Unconsidered Installations: Discovering IoT Deployments in the IPv6 Internet
Markus Dahlmanns, Felix Heidenreich, Johannes Lohm\"oller, Jan, Pennekamp, Klaus Wehrle, Martin Henze

TL;DR
This study develops a methodology to discover IPv6-reachable IoT deployments, revealing security issues similar to IPv4, despite IPv6 deployments being newer and more up-to-date.
Contribution
The paper introduces a novel approach combining IPv6 scan techniques and address generators to effectively discover and analyze IPv6 IoT deployments.
Findings
Discovered 6,658 IPv6 IoT deployments using combined scanning methods.
Most deployments lack proper access control and TLS security measures.
IPv6 IoT deployments exhibit security issues similar to IPv4, despite being newer.
Abstract
Internet-wide studies provide extremely valuable insight into how operators manage their Internet of Things (IoT) deployments in reality and often reveal grievances, e.g., significant security issues. However, while IoT devices often use IPv6, past studies resorted to comprehensively scan the IPv4 address space. To fully understand how the IoT and all its services and devices is operated, including IPv6-reachable deployments is inevitable-although scanning the entire IPv6 address space is infeasible. In this paper, we close this gap and examine how to best discover IPv6-reachable IoT deployments. To this end, we propose a methodology that allows combining various IPv6 scan direction approaches to understand the findability and prevalence of IPv6-reachable IoT deployments. Using three sources of active IPv6 addresses and eleven address generators, we discovered 6658 IoT deployments. We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
