 network telescope over a period of 3 years to characterize these curious data flows. We find that port 0 traffic seems to be used in the wild by a select few for a variety of purposes, from DDoS attacks to system fingerprinting, and that some of these actors possess a surprisingly sophisticated knowledge of OS behavior.
机译:为了将网络流量引向应用程序,TCP和UDP等传输层协议增加了端口号的概念。这些号码中的一部分被注册用于诸如Web或邮件之类的众所周知的服务,而其中的一些则由OS动态分配给客户端连接。特殊情况是端口0,该端口已保留但从未分配。往返端口0的流量非常少见,因为它不应在野外发生。由于未分配端口0,因此此处没有用于连接的公共服务列表。此外,操作系统通常将打开端口0的请求解释为分配和打开任何当前未使用的端口的请求。因此,不应发生往返端口0的流量,因为没有应用程序应在该端口侦听并且应用程序无法从端口0发送。但是,实际上,我们确实看到了往返于端口0的流量,这表明有人在努力绕过端口0。正常的操作系统网络堆栈会创建这些异常的数据包。作为网络协议的一个极端案例,端口0的方面基本上从未被彻底研究过。在本文中,我们分析了通过/ 15网络望远镜在3年内收集到的网络流量,以表征这些奇怪的数据流。我们发现,从DDoS攻击到系统指纹识别,少数人似乎在多种目的下广泛使用了端口0流量,并且其中一些行为者具有惊人的OS行为知识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号