University of California, Irvine
Internet Measurement Research at UC Irvine
You are probably here because you saw connection attempts from
128.195.32.11 in a firewall log, an IDS alert or an abuse
report. That address is scanner1.ics.uci.edu, a research
measurement host operated deliberately by the Donald Bren School of Information &
Computer Sciences at the University of California, Irvine. This page explains what it
does and how to have your networks excluded.
At a glance
- What it is
- An academic network measurement host, operated by the University of California, Irvine — Donald Bren School of Information & Computer Sciences.
- What it does
- Makes connection attempts to publicly reachable addresses and records what the service there presents to any client that connects.
- How to stop it
- Opt out — section 1 below. Email us and we will exclude your networks, and/or block the address at your firewall.
- Contact
- ics-network-measurement@uci.edu
Can I opt out of these measurements?
Yes. We honor opt-out requests, and you do not need to justify one.
Email us and we will exclude your networks
Send the address ranges you want excluded, in CIDR notation, to:
ics-network-measurement@uci.edu
Ranges you send are added to the exclusion list used by measurements from this host.
Blocking 128.195.32.11 at your firewall also works and takes
effect immediately, but emailing us stops the packets being sent at all.
Why am I receiving connection attempts from this host?
These connections are part of computer science research at the University of California, Irvine. We make connection attempts to publicly reachable addresses and record what the services there present to any client; for hosts that respond, the connection may continue into a normal protocol exchange. Taken together across many addresses, those observations let researchers study how the Internet is actually built and operated — which protocols and software are deployed, how they are configured, and how that changes over time.
What this host does
- Attempts connections to publicly reachable addresses.
- Records responses that the service presents to any client.
- Sends from its own IPv4 address, which has matching forward and reverse DNS.
- Serves this page from that same host and address.
What this host does not do
- Attempt to exploit vulnerabilities or bypass access controls.
- Guess, brute-force or submit passwords or other credentials.
- Modify, disrupt or reconfigure anything on the systems it contacts.
- Attempt to reach systems or data that are not already publicly served.
Each address is contacted infrequently, and the traffic any single address receives from this host is intended to be negligible. It is not conducting a denial-of-service attack. If the volume you are seeing is not negligible, please tell us — that would be a bug, and we want to know.
We do not publish a port or protocol list on this page. If you send us a few log lines, we will confirm whether the traffic was ours and tell you what it was.
Why are you collecting this data?
The data collected consists only of information that is already publicly visible on the Internet. It supports academic study of how network protocols, software and security technologies are deployed and configured in practice — for example, how widely a protocol change or a security improvement has actually been adopted, and which classes of systems remain misconfigured or unpatched. Work of this kind depends on observations of the real Internet rather than of laboratory networks.
This work is carried out as academic research within the university, and is subject to the University of California’s policies governing research and the use of its network.
Contacting us
Questions, complaints, abuse reports and opt-out requests all go to the same mailbox: ics-network-measurement@uci.edu. To help us respond, please include whatever of the following you have:
- The IP address or CIDR ranges affected — that is, your networks.
- A few log lines, with timestamps and the time zone or UTC offset.
- The destination ports involved, if your logs show them.
- Whether you want an opt-out, an explanation, or both.
If this traffic caused an operational problem on your network — not just log noise — please say so in the subject line so that it is not missed.