Exploitation of ICMP Time Exceeded Packets for A Large-Scale Router Delay Analysis

Internet Control Message Protocol Time-Exceeded (ICMP-TE) time exceeded packets are particular communication protocols to express inaccessibility of nodes in terms of hop count limitations. With the Internet of Things (IoT) concept taking more space in our daily life, accessibility or in some manners inaccessibility of hosts should be analysed more carefully. ICMP time exceeded packets might be hand of an attacker, sometimes an indicator of compromise for a possible IoT Botnet attack or a tool for delay measurement. In this study, with the exploitation of ICMP time exceeded packets, we analyse Round Trip Time (RTT) delays of randomly distributed IP routers around the globe. We conduct a comprehensive delay analysis study considering the delay results of more than 1 million time exceeded packets taken in return for subject ICMP requests. To prove ICMP time exceeded packets might also be a signature for a possible IoT Botnet attack, we carry out a secure experiment for Mirai IoT Botnet scanning and exhibit the indicators to differentiate these two possible usages.

Gary Warner was born in Indiana and grew up in the Mid-West. He moved to Birmingham, Alabama to attend UAB, where he earned his Bachelor's in Computer Science. Warner has worked in mainframe operations, network security and design, and as the I.T. Director for an oil and gas company. He started the Birmingham InfraGard chapter in 2001, and has served on the national board of directors for both the FBI InfraGard program and the DHS Energy ISAC. In 2007, he joined the University of Alabama at Birmingham to train future cybercrime investigators. He currently directs a staff of 50 student researchers in the UAB Computer Forensics Research Lab where he works primarily on malware and botnet investigations, cybercrime investigations, and the social media usage of criminals, hate groups, and terrorists. Ali Gezer was born in Kayseri City, Turkey, in 1976. He received the B.S. degree in Electronic and Computer Education from Marmara University in 1999 and M.S. degree in Computer Engineering from Erciyes University in 2004, and the Ph.D. degree in Electronic Engineering from Erciyes University, Kayseri, TURKEY, in 2011. He is an assistant professor with the Electronic and Communication Technology in Kayseri University. His research interests include internet traffic analysis, self- similarity, network traffic modelling and characterization, signal processing techniques, telecommunication technologies, IoT botnet investigations, and malware analysis.