OK so what's going with these millions of Pentagon-owned IPv4 addresses lighting up all of a sudden?
- Reference: 1619469311
- News link: https://www.theregister.co.uk/2021/04/26/defense_department_ipv6/
- Source link:
On January, 20, 2021, as [1]noted over the weekend by Doug Madory, director of internet analysis at network monitoring biz Kentik, a sizable portion of unused IPv4 address space registered to the DoD (GRS-DoD) and referred to as [2]AS8003 , began announcing the reachability of millions of previously unreachable addresses via the Border Gateway Protocol (BGP).
Coming ten minutes after President Joseph Biden was sworn into office and three minutes prior to the statutory conclusion of Donald Trump's term, the timing of the BGP announcement invited speculation about the motives for lighting up so many previously dark addresses.
[3]
More so, because the company administering the growing swath of addresses – Plantation, Florida-based Global Resource Systems LLC – lacks a meaningful web presence and because that opacity extends to the organization's ownership.
China showing signs of brewing IPv6 eruption [4]READ MORE
When the Washington Post [5]sent a reporter to knock on the door of the company's office – a shared workspace – the receptionist declined to provide any information about the business and asked the reporter to leave.
The Register called the biz and emailed to learn more about who's running things at Global Resource Systems, and we've not heard back.
Up through April, the advertised address range continued to expand to that point that Global Resource Systems is now representing almost 175 million DoD-registered IPv4 addresses, more than any other Autonomous Systems Number in the US, [6]including AT&T .
[7]
That's a potentially valuable asset at time when the supply of available IPv4 addresses is scarce.
Concerned about the possibility that this government-owned resource might be sold – contemplated by lawmakers in 2019
[8]PDF
but not enacted – or given away to an opaque private company, The Register asked the Defense Department to clarify what's going on.A DoD spokesperson suggested that merely advertising the validity of the IP addresses within AS8003 hasn't changed anything.
"There was no change in the allocation and assignment of address space," the spokesperson said in an email. "The address space was not sold, and the address space is still registered, allocated and assigned to the DoD Network Information Center (NIC)."
[9]
Asked to provide further detail about who's running Global Resource Systems, the DoD spokesperson did not respond, but did provide a statement from Brett Goldstein, director of the US military's Defense Digital Service (DDS).
Formed in 2015, the DDS aims to apply private sector expertise to Defense Department projects. The agency, said Goldstein, authorized the advertisement of the previously unused DoD IP addresses as part of a pilot test.
"This pilot will assess, evaluate and prevent unauthorized use of DoD IP address space," said Goldstein. "Additionally, this pilot may identify potential vulnerabilities."
He characterized the effort as one of many cybersecurity initiatives undertaken in response to sophisticated threats as a way to mitigating potential vulnerabilities.
Madory in his post interpreted the address space advertisement as a way to deter squatters who might try to abuse unused DoD addresses as a way to bypass blocklists, and as a way to gather internet traffic data for threat analysis.
And well, now we know. ®
Get our [10]Tech Resources
[1] https://www.kentik.com/blog/the-mystery-of-as8003/
[2] https://ipinfo.io/AS8003
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIc39pENWlXTE933gxUPWwAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2021/01/13/china_ipv6_eruption/
[5] https://www.washingtonpost.com/technology/2021/04/24/pentagon-internet-address-mystery/
[6] https://ipinfo.io/countries/us
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIc39pENWlXTE933gxUPWwAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.congress.gov/116/crpt/hrpt120/CRPT-116hrpt120-pt2.pdf
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIc39pENWlXTE933gxUPWwAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Advertising to something you control
Advertising dead space to something you own stops someone else doing it.
In the olden days public address space was used internally, meaning internal hosts could potentially be directly addressable from anywhere else on the internet just like what people want to do with ipv6.
You can still use that public address space internally and hide it behind NAT or proxies or whatever to prevent the internet reaching your internal systems, bonus points for advertising those public addresses on the internet to route to some place that isn’t connected to your internal net, null is a good starter. Doing that ensures internet hosts can never directly route to your internal hosts and any virus writers need to account for public routing not going where it should.
Internet routers shouldn’t route rfc 1918 addresses for obvious reasons, but that’s a shouldn’t and traffic could be exfiltrated, same as any public space null routed but public address space in traffic turning up in places it shouldn’t should be a bit easier to spot.