News: 1595316544

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Networking boffins detect wide abuse of IPv4 addresses bought on secondary market

(2020/07/21)


Malicious actors are abusing the secondary market for IPv4 addresses, according to Lancaster University lecturer [1]Vasileios Giotsas , University College London research and teaching assistant and postdoctoral fellow Ioana Livadariu from Norway's Simula Metropolitan Center for Digital Engineering.

In a recent paper titled [2]A first look at the misuse and abuse of the IPv4 Transfer Market [PDF], the three explain how IP address depletion saw regional internet registries establish transfer markets for the increasingly-hard-to-find IPv4 addresses.

“However, the IPv4 market has been poorly regulated due to the lack of widely adopted IP prefix ownership authentication mechanisms, inconsistent contractual requirements between legacy and allocated address space, and policy incongruences among Regional Internet Registries (RIRs),” the trio wrote. “As a result, IPv4 transfers have become target of fraud and abuse by malefactors who try to bypass legal IP ownership processes.”

Those who abuse the process do things like using “clean” IP addresses from which to host botnets or fraudulent sites.

The authors explain that he was able to access data about address transfers from internet registries, map the address ranges against known autonomous system numbers (AS numbers), correlate all of that with border gateway protocol activity and eventually create a picture of what happens to IPv4 addresses after they are bought and sold.

The paper's conclusions are not pretty: “We find that for more than 65 percent of the IP transfers, the origin ASes and the transaction dates appear to be inconsistent with the transfer reports, while six percent of Route Origin Authorizations (ROAs) become stale after the transfer for many months.”

“Our results reveal at best poor practices of resource management that can facilitate malicious activities, such as hijacking attacks, and even lead to connectivity issues due to the increasing deployment of RPKI-based or IRR-based filtering mechanisms.”

It gets worse: “ASes involved in the transfer market exhibit consistently higher malicious behavior compared to the rest of the ASes, even when we account for factors such as business models and network span,” the three authors said, adding “Our findings are likely to be a lower bound of malicious activity from within transferred IP addresses since a number of transactions may occur without being reported to the regional internet registries.”

The authors hope their work helps registries and others to do better.

“We believe that these insights can inform the debates and development of … policies regarding the regulation of IPv4 markets, and help operators and brokers conduct better-informed due diligence to avoid misuse of the transferred address space or unintentionally support malicious actors,” they wrote.

“Moreover, our results can provide valuable input to blacklist providers, security professionals and researchers who can improve their cyber-threat monitoring and detection approaches, and tackle evasion techniques that exploit IPv4 transfers.”

Giotsas talks through the paper in the video below. ®

[3]Youtube Video

Get our [4]Tech Resources



[1] https://www.lancaster.ac.uk/scc/about-us/people/vasileios-giotsas

[2] https://eprints.lancs.ac.uk/id/eprint/139789/1/VGiotsas_PAM2020_IPv4_Transfers_abuse.pdf

[3] https://www.youtube.com/watch?v=Al_FvF4irMY

[4] https://whitepapers.theregister.com/

Unfortunate but not unexpected

Mike 137

This is not specific to IPv4 addresses. Whenever there's a slackening off of governance there are opportunities for fraud, and such opportunities are soon spotted and exploited by opportunist fraudsters. Where's the surprise in that?

Re: Unfortunate but not unexpected

Charlie Clark

Indeed, yet another reason why these shouldn't really be tradeable.

cb7

How many cowboys are out there continuing to set up new servers/routers etc with IPv4 only, because they don't understand IPv6, or they encounter issues that are easily "resolved" by turning IPv6 off instead of configuring things properly?

Pascal Monett

When you're looking for a chance to rip people off, configuring things "properly" is not your priority.

sebbb

While I'm an all-in "dictator" in my company in support of IPv6, this issue is not really 100% resolved with that, as we will still need IPv4 for a while (while people get less moany about v6). This is normal when you have a limited resource that you still need for stuff to function.

Thought About IT

Doesn't v6 give an infinitely greater possibility for bots to avoid being blacklisted?

Interesting market effects

Len

I can picture all sorts of interesting market effects happening to IPv4 addresses.

A pricing difference between "clean" and "dirty" addresses. Addresses that are on blocklists for spam or botnets should trade at a lower value than ones that are clean. The question is, how can a buyer assess the "quality" of an address? Without transparency that market effect can't work. Are there already consultancies or services that can help you buy a "clean" block of IPv4 addresses?

Some companies might be more relaxed about buying dirty addresses, depending on their use case. Would it matter if Netflix would buy a block of addresses for its streaming servers that happens to feature on spam blocklists? I would think not. Meanwhile, if you're planning to set up a new email service provider you'd want to buy the cleanest blocks available.

On overall view, not tomorrow but perhaps next decade, that due to the lack of regulation, legacy ownership issues, legacy transparency issues, rampant abuse etc. that IPv4 traffic is dodgier than IPv6 traffic. It may lead to a situation in let's say 2030 that people reaching your server from IPv4 addresses will need to go through a CAPTCHA (or other Turing test) whereas standard IPv6 traffic doesn't. At the moment Google is a bit stricter about email traffic coming from servers over IPv6 than over IPv4 as blocklists for IPv4 are easier (and more established) than for IPv6. Will that stance reverse at some point?

A steady rise in value in IPv4 addresses up to a certain point until it hits a peak and then a fairly sharp drop. At the moment about 33% of all traffic is IPv6, once that reaches a certain level the value of IPv4 will suddenly decrease and it tips from a seller's market into a buyer's market. As a seller of an IPv4 block it makes sense to hold out for a bit longer, but not too long because it will suddenly drop quite rapidly as every holdout will sell their block while it still has value. Like most markets, it doesn't matter when the real tipping point is, it matters when people think we have reached that tipping point. The perception is enough to create the tipping point.

At some point the majority of home and office users will have a Dual Stack (IPv4+IPv6) or DS-Lite (IPv6+IPv4 behind NAT) connection. At that point the only people still interested in IPv4 blocks will be owners of servers who need to make sure that IPv4-only users can still reach them. This might mean a release of IPv4 blocks by ISPs who sell it to server owners (from massive cloud companies to smaller hosters). If you're an ISP that always had a good abuse department your blocks might be worth more than those of ISPs that are infamous for their lax approach to botnets, spammers, open relays etc.

I know it's weird, but it does make it easier to write poetry in perl. :-)
-- Larry Wall in <7865@jpl-devvax.JPL.NASA.GOV>