Secure IP Address Allocation at Cloud Scale
Eric Pauley
Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Internet Security
Overview
In the modern cloud computing landscape, the fundamental role of IP addresses has undergone a significant transformation. Historically, IP addresses served primarily as an infrastructure component, facilitating traffic routing between physical networks and typically mapping to long-lived, organization-owned infrastructure. However, as articulated by Eric Pauley at NDSS 2025, IP addresses are increasingly functioning as a security principle, mediating access in firewall rules, routing sensitive data via DNS records, and even enabling TLS certificate provisioning (e.g., via Let's Encrypt). This shift, coupled with the elastic, short-term leasing model prevalent in public clouds, introduces a new class of complex security vulnerabilities that traditional allocation policies fail to address.
Key moments
- 0:00 Introduction: IP addresses as security principles in cloud
- 2:00 Explaining retrospective and prospective threats for IP addresses
- 3:07 Identifying core problem and goal: secure IP allocation policies
- 4:10 Introducing EIPM: Elastic IP address simulator for evaluation
- 4:47 IP Tagging: A preliminary smart allocation policy
- 6:07 New policy: Behavioral segmentation for secure IP allocation
Secure IP Address Allocation at Cloud Scale
Speakers: Eric Pauley
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=yNTGpZ-ikkA
Overview
In the modern cloud computing landscape, the fundamental role of IP addresses has undergone a significant transformation. Historically, IP addresses served primarily as an infrastructure component, facilitating traffic routing between physical networks and typically mapping to long-lived, organization-owned infrastructure. However, as articulated by Eric Pauley at NDSS 2025, IP addresses are increasingly functioning as a security principle, mediating access in firewall rules, routing sensitive data via DNS records, and even enabling TLS certificate provisioning (e.g., via Let's Encrypt). This shift, coupled with the elastic, short-term leasing model prevalent in public clouds, introduces a new class of complex security vulnerabilities that traditional allocation policies fail to address.
The core problem arises from the temporal and spatial locality of benign and adversarial tenants within public cloud IP pools. An IP address released by a legitimate user can quickly be reallocated to a malicious actor, leading to both retrospective threats (attackers exploiting previous tenants) and prospective threats (harm to future tenants due to prior adversarial actions). These threats manifest as data compromise through dangling DNS, firewall bypasses, and reputational damage to IP addresses. Pauley's talk delves into the design and evaluation of novel IP allocation policies specifically engineered to mitigate these risks, preventing adversaries from acquiring large numbers of unique public cloud IP addresses and ensuring their spatial and temporal separation from benign tenants.
This research, building on prior work presented at S&P22, highlights that current cloud IP allocation practices—primarily random assignment—are inherently insecure, allowing adversaries to scan and allocate millions of unique IP addresses. The talk introduces EIPM (Elastic IP Address Simulator), an open-source tool used to evaluate new security-conscious allocation policies. The most significant contribution is IP scan segmentation, a heuristic approach that segments the IP address pool based on tenants' historical allocation behavior. This policy demonstrates a substantial reduction in adversarial success, even under sophisticated civil attack models, offering a practical and scalable solution for cloud providers to enhance the security of their IP address infrastructure.
Background
▶ Watch: Introduction: IP addresses as security principles in cloud (0:00)
The internet's foundational addressing scheme, Internet Protocol (IP) addresses, was originally conceived for a static, infrastructure-centric environment. In this historical context, an IP address typically corresponded to a piece of physical network hardware, was owned by an organization for extended periods, and primarily facilitated the routing of network traffic. This model assumed a relatively stable mapping between an IP address and its legitimate owner, with security considerations largely focused on network perimeter defenses.
However, the advent of public cloud computing has fundamentally altered this paradigm. Cloud providers operate on an elastic, on-demand leasing model, allowing tenants to acquire and release IP addresses for very short durations. This flexibility, while beneficial for scaling, introduces significant security challenges:
- Elasticity for Adversaries: Malicious actors can easily lease and release many unique IP addresses, rapidly cycling through the address space.
- Temporal and Spatial Locality: Benign and adversarial tenants often share the same IP address pools, with addresses frequently changing hands. An IP released by a legitimate user can be immediately acquired by an attacker.
- Retrospective Threats: Attackers can exploit IP addresses previously used by benign tenants. Examples include:
- Firewall Bypass: If firewall rules hardcode IP addresses, an attacker acquiring a previously trusted IP can gain unauthorized access to sensitive data.
- Dangling DNS: When DNS records point to IP addresses that are no longer owned by the legitimate service, clients can unknowingly route sensitive data to an adversary who has since acquired that IP. This constitutes both confidentiality and integrity breaches.
- Prospective Threats: Actions by an adversary on an IP address can negatively impact future, benign tenants. Examples include:
- IP Reputation Damage: Sending spam or engaging in malicious activities can blacklist an IP address, harming the delivery rates or connectivity for subsequent legitimate users.
Prior research, specifically presented at S&P22, empirically demonstrated the severity of this problem. It revealed that attackers can effectively scan and allocate a majority of IP addresses in public cloud pools, achieving high coverage and acquiring millions of unique IP addresses on major providers. This widespread vulnerability stems directly from the prevailing IP allocation policy in public clouds: random allocation. Cloud providers typically assign any available IP address to any tenant, a design choice that prioritizes availability and simplicity over the security implications of IP address reuse and rapid turnover. The core motivation for this work is to design and evaluate new allocation policies that proactively address these vulnerabilities by preventing adversaries from easily accumulating unique IP addresses and by spatially and temporally separating malicious and benign workloads.
Key Findings
▶ Watch: Identifying core problem and goal: secure IP allocation policies (3:07)
The research presented by Eric Pauley at NDSS 2025 delivers several crucial findings that highlight both the vulnerability of current cloud IP allocation practices and the efficacy of proposed countermeasures.
Firstly, the talk reiterates and reinforces the finding from previous work (S&P22) that current random IP allocation policies in major public clouds are fundamentally insecure. Adversaries can readily scan the majority of IP address pools and allocate millions of unique IP addresses, exploiting this randomness to facilitate a range of attacks, including dangling DNS vulnerabilities, firewall rule bypasses, and IP reputation damage. This underscores the urgent need for more sophisticated, security-aware allocation strategies.
Secondly, the introduction of the Elastic IP Address Simulator (EIPM) represents a significant contribution. EIPM is an open-source, reproducible artifact designed to simulate IP address allocation policies of major public cloud providers at scale. It can integrate both synthetic and real-world traces of benign allocation behavior, alongside sophisticated simulated adversaries, providing a robust platform for evaluating new allocation policies. This tool itself is a key finding, enabling data-driven security research in this domain.
Thirdly, the development and evaluation of new allocation policies, particularly IP scan segmentation, demonstrate a substantial improvement in security posture. While an initial, simpler policy called IP tagging showed promise in reducing attack success rates by preferentially reassigning IPs to their previous tenants, its effectiveness was limited by the assumption of a single cloud account per adversary. The more advanced IP scan segmentation policy, however, addresses the sophisticated civil attack model (where adversaries can create unlimited cloud accounts via stolen credentials). This policy heuristically segments the IP address space by tracking and matching tenants' average historical allocation behavior with the historical behavior of IP addresses.
The most impactful quantitative finding is that IP scan segmentation offers an 84% reduction in adversarial success across the discussed attack types (dangling DNS, firewall bypasses, etc.), even in the worst-case scenarios across hundreds of years of simulated allocation and varied parameters. In scenarios where IP pools are well-managed, the ability of adversaries to exploit these vulnerabilities is "virtually eliminated."
Finally, the research demonstrates the practicality and scalability of these proposed policies. EIPM was used to evaluate policies on pools of over 10 million addresses, exceeding the size of any major public cloud region or availability zone today. The simulations ran for hundreds of years of allocation at thousands of times real-time speed on single CPU cores, proving that these policies are computationally feasible for global-scale implementation by cloud providers. Furthermore, evaluation against real-world allocation data from Google's cluster data 2019 dataset showed that the policies actually outperform their synthetic trace results, indicating their robust effectiveness in practical cloud environments.
Technical Deep Dive
▶ Watch: Introducing EIPM: Elastic IP address simulator for evaluation (4:10)
The core of this research lies in moving beyond the simplistic random allocation policy currently employed by public cloud providers, which inadvertently enables widespread adversarial exploitation. To address this, Eric Pauley and his team developed and evaluated new, security-conscious allocation policies using a specialized simulation framework.
The primary tool for this evaluation is the Elastic IP Address Simulator (EIPM). EIPM is an open-source, large-scale simulator designed to model the IP address allocation behaviors of major public cloud providers. It allows researchers to:
- Simulate large-scale IP pools: Capable of handling over 10 million addresses, exceeding typical cloud region sizes.
- Incorporate diverse workloads: Utilizes both synthetic traces and real-world allocation data (e.g., Google's cluster data 2019 dataset) to represent benign tenant behavior.
- Model sophisticated adversaries: Simulates attackers employing advanced techniques, including the ability to perform civil attacks (creating unlimited cloud accounts).
- Evaluate new policies: Provides a platform to test the effectiveness of novel allocation strategies against defined threat models.
Initially, the research explored a simpler "smart policy" called IP tagging, first introduced at S&P22. The mechanism for IP tagging is straightforward:
- When an IP address is released by a tenant, the system "remembers" that this specific IP was previously used by that tenant.
- When a tenant requests a new IP address, the system preferentially allocates a free IP that the tenant has used before.
The intent behind IP tagging was to make it harder for attackers seeking many unique IP addresses to achieve their goal; they would instead repeatedly receive the same IP. Evaluations under a simplified threat model (where adversaries use a single cloud account) showed IP tagging to be quite successful, dramatically reducing attack success rates as pool utilization increased. However, this policy had a critical limitation: it failed under the civil attack model, where adversaries can bypass tenant-ID-based tracking by creating an unlimited number of cloud accounts, a realistic scenario given the prevalence of stolen payment credentials.
To overcome this limitation, the team developed IP scan segmentation, a more robust and heuristic-based policy. This approach focuses on identifying and segmenting the address space based on observed allocation behavior, rather than relying solely on tenant identity. The key mechanisms of IP scan segmentation are:
- Tenant Behavior Tracking: For each tenant, the system tracks their average historical allocation duration. Adversaries performing IP pool scanning typically allocate IPs for very short periods to maximize coverage, a behavior distinct from most benign users.
- IP Behavior Tracking: For each individual IP address, the system tracks how long that IP was previously allocated for.
- Decay Policies: To ensure relevance and adapt to changing behaviors, historical data (both tenant and IP) is subject to decay policies (details are elaborated in the full paper). This allows the system to provide the "right level of segmentation" over time.
- Allocation Logic: At allocation time, when any tenant requests an IP address, they are preferentially given an IP that has similar historical allocation behavior to their own average historical allocation behavior. This creates a feedback loop: if a tenant consistently allocates IPs for short durations (like a scanner), they will tend to receive IPs that have also been historically allocated for short durations.
The goal of IP scan segmentation is to heuristically segment the IP address pool. By matching similar behaviors, the policy effectively separates the addresses frequently used by short-lived, scanning adversaries from those typically used by longer-lived, legitimate tenants. This prevents adversaries from easily acquiring a broad range of IPs used by benign tenants, even if they use multiple cloud accounts. The talk also briefly mentions that while the system aims for similar behavior, random noise is intentionally added to the allocation process. This noise, initially included for "computational tractability reasons," also has the beneficial side effect of reducing the predictability of specific IP assignments, which could otherwise be exploited for targeted attacks (e.g., volumetric denial-of-service attacks).
Demo / Proof of Concept
▶ Watch: IP Tagging: A preliminary smart allocation policy (4:47)
The talk "Secure IP Address Allocation at Cloud Scale" did not feature a live, interactive demonstration in the traditional sense, but rather presented a robust, simulation-based proof of concept and evaluation of the proposed IP allocation policies. The core "demonstration" of the research's efficacy lies in the Elastic IP Address Simulator (EIPM) and the extensive quantitative results derived from its use.
EIPM serves as the central proof of concept tool. It is an open-source, reproducible simulation framework designed specifically to model the complex dynamics of IP address allocation within large-scale public cloud environments. The researchers utilized EIPM to:
- Simulate diverse pool configurations: The simulator can model IP address pools containing over 10 million addresses, a scale larger than any single major public cloud region or availability zone currently in operation. This demonstrates the policies' applicability to real-world cloud infrastructure.
- Replicate real-world workloads: Beyond synthetic traces, EIPM was fed real-world allocation data from Google's cluster data 2019 dataset. This dataset represents actual workloads within Google, providing a realistic benchmark for the policies' performance. The fact that the policies outperformed their synthetic trace results under these real-world conditions further bolsters their practical viability.
- Model sophisticated adversarial behavior: The simulator incorporates advanced adversarial models, including the crucial civil attack model, where attackers can provision an unlimited number of cloud accounts to evade simple identity-based tracking. This ensures that the evaluation is against a realistic and challenging threat.
Through EIPM, the research rigorously evaluated the IP scan segmentation policy. The quantitative results served as the "demonstration" of its effectiveness:
- Significant Attack Reduction: The policy achieved an 84% reduction in adversarial success in the worst-case scenarios, considering a wide range of parameters and hundreds of years of simulated allocation. This percentage is a concrete metric of the policy's defensive capability against attacks like dangling DNS and firewall bypasses.
- Scalability and Performance: The simulations themselves ran for "hundreds of years" of allocation time at "thousands of times real-time speed" on single CPU cores. This demonstrates that the computational overhead of implementing IP scan segmentation is low enough for major cloud providers to deploy it globally today, using their existing data structures.
In essence, the proof of concept is a highly detailed, data-driven simulation that systematically validates the proposed security policies against realistic threats and operational constraints, providing compelling evidence of their practical benefits without requiring a live cloud deployment.
Defensive Implications
▶ Watch: New policy: Behavioral segmentation for secure IP allocation (6:07)
The research on secure IP address allocation has significant implications for various stakeholders within the cloud ecosystem: cloud providers, cloud customers, and security researchers.
For Cloud Providers:
The primary implication is a clear call to action: implement security-aware IP allocation policies like IP scan segmentation. Current random allocation policies are demonstrably insecure and enable widespread exploitation. By adopting these new policies, cloud providers can:
- Enhance Platform Security: Proactively mitigate a broad range of vulnerabilities, including dangling DNS, firewall bypasses, and IP reputation damage, thereby improving the overall security posture of their infrastructure.
- Protect IP Pool Value: Safeguard the reputation of their IP address pools. By segmenting malicious traffic away from benign users, providers can prevent their IP ranges from being blacklisted, ensuring better service quality for legitimate tenants.
- Leverage Existing Infrastructure: The policies are designed to use existing data structures and exhibit high computational performance (thousands of times real-time speed on single CPU cores), making them readily implementable at global scale without requiring massive re-architecting.
- Shape Market Forces: If mainstream providers adopt these policies, it could increase the market pressure for network-level blocking of bulletproof hosting providers, as malicious traffic would become more clearly attributable to specific, less reputable sources. This could lead to a stronger collective defense against cybercrime. The speaker explicitly urges cloud providers to get in touch, advocating for these techniques to become the de facto policy for IP allocation.
For Cloud Customers:
The advice for cloud customers is more nuanced and centers on adopting a defense-in-depth strategy, particularly regarding how they treat public IP addresses:
- Avoid Using Public IPs as Security Principles: This is the most crucial takeaway. Customers should not hard-code public IP addresses into security-critical configurations. This includes:
- DNS Records: Do not directly point DNS records to specific IP addresses, especially for sensitive services. Utilize cloud-native DNS services that integrate with dynamic IP assignments or CNAMEs that abstract the underlying IP.
- Security Groups/Firewall Rules: Avoid creating firewall rules that rely solely on specific public IP addresses for access control. Instead, use identity-based access controls, service-level security policies, or private IP ranges where possible.
- Embrace Defense-in-Depth: Rely on security mechanisms that are not directly tied to the transient nature of public IP allocation. This includes:
- Encryption and TLS: Always use TLS for all sensitive communications, regardless of the underlying IP address. This protects data confidentiality and integrity even if an IP is reallocated to an adversary.
- Authentication and Authorization: Implement strong authentication (e.g., multi-factor authentication) and granular authorization mechanisms at the application layer.
- Service Mesh and Zero Trust: Consider adopting architectural patterns like service meshes and zero-trust principles, where every request is authenticated and authorized, irrespective of its network origin.
For Security Researchers:
The work highlights the power of security modeling and data-driven security research. It demonstrates that combining large-scale simulation with real-world data is a highly effective methodology for:
- Evaluating System Security: Accurately assessing the security performance of complex distributed systems as they are deployed in practice.
- Informing Policy Design: Using empirical evidence to design and refine security policies that are both effective against realistic threats and practical for real-world implementation.
- Driving Innovation: Providing an open-source framework (EIPM) to enable future scientific inquiry and policy development in network security.
Key Takeaways
- IP Addresses as Security Principles: In modern public clouds, IP addresses are increasingly used as security principles, mediating access and routing sensitive data, which creates new vulnerabilities due to their elastic, short-lived allocation.
- Inherent Insecurity of Random Allocation: Current public cloud IP allocation policies, primarily random assignment, enable adversaries to easily scan, allocate millions of unique IP addresses, and exploit vulnerabilities like dangling DNS and firewall bypasses.
- IP Scan Segmentation as a Solution: The proposed IP scan segmentation policy, which heuristically segments the IP address pool based on tenants' and IPs' historical allocation behaviors, offers a robust defense even against sophisticated civil attacks.
- Quantifiable Security Improvement: This new policy demonstrates a significant security enhancement, achieving an 84% reduction in adversarial success in worst-case scenarios and virtually eliminating exploitation under well-managed pool conditions.
- Practicality and Scalability: The evaluated policies are highly practical, scalable to over 10 million addresses, computationally efficient (thousands of times real-time speed on single CPU cores), and proven effective with real-world cloud workloads (Google's cluster data 2019 dataset).
- Call to Action for Cloud Providers and Customers: Cloud providers should adopt these security-aware allocation policies, while cloud customers must avoid using public IP addresses as primary security principles, instead relying on defense-in-depth strategies like TLS and robust application-layer security.
About the Speaker(s)
Eric Pauley is a security researcher, likely affiliated with an academic institution, who presented his work on secure IP address allocation at the NDSS Symposium. His research focuses on rigorous, empirical, and data-driven security, particularly in the context of network distributed systems and cloud environments. At the time of this talk, he indicated he was on the job market, seeking opportunities to continue his work in this field. His presentation highlighted his expertise in designing and evaluating practical security solutions for large-scale cloud infrastructure.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Pauley delivers a genuine research contribution: a well-motivated threat model, a purpose-built simulation framework, and a concrete policy (IP scan segmentation) with quantified results against a realistic civil attack model. This is the kind of systems security work that belongs at NDSS — it solves a real, underappreciated problem and leaves the field with an open-source tool to build on.
Heather Calloway (CISO) — WEAK
Technically rigorous work on a real structural vulnerability in cloud IP allocation — but it stops at the research boundary and never crosses into institutional action. The defender guidance is generic, and cloud providers are addressed as if a conference talk is the leverage point.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025