Research sensors

IPBGP operates low-interaction TCP research sensors on its own address space, as part of our own detection network. If a connection to one of our addresses answered with a one-line notice pointing here, this page explains what that sensor does and how to opt out.

The notice a sensor writes to every connection
IPBGP research sensor; metadata only; see https://www.ipbgp.org/sensors

What the sensors are

Each sensor is a small program that accepts TCP connections on an IPBGP address — currently on ports 23, 2222 and 3389 — writes a one-line notice identifying itself as an IPBGP research sensor, and then closes the connection: as soon as the source sends anything, or after a short deadline if it stays silent. It does not emulate any protocol or service behind those ports.

What is recorded

For each accepted connection the sensor keeps exactly these fields:

  • Source IP address
  • Destination port
  • First-seen and last-seen timestamps
  • Identifier of the sensor node that saw it
  • Connection count
  • TCP handshake state
  • A fixed classification label recording the observation as a scan; the sensor sets the same value on every connection and does not infer anything about the source

Those are the only fields recorded, and they describe the connection itself — not its contents.

What is not recorded

  • No payload bytes are stored. Anything the source sends is read up to a small bound and discarded; it is never written to a log or a file.
  • No credentials are collected. The sensor presents no login prompt and does not parse what it receives.
  • No protocol is emulated. The sensor does not behave like a Telnet, SSH or remote-desktop service; it writes the notice, waits briefly and closes.
  • No connection is ever initiated to the source. The sensor only accepts connections; it never connects back, scans or probes.

Why we run them

The sensors let us observe which addresses actively scan or abuse our own infrastructure. That observation is first-hand evidence in our IP assessments.

How to opt out

Write to us with the IP address or CIDR range you want excluded and a contact we can reply to. We add it to a protected opt-out list that every sensor node honours: connections from a listed address are closed at once and nothing is recorded for them. The list is applied at the sensor and takes effect when the sensor next loads its configuration.

abuse@ipbgp.org

Abuse reports and questions

For anything about the sensors — an opt-out request, a concern or a question — use this mailbox.

abuse@ipbgp.org