{"id":"45161924-0d7d-4f4d-b7c6-2de7de9cf4ba","arxiv_id":"2508.07506","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"A large-scale IPv6 proactive telescope in a production ISP network collected 600M unsolicited packets, enabling analysis of scanner sources and target-selection strategies.","lead":"This paper reports the largest-ever IPv6 proactive telescope deployment, collecting over 600 million unsolicited packets from scanners in 1.9k autonomous systems over 10 months. The study characterizes scanner sources and strategies, giving new visibility into how IPv6 scanning operates.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Single-ISP telescope's external validity is the core unverified assumption; a cross-telescope comparison is needed.","rationale":"The reader's weakest_assumption exactly matches the most load-bearing concern I can identify from the abstract: the external validity of a single-telescope study. The abstract's claim to characterize global IPv6 scanning dynamics from one production ISP network is only as strong as the assumption that the telescope's vantage point does not systematically bias the observed scan sources and strategies. Since the full text is unavailable, I cannot determine whether the authors already address this via multi-location validation, bias-aware inference, or comparison with passive telescope data. The reader's UNVERDICTED verdict appropriately reflects this evidentiary gap. My stress-test does not change that verdict; it sharpens the specific condition under which the paper's central claim would be validated: a demonstration of cross-telescope consistency or a convincing statistical adjustment for vantage-point bias. The concrete test I propose is feasible and would directly settle the concern.","tokens_in":537,"tokens_out":2049,"duration_ms":25122,"concrete_test":"Deploy or obtain data from at least one independent IPv6 telescope in a different network (e.g., CAIDA's IPv6 telescope or a non-ISP academic vantage point) over an overlapping time period. Compute the overlap of top source /48s or /32s, the Jensen–Shannon divergence of ASN distributions, and the agreement on inferred scanning strategies (e.g., which ports, address-generation patterns, and hit rates). If the overlap is low or the distributions diverge significantly (e.g., rank correlation < 0.5), the single-telescope findings are not representative of global IPv6 scanning.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim generalizes from one IPv6 proactive telescope deployed in a production ISP network to global IPv6 scanning dynamics. This assumes the observed unsolicited traffic is representative of all scanners, but the telescope's location, advertised prefix size/placement, and network ingress policies will bias which scanners reach it and which probes are recorded. IPv6 scanning strategies are known to be selective (e.g., scanning recently delegated prefixes, target-rich areas, or address patterns), so a single vantage point may only capture a subset of strategies and sources. The paper further infers scanners' target-address generation strategies from the probes received; this inference is only valid if the telescope's address space is an unbiased random sample of the IPv6 address space or if the inference method explicitly accounts for the advertised range. Without demonstrating representativeness—e.g., by comparing against independent IPv6 telescopes in different networks—the conclusions about scanner sources and strategies remain unverified for the global population.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript reports a longitudinal measurement study of IPv6 scanning using a combination of proactive and passive telescopes deployed in a production ISP network. The abstract claims that this is the largest-ever IPv6 proactive telescope, with over 600M unsolicited packets observed from 1.9k Autonomous Systems over 10 months. The authors state that they characterized the sources of unsolicited traffic, evaluated five network-stack features, and inferred scanners' sources of target addresses and their scanning strategies. The study is observational and descriptive in design, with the central contribution being the scale and integration of proactive and passive vantage points.","tokens_in":771,"tokens_out":2221,"duration_ms":29319,"significance":"If the full manuscript substantiates the abstract's claims, this would be a valuable empirical contribution to the understanding of IPv6 scanning dynamics. The 10-month, 600M-packet dataset from a production ISP network is potentially a significant resource, and the combination of proactive and passive telescopes is a methodological strength. The work is particularly relevant to network measurement and security communities concerned with IPv6 address exposure and scanner behavior. However, the abstract alone cannot establish the validity of the global-inference claims: the reliance on a single production ISP network presents a clear external-validity risk, and the inferential step from received probes to scanner target-generation strategies requires careful modeling of the observation process. The paper's significance will depend on how these issues are handled in the full text.","major_comments":[{"comment":"The abstract concludes by claiming to characterize global 'IPv6 scanning dynamics' and to infer scanners' target-address sources and strategies, yet the only described deployment is 'a production ISP network' (singular). A single telescope's location, advertised prefix size and placement, routing policies, and ingress filtering can strongly bias which scanners reach it and which probes are recorded. The abstract provides no evidence—e.g., comparison with independent telescopes, analysis of address-space coverage, or modeling of the observation process—that the observed traffic is representative of global scanning behavior. This external-validity issue is load-bearing for the paper's central claim and must be addressed in the full text, either by demonstrating representativeness or by appropriately restricting the conclusions.","section":"Abstract (central claim)"},{"comment":"The abstract states that the authors 'inferred scanners' sources of target addresses and their strategies.' This inference is only sound if the analysis explicitly accounts for the telescope's advertised address range and the probability that a given scanner's probe would arrive at that range. IPv6 scanning strategies are known to be non-uniform, often targeting recently delegated prefixes or patterns in address space. The abstract gives no indication of a statistical model, counterfactual analysis, or cross-validation that would separate scanner behavior from the telescope's visibility. The full manuscript must describe this inference methodology and its assumptions; otherwise the central claim about scanner strategies remains unverified.","section":"Abstract (inference of scanner strategies)"},{"comment":"The abstract's headline numbers—'largest-ever IPv6 proactive telescope,' 'over 600M packets,' '1.9k Autonomous Systems'—lack the operational definitions needed for assessment. For example: what address-block sizes were advertised? Are the 600M packets unique packets or total observations? Is 1.9k ASes measured by source ASN of packets, or by unique source addresses? How were the passive and proactive telescopes integrated? Without these definitions, the scale claims are not verifiable and cannot be compared with prior work. The full text should provide a precise measurement and deployment description.","section":"Abstract (quantitative claims)"}],"minor_comments":[{"comment":"The phrase 'develop and integrate proactive techniques to attract IPv6 scan traffic' is awkward; consider 'develop and integrate proactive techniques that attract IPv6 scan traffic' or 'develop tools and vantage points...' for clarity.","section":"Abstract (language)"},{"comment":"The expression '1.9k Autonomous Systems' mixes informal numeric shorthand with a technical term; use '1,900 Autonomous Systems' or define the metric. Also, 'five major features across the network stack' is vague; listing or naming the features would help the reader assess the claim even at the abstract level.","section":"Abstract (notation and precision)"}],"recommendation":"uncertain","confidential_remarks":"Only the abstract was available for review, so the soundness of the methodology and the validity of the global-inference claims cannot be assessed. I recommend that the full manuscript be sent for review with particular attention to the external-validity of the single-ISP deployment and the statistical inference of scanner strategies. The current abstract is promising but insufficient for a decision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague—short version: this is a worthwhile measurement paper to send out, but the abstract alone can't support strong conclusions. The core deliverable is a new IPv6 proactive telescope in a production ISP network, 600M unsolicited packets from 1.9k ASes over 10 months. That scale is new, and combining proactive and passive telescopes to fingerprint scanners' target generation strategies is a genuinely useful direction. If the data are actually public or shared, that alone is a contribution the community can build on.\n\nWhat I can't judge from the abstract: the selectivity of the vantage point. The stress-test note is right that a single ISP's advertised address range and ingress filtering shape which scanners reach you. IPv6 scanners don't probe uniformly; they target recently delegated prefixes and address patterns. So the inference that the 1.9k ASes represent global scanning dynamics is load-bearing and unproven here. That doesn't mean it's wrong — maybe the paper compares against other telescopes or argues the advertised space is dense enough — but the abstract doesn't say. Same for the scanner-strategy inference: if the method doesn't account for the probability of a probe hitting the advertised range, the inferred target-address generation strategy could be an artifact of the telescope's location.\n\nAlso worth watching: the 'five major features' effectiveness evaluation. That is only meaningful if the authors control for the mix of scanners and address-generation methods, otherwise it's descriptive, not evaluative.\n\nWho is this for? People working on IPv6 scanning, dark address space monitoring, and Internet background radiation. It will be useful as a dataset and methodology reference even if the global-generalization claims soften.\n\nNet: send it to peer review. A referee should ask for the external-validity analysis: cross-telescope comparison, coverage of delegated space, and sensitivity of strategy inference to the advertised prefix. If those are in the paper, great. If not, the paper should be a measurement report rather than a claim about global dynamics. I'd rather see this reviewed than bounced, because the field needs more IPv6 vantage points and the authors are clearly doing real work.","headline":"A large new IPv6 telescope dataset that likely deserves serious review; the main open question is how far a single-ISP view generalizes.","tokens_in":1194,"tokens_out":1523,"would_cite":true,"duration_ms":17931,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"By running the largest IPv6 telescope inside a working ISP, this paper uses over 600 million unsolicited packets to map who scans the IPv6 internet and how scanners choose targets.","keywords":["IPv6 scanning","network telescope","proactive telescope","unsolicited traffic","internet measurement","autonomous systems","scanning dynamics"],"falsifier":"Compare two identical telescopes deployed in different ISPs with different routing and prefix characteristics. If the inferred scanner target-selection strategies and the rank order of source autonomous systems change dramatically between the two, the observed dynamics are deployment-specific rather than global IPv6 scanning behavior.","tokens_in":509,"feed_emoji":"🔭","tokens_out":3248,"duration_ms":36363,"temperature":0.7,"pith_summary":"This paper reports the largest-ever IPv6 proactive telescope deployment, situated in a production ISP network. Over ten months it collected more than 600 million unsolicited packets from around 1,900 autonomous systems. The authors use this traffic to characterize who sends unsolicited IPv6 traffic, to evaluate how five network-stack features influence whether scans reach the telescope, and to infer where scanners get their target addresses and what strategies they follow. If the approach works, it gives the research community a way to observe IPv6 scanning at a scale and diversity that earlier passive-only or small-scale telescopes could not.","feed_headline":"Largest IPv6 telescope reveals how scanners pick targets","feed_subtitle":"Ten months of unsolicited traffic in a live ISP expose scanner sources and the network-stack features that attract scans.","key_machinery":"The central object is the IPv6 telescope: a large block of advertised yet unused IPv6 address space inside a production ISP that logs unsolicited packets. The paper's machinery includes the integration of proactive advertisement (to draw scans) with passive monitoring (to record them), plus an analysis of five network-stack features that determine how much scanning traffic a telescope can attract and observe.","core_discovery":"The core discovery is that a proactive IPv6 telescope embedded in a production ISP network can attract a large, diverse body of unsolicited traffic, and that this traffic carries enough signal to reconstruct scanning behavior. The paper claims that by advertising unused IPv6 space and combining proactive and passive observation, it captured over 600 million packets from 1.9k autonomous systems in 10 months. From these packets it characterizes the sources of unsolicited traffic, assesses the effect of five features across the network stack, and infers scanners' sources of target addresses and their strategies. The contribution is a new measurement method and a longitudinal dataset, rather tha","pith_inferences":["A natural extension would be replicating this telescope design at several ISPs to test whether the inferred scanner strategies depend on the telescope's location or advertised prefixes.","The inferred target-address sources could be validated against external IPv6 hitlist data; agreement would strengthen the claim that telescopes observe selection strategies rather than telescope-driven artifacts.","The five network-stack features could become a benchmark for comparing future telescope deployments, letting researchers quantify how much of their traffic is shaped by design choices."],"forward_implications":["A single production-ISP telescope can collect unsolicited traffic from nearly 2,000 autonomous systems within ten months, so IPv6 scanning is not a marginal phenomenon.","Scanners' target-address sources and strategies are inferable from telescope data, meaning IPv6 scanning is structured enough to model.","The five network-stack features measurably affect how much scanning traffic reaches a telescope, so telescope design choices change what measurements see.","Proactive and passive telescopes can be combined in one deployment, giving a way to observe both the scans directed at advertised space and background unsolicited traffic."],"supporting_citations":[],"fun_headline_variants":["600M unsolicited IPv6 packets expose scanner strategies","Largest IPv6 telescope maps 600M scan packets","Scanner target selection deduced from IPv6 telescope","Live ISP telescope captures 600M unsolicited IPv6 packets"],"cache_read_input_tokens":2816,"weakest_assumption_plain":"That the unsolicited traffic arriving at this single production ISP's telescope is representative of global IPv6 scanning, so conclusions about scanner sources and strategies generalize beyond this deployment.","fun_headline_variants_meta":{"raw":{"variants":["600M unsolicited IPv6 packets expose scanner strategies","Largest IPv6 telescope maps 600M scan packets","Scanner target selection deduced from IPv6 telescope","Live ISP telescope captures 600M unsolicited IPv6 packets"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000802,"raw_usage":{"total_tokens":3287,"prompt_tokens":595,"completion_tokens":2692,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":339,"completion_tokens_details":{"reasoning_tokens":2626}},"tokens_in":339,"tokens_out":2692,"duration_ms":20560,"temperature":1.0,"reasoning_tokens":2626,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T22:02:45.505313+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compare two identical telescopes deployed in different ISPs with different routing and prefix characteristics. If the inferred scanner target-selection strategies and the rank order of source autonomous systems change dramatically between the two, the observed dynamics are deployment-specific rather than global IPv6 scanning behavior.","supporting_citations":[],"review_version":1}