
GCA Internet Integrity Papers: Expanding IoT Honeypots to Include IPv6-Connected Devices
GCA Internet Integrity Paper, “Expanding IoT Honeypots to Include IPv6-Connected Devices,” investigates the possibility of including the IPv6 address space in honeypot operations to, among other things, stop malware at its source. We propose a way to extend ProxyPot, the Global Cyber Alliance’s proprietary honeypot technology, to detect attacks over SSH, Telnet, HTTP, and HTTPS, over both IPv4 and IPv6— a first of its kind.
This paper is the third in a series of research projects done in collaboration with Microsoft to help make the Internet more secure, specifically related to Internet of Things (IoT) devices attached to the Internet. You can read the first two papers here and here.
In the paper, we explain our AIDE project, recap the difficulty of scanning IPv6 address space for attacks, outline current IPv6 practices that might increase attack vulnerability, define best practices at the device level, and explore potential IPv6 scanning options.