Identificação e Categorização de Endereços IP Dinâmicos com Dados Públicos

Gabriel Pains de Oliveira Cardoso

The identification and tracking of devices running services and applications in network vulnerability studies and forensic analysis rely heavily on the assumption of static IP addresses. However, the dynamic allocation of IP addresses, driven by IPv4 exhaustion and cloud computing environments, makes it harder to map behaviors, vulnerabilities, and attack sources to devices. Methods for classifying an IP as static or dynamic exist, but they face limitations such as the reliance on outdated or incomplete Reverse DNS (RDNS) records, or the need for private data. This work expands on DynMap, an algorithm that identifies dynamically-allocated IP blocks from public fingerprint data, previously applied only to Shodan HTTPS certificate scans. We stress and generalize DynMap by applying the same algorithm to two longitudinal Shodan datasets, HTTPS certificates and SSH host keys, plus a shorter, complementary set of \sw{zgrab2} TLS scans of the Tranco list, while sweeping its highest-impact parameter, the minimum block size. Our central finding is that the fingerprint type fundamentally shapes what DynMap observes: HTTPS certificate scans are dominated by dynamic addresses, whereas SSH host keys instead reveal shared infrastructure, default keys cloned across customer devices, rather than dynamism. The Tranco set was explored as complementary data but lacked a long enough observation window for meaningful results; since it uses the same fingerprint as the HTTPS set, we expect comparable findings given sufficient longitudinal data. The block-size parameter offers an adjustable trade-off between precision and coverage.


2026/2 - POC2

Orientador: Ítalo Fernando Scotá Cunha

Palavras-chave: Dynamic IP, IP Identification, Fingerprinting, DynMap, Internet Measurement

PDF Disponível