Research sensors
IPBGP operates low-interaction TCP research sensors on its own address space, as part of our own detection network. If a connection to one of our addresses answered with a one-line notice pointing here, this page explains what that sensor does and how to opt out.
IPBGP research sensor; metadata only; see https://www.ipbgp.org/sensorsWhat the sensors are
Each sensor is a small program that accepts TCP connections on an IPBGP address — currently on ports 23, 2222 and 3389 — writes a one-line notice identifying itself as an IPBGP research sensor, and then closes the connection: as soon as the source sends anything, or after a short deadline if it stays silent. It does not emulate any protocol or service behind those ports.
What is recorded
For each accepted connection the sensor keeps exactly these fields:
- Source IP address
- Destination port
- First-seen and last-seen timestamps
- Identifier of the sensor node that saw it
- Connection count
- TCP handshake state
- A fixed classification label recording the observation as a scan; the sensor sets the same value on every connection and does not infer anything about the source
Those are the only fields recorded, and they describe the connection itself — not its contents.
What is not recorded
- No payload bytes are stored. Anything the source sends is read up to a small bound and discarded; it is never written to a log or a file.
- No credentials are collected. The sensor presents no login prompt and does not parse what it receives.
- No protocol is emulated. The sensor does not behave like a Telnet, SSH or remote-desktop service; it writes the notice, waits briefly and closes.
- No connection is ever initiated to the source. The sensor only accepts connections; it never connects back, scans or probes.
Why we run them
The sensors let us observe which addresses actively scan or abuse our own infrastructure. That observation is first-hand evidence in our IP assessments.
How to opt out
Write to us with the IP address or CIDR range you want excluded and a contact we can reply to. We add it to a protected opt-out list that every sensor node honours: connections from a listed address are closed at once and nothing is recorded for them. The list is applied at the sensor and takes effect when the sensor next loads its configuration.
abuse@ipbgp.orgAbuse reports and questions
For anything about the sensors — an opt-out request, a concern or a question — use this mailbox.
abuse@ipbgp.org