State of UDP Scanners on the Internet

Sina Rostami, Taha Albakour, Tiago Heinrich · 2025

Internet scanning is a prevalent event on the Internet. Scanning can have both benevolent and malicious intents. It can potentially be utilized to find vulnerable machines and services to then initiate further intents, such as Denial of Service (DoS) attacks. Therefore, studying the behavior of scanners, the services they are targeting, and the information they are looking for is essential for protecting Internet-facing services and preventing malicious intent against them. In this work, we present our first steps towards our methodology for studying the behavior of Internet scanners. Specifically, we investigate the payloads of the first scan-packets in User Datagram Protocol (UDP). We group payloads based on their similarities to see different characteristics of scanners of the same protocol/service. We find that the variety of scan payloads depends on the protocol for example, 99% of NTP scans have the exact same payload. However, in SIP, this number reduces to 12%. We also highlight the existence of non-standard payloads such as MGLNDD scans in common UDP services.

Read the paper · More papers on PaperTik