Searcharxiv⌕ Search

arXiv · 2610.05545

Reactive Constraint-Based Geolocation of Internet Hosts

Abstract

Active IP geolocation techniques rely on the responsiveness of Internet hosts, while passive techniques depend on data sources that are unevenly adopted and prone to staleness and error. In this work, we invert the active IP geolocation problem by listening at a geographically distributed set of vantage points for unsolicited Internet scans. By reactively completing connections with these scanners, we obtain round-trip time (RTT) measurements from hosts that may otherwise be unresponsive and use those measurements for geolocation. Over the course of 20 days in August 2026, we recorded 46.8 million scans from 289,746 distinct scanners, with a reactive RTT for each scan. We show that reactive RTTs align with those obtained by sending active probes, with more than three-quarters of 990,204 measurement pairs differing by at most 10 ms. Over half of the scanners that yielded a reactive RTT did not answer our active probes, highlighting the value of our approach. We demonstrate the feasibility of multilateration using purely reactive RTTs for 56,112 distinct IP addresses. Finally, using speed-of-light constraints, we refute commercial geolocation claims for 6,852 addresses.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Spencer Ye, Chase Kanipe, Peter Ryan, Erik Rye. 2026-10-04. Reactive Constraint-Based Geolocation of Internet Hosts. https://arxiv.org/abs/2610.05545

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

From ASIC to Fleet: Lessons from Building and Operating a Hyperscaler NIC

We describe the operational infrastructure built to deploy and operate fbnic, a custom multi-host NIC, across hundreds of thousands of production hosts at Meta. Vendor multi-host NICs, designed by retrofitting single-host architectures, suffered from shared firmware and buffers that created cascading isolation failures over seven years. fbnic eliminates these through physical isolation, but shifting to in-house hardware shifts the entire operational burden to the hyperscaler. We present a hardware-in-the-loop CI pipeline testing firmware, driver, and kernel cross-products; a unified observability pipeline co-locating NIC and switch counters for cross-layer fault attribution; a driver-first architecture with fewer than ten firmware message types; a targeted firmware upgrade orchestrator at sub-sled granularity; and scoped repair automation confining blast radius to individual host slices. Over ten months, fbnic achieved a 12X reduction in unplanned unavailability, 37% lower mean time to repair, and 2.3X fewer hardware swaps compared to vendor NICs on the same platform.

cs.NI↗

Semantic Split Inference for Remote Modulation Recognition

Remote automatic modulation recognition balances sensing-node complexity, reporting cost and accuracy. To address this trade-off, we propose channel-aware semantic split inference: a sensing node sends a semantic report over a noisy link and the edge server completes recognition. In our model, split depth and report length are independent design variables, with end-to-end training through the channel. We compare the resulting design against basic split placements, which run inference at the edge server or at the sensing node, and against a state-of-the-art collaborative scheme. We assess sensing-node model size, computation, latency and energy against recognition accuracy. We show that intermediate splits give the best accuracy-cost trade-off.

cs.NI↗

When Weak Reports Matter: Staged Anchored Fusion for Cooperative UAV Sensing

Local multipath rejection can erase evidence needed for cooperative sensing. We propose staged anchored recovery: preserve strong-only confirmations, then query compatible weak reports using unused strong anchors. For any number of sensing nodes, we prove lossless residual screening and derive corroboration and bidirectional cost laws. In 1,024 five-UAV drops, recovery adds 30 matched targets and three false outputs over strict consensus, matching one-pass anchored confirmation's detection counts while reducing weak uploads by 97.4%. Equal-sized cue/report records yield 4.5% less payload than uploading all eligible reports. Independent validation recovers four additional targets with no observed false outputs.

cs.NI↗