Conference Agenda
Overview and details of the sessions of this conference. Please select a date or location to show only sessions at that day or location. Please select a single session for detailed view (with abstracts and downloads if available).
|
Daily Overview |
| Session | ||
Internet infrastructure-1: On IP Addresses as Identifiers of Internet Users and Services
| ||
| Presentations | ||
On IP Addresses as Identifiers of Internet Users and Services 1: Stanford University; 2: Independent; 3: Cloudflare The Internet is attracting more attention from legislators, regulators, and policy makers, who seek to balance identity and accountability online with safety and privacy for their constituents. IP addresses link devices to the Internet, along with those devices’ users and software, causing IP addresses to often be treated as identifiers for users or services on the Internet. The position is understandable from a historical perspective when IPs uniquely identified hosts on the Internet. Anecdotally, however, the technical community would argue the matter is less clear and more nuanced. For example, IPv6 addresses change frequently, and IPv4 exhaustion has led to large-scale address sharing. As a result, there is considerable inconsistency between the technical role that IP addresses play on the Internet in practice and how people, including policymakers, perceive them. The consequences of those gaps in understanding have already been laid bare in large public events, where IP addresses are used in attempts to uniquely identify malicious users, locate malicious software, or block websites despite significant collateral damage [1,2,3]. In 2022, Austrian courts directed Internet Service Providers (ISPs) to block several websites by IP address. Among them were 11 blocked addresses belonging to Cloudflare, a content delivery network (CDN), which resulted in citizens losing access to thousands of unrelated sites [4]. Similarly, many network protections rely on IP-based reputation datasets and IP-based rate limits, which disproportionately affect populations where IP sharing is more common [5]. In these scenarios, singular malicious or compromised users can negatively affect a sizable portion of a population, even an entire country. In our work, we will present a holistic view of IP address sharing as seen by both websites and users. Given the consequences of using IP addresses to attribute behavior on the Internet, this paper is motivated by the following questions: To what extent do IP addresses meaningfully function as identifiers on the Internet, and how should policymakers conceptualize them? We will investigate trends for both websites and services, as well as the users who access them. On the server side, we will analyze a decade of longitudinal DNS data covering the .com, .net and .org top-level domains, supplemented by active DNS measurements of popular websites. On the client (users’) side, we have access to anonymized, globally distributed traffic logs for 198 countries from a major content delivery network (CDN). Since there exists no accurate method to uniquely identify clients, we will analyze the distribution of requests and their metadata across desktops and mobile devices by devising testable hypotheses. Our investigation will show how IP sharing has increased over the past decade, with it being increasingly common for millions of websites to be served by a single IP address. Early analysis shows that fewer than 0.2% of domains in the .com, .net, and .org top-level domains (TLDs) use a unique IP address. Our paper will explore how the extent of IP sharing differs according to the popularity of a website. Among clients, we will show that traffic is also highly concentrated on a small set of IP addresses. Globally, 5% of client IP addresses account for over half of the observed requests, suggesting that client IPs do not act as a viable identifier for users in any part of the world. We further discuss possible reasons why IP sharing is more common in some countries than in others. By taking an empirical view of the relationship between addresses and the users or services that use them, our study will show the disproportionate impacts that can emerge by treating all IP addresses as equal---and provide a reference point to evaluate or design data-driven guidance and policies. We will additionally use these insights to argue for better indicators that are accurate, fair, and privacy-preserving, leading to a more resilient and safe Internet.
| ||
