Get the latest tech news

Ping Storms at GreyNoise


GreyNoise has been seeing crazy noise storms full of pings for years. I may have figured out what some of them are.

Basically, they watch and monitor activity that hits lots of hosts randomly – network mapping, port scanning, doorknob rattling. Don’t get me wrong – I love the idea, and have already imagined a half-dozen approaches using pseudorandom keystreams and encrypted data… But if I can come up with a much better way to do this, then anything that actual, professional, you know, SPIES, could do, would probably not be something we’d even notice. I spent some time trying to get them to show up in Wireshark itself, thinking that maybe I’ll see obvious patterns in the “BD 58” fields, but I just couldn’t get them to be recognized, no matter what I did to tweak the timestamp data.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of GreyNoise

GreyNoise

Photo of Ping Storms

Ping Storms