These connections are part of an Internet-wide research study being conducted by computer scientists at RWTH Aachen University. The research involves making benign connection attempts to every public 5G RAN deployment from our own subnets (see below). By measuring the entire public address space, we are able to analyze patterns and trends in 5G deployments and security.
As part of this study, every public IP address receives a handful of packets per day on a selection of common 5G RAN ports. These consist of regular SCTP connection attempts followed by protocol handshakes with responsive hosts. After successfully connecting to a responsive host, we immediately end the connection. We never attempt to exploit security problems, guess passwords, or change device configuration. We only receive data that is publicly visible to anyone who connects to a particular address and port.
The data collected through these connections helps computer scientists study the deployment and configuration of network protocols and security technologies. For example, we use it to help web browser makers and other software developers understand the impact of proposed protocol changes and security improvements. In some cases, we are able to detect vulnerable systems and report the problems to the system operators.
To have your host or network excluded from future scans conducted by RWTH Aachen University, please contact researchscan@spice.rwth-aachen.de with your IP address or CIDR block. Alternatively, you can configure your firewall to drop traffic from our main IP we use for scanning. Our main IP is 137.226.92.28.