Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Jinsong Chen, Qi Liu, Shujun Tang, Youhao Li, Baojun Liu, Haixin Duan, Min Yang
Abstract
In the digital age, device search engines such as Censys and Shodan play crucial roles by scanning the internet to catalog online devices, aiding in the understanding and mitigation of network security risks. While previous research has used these tools to detect devices and assess vulnerabilities, there remains uncertainty regarding the assets they scan, the strategies they employ, and whether they adhere to ethical guidelines.
This study presents the first comprehensive examination of these engines’ operational and ethical dimensions. We developed a novel framework to trace the IP addresses utilized by these engines and collected 1,407 scanner IPs. By uncovering their IPs, we gain deep insights into the actions of device search engines for the first time and gain original findings. By employing 28 honeypots to monitor their scanning activities extensively in one year, we demonstrate that users can hardly evade scans by blocklisting scanner IPs or migrating service ports. Our findings reveal significant ethical concerns, including a lack of transparency, harmlessness, and anonymity. Notably, these engines often fail to provide transparency and do not allow users to opt out of scans. Further, the engines send malformed requests, attempt to access excessive details without authorization, and even publish personally identifiable information(PII) and screenshots on search results. These practices compromise user privacy and expose devices to further risks by potentially aiding malicious entities. This paper emphasizes the urgent need for stricter ethical standards and enhanced transparency in the operations of device search engines, offering crucial insights into safeguarding against invasive scanning practices and protecting digital infrastructures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0edcc335-8a44-4626-9e34-8e8df67c57c3Cited by top-tier papers3
- Censys: A Map of Internet Hosts and ServicesZakir Durumeric, Hudson Clark, Jeff Cody, Elliot Cubit et al.SIGCOMM 2025 · 6 citations
- Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version IdentificationJinsong Chen, Mengying Wu, Geng Hong, Baichao An et al.USENIX Security 2025
- Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level RisksAnna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah et al.CCS 2026
Builds on6
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Resident Evil: Understanding Residential IP Proxy as a Dark ServiceXianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu et al.S&P 2019 · 80 citations
- Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove MiraiOrçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama et al.NDSS 2019 · 57 citations
- Good Bot, Bad Bot: Characterizing Automated Browsing ActivityXigao Li, Babak Amin Azad, Amir Rahmati, Nick NikiforakisS&P 2021 · 45 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
Related papers
- Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network DataRyan Pickren, Animesh Chhotaray, Frank Li, Saman A. Zonouz et al.CCS 2024 · 5 citations
- Trust but Verify: An Assessment of Vulnerability Tagging ServicesSzu-Chun Huang, Harm Griffioen, Max van der Horst, Georgios Smaragdakis et al.USENIX Security 2025
- Landing Reinforcement Learning onto Smart Scanning of The Internet of ThingsJian Qu, Xiaobo Ma, Wenmao Liu, Hongqing Sang et al.INFOCOM 2022 · 9 citations
- ScannerGrouper: A Generalizable and Effective Scanning Organization Identification System Toward the Open WorldXin He, Enhuan Dong, Jiyuan Han, Zhiliang Wang et al.CCS 2025
- Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy ResearchFlorian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz et al.S&P 2024 · 17 citations
