Jump to content

AMPRNet

From Wikipedia, the free encyclopedia

Antennas for High-speed Amateur-radio Multimedia Network (HamNET) in Europe, part of the AMPRNet wireless mesh network

The AMPRNet (AMateur Packet Radio Network) or Network 44 is used in amateur radio for packet radio and digital communications between computer networks managed by amateur radio operators. Like other amateur radio frequency allocations, an IP range of 44.0.0.0/8 was provided in 1981 for Amateur Radio Digital Communications (a generic term) and self-administered by radio amateurs. In 2001, undocumented and dual-use of 44.0.0.0/8 as a network telescope began,[1] recording the spread of the Code Red II worm in July 2001. In mid-2019, part of IPv4 range was sold off for conventional use, due to IPv4 address exhaustion.

Protocol

[edit]

Beginning on 1 May 1978, the Canadian authorities allowed radio amateurs on the 1.25-meter band (220 MHz) to use packet radio, and later in 1978 announced the "Amateur Digital Radio Operator's Certificate".[2][3] Discussion on digital communication amateur radio modes, using the Internet protocol suite[4] and 44/8 IPv4 addresses followed subsequently.

By 1988, one thousand assignments of address space had been made.[5] As of December 2009 approximately 1% of inbound traffic volume to the 44/8 network was legitimate radio amateur traffic that could be routed onwards, with the remaining 2‒100 gigabyte per day of Internet background noise being diverted and logged by the University of California San Diego (UCSD) internet telescope for research purposes.[1] By 2016, the European-based High-speed Amateur-radio Multimedia NETwork (HAMNET) offered a multi-megabit Internet Protocol network with 4,000 nodes, covering central Europe.[6]

History and design

[edit]

The use of the Internet protocols TCP/IP on amateur (ham) radio occurred early in Internet history, preceding the public Internet by over a decade. In 1981, Hank Magnuski obtained the class A 44/8 netblock of 16.7 million IP addresses for amateur radio users worldwide.[7][8] This was prior to Internet flag day (1 January 1983) when the ARPANET Network Control Protocol (NCP) was replaced by the Transmission Control Protocol (TCP).[8] The initial name used by Jon Postel in RFC 790 was the "Amateur Radio Experiment Net".[7]

Originally the amateur link layer protocol AX.25 carried several competing higher level protocols, with TCP/IP a minority due to the complexity of the configuration and the high protocol overhead. Very few systems operated over HF for this reason. One approach for 1,200/9,600-baud VHF/UHF operation emerged as TCP/IP over ROSE (Radio Amateur Telecommunications Society "RATS" Open Systems Environment, based on X.25 CCITT standard). Within just a few years the public Internet made these solutions obsolete. The ROSE system today is maintained by the Open Source FPAC Linux project.[9]

The AMPRNet is connected by wireless links and Internet tunnels. Due to the bandwidth limitations of the radio spectrum, 300 bit/s is normally used on HF, while VHF and UHF links are usually 1,200 bit/s to 9,600 bit/s. Mass-produced Wi-Fi access points equipment on 2.4 GHz and 5 GHz is now being used on nearby amateur frequencies to provide much faster links as HSMM or hinternet. Since it is based on IP, the AMPRNet supports the same transport and application protocols as the rest of the Internet, though there are regulatory restrictions on encryption and third-party traffic.

The AMPRNet is composed of a series of subnets throughout the world. Portions of the network have point-to-point radio links to adjacent nodes, while others are completely isolated.

Geographically dispersed radio subnets can be connected using an IP tunnel between sites with Internet connectivity. Many of these sites also have a tunnel to a central router, which routes between the 44 network and the rest of the Internet using static routing tables updated by volunteers.

As of October 2011 experimentation had moved beyond these centrally controlled static solutions, to dynamic configurations provided by peer to peer VPN systems such as n2n, and ZeroTier.

Address administration

[edit]

The allocation plan agreed in late-1986 reserved half of the address space (44.0/9 or ~8 million addresses) for use within United States territory and (44.128/9, the remaining ~8 million addresses) for the rest of the world.[10]

After the sale of 44.192.0.0/10 in 2019, the remaining Internet Protocol (IP) addresses are the 44.0.0.0/9 for USA subnets and 44.128.0.0/10 subnet for the rest of the world, available to any licensed amateur radio operator.[11] The IP address management and assigning of addresses is done by volunteer coordinators with the proviso "we do not provide the same level of response as a commercial organisation." These addresses can possibly be made routable over the Internet if fully coordinated with the volunteer administrators. Radio amateurs wanting to request IP addresses within the AMPRNet should visit the AMPRNet Portal.[12]

mirrorshades router

[edit]
San Diego Supercomputer Center, host of AMPRNet internet gateway, and CAIDA/UCSD network telescope

Since the 1990s most packets within the 44/8 range were arranged to transit via an IP tunnel using IP in IP encapsulation to/from a router hosted at the University of California, San Diego.[13] This forwarding router was originally named mirrorshades.ucsd.edu[13] and later gw.ampr.org[14] or "AmprGW".[11][14][15][16]

By 1996 higher-speed 56k modems briefly had greater throughput than was possible to forward via the "mirrorshades" central reflector router and back again.[17] Only IP addresses with an active Domain Name System (DNS) entry under ampr.org are passed by the packet filter for forwarding.[11][18]

By 19 August 1999 daily encapsulated IP in IP traffic was ~100 kilobits per second, peaking to 0.14 megabits per second.[19] During mid-2000, the majority of unique IP addresses seen on the University of California, San Diego connection from CERFnet began with the 44 prefix, except for 17% of IP addresses which did not.[20] In mid-2009 the mirrorshades server was upgraded and replaced after about ~1,100 days uptime.[21] A funding proposal in 2010 raised the possibility that "The legitimate traffic is also a potential research resource".[1]

UCSD network telescope

[edit]

Beginning in February 2001,[1][22][23][24] as part of backscatter research and the CAIDA/UCSD network telescope project, the whole of the 44/8 address block[25] was being advertised via the border gateway protocol (BGP) as a passive honeypot for Internet background noise and backscatter collection,[24][26] based in the Center for Applied Internet Data Analysis[note 1] at the San Diego Supercomputer Center.[29] On 15 July 2001 the network monitoring of 44.0.0.0/8 traffic recorded the spread of the Code Red II worm.[30] Prior to July 2001, the project had been logging unsolicited TCP SYN packets destined for IP addresses within 44.0.0.0/8; and after 19 July 2001 full incoming IP header logging took place.[31] The 44/8 IP address block was stated to have "high value to research".[32]

Capture data for August 2001, using data compression and retaining only IP headers was 0.5 gigabyte per hour.[33] In 2002 the block was 0.4% of all internet IPv4 address space.[34] By September 2003, traffic was 0.75 terabytes per month and costing $2,500 per month for bandwidth.[35] In October 2004 Limelight Networks began to sponsor the internet transit costs of the CAIDA network telescope.[35] In April 2009 the upstream rate limiting was removed, increasing the number of packets reaching the network telescope.[36] At the end of 2012, seaport.caida.org was the network telescope data capture server with thor.caida.org used for near real-time data access.[25][37][38] As of 2016, the 44/8 network was receiving backscatter from denial-of-service attacks (DoS) each measuring ~226 packets per second (mean peak average)[39] totalling 37 terabytes per month.[38]

Support was supplied by Cisco Systems under a University Research Board (URB) grant.[31][40] The project was funded by an Advanced Networking Infrastructure and Research (ANIR) award,[41] and Computer and Network Systems (CNS) award[42] from the National Science Foundation (NSF); the United States Department of Homeland Security (DHS);[41] and Network Modeling & Simulation (NMS) / Next Generation Internet Program (NGI) of the Defense Advanced Research Projects Agency (DARPA).[26][31]

  1. Both "Cooperative Association for Internet Data Analysis" (CAIDA) and "Center for Applied Internet Data Analysis" (CAIDA) appear in academic texts.[27][28]
Feed
[edit]

In May 2017, the Center for Applied Internet Data Analysis provided a new server for the AMPRNet gateway, in a different building.[16] As of mid-2017 a passive monitoring configuration was in use, involving a network switch with port mirroring set to duplicate the incoming packets being seen by the AMPRNet gateway to the UCSD network telescope capture server.[24] The project funding proposal for "Sustainable Tools for Analysis and Research on Darknet Unsolicited Traffic" (STARDUST) specified a planned upgrading to 10 Gigabit Ethernet with a passive optical tap, in order to provide finer timestamping and avoid packet loss.[24]

By July 2018, the replacement 10 Gigabit Ethernet infrastructure, using an optical splitter and Endace capture card, was operational.[43]

Archives
[edit]

The archived intermittent captures for 2001‒2008 were 657 gigabytes.[44] The archived pcap captures from 2008‒2012 were 192 terabytes of data uncompressed.[45] In January 2012, five weeks of recent data were 5.5 terabytes uncompressed.[45] Beginning on 22 March 2012, the raw hourly compressed pcap traces from 2003‒2012 were transferred to the National Energy Research Scientific Computing Center (NERSC) for long-term storage and research data archiving.[36] This data migration of 104.66 tebibytes took one week at a sustained rate of 1.5 gigabits per second via the Energy Sciences Network (ESnet).[36]

For the 2012‒2017 period, 2.85 petabytes of data was collected (1.3 petabyte compressed).[25] As of 31 December 2017