Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Jinsong Chen, Qi Liu, Shujun Tang, Youhao Li, Baojun Liu, Haixin Duan, Min Yang
摘要
In the digital age, device search engines such as Censys and Shodan play crucial roles by scanning the internet to catalog online devices, aiding in the understanding and mitigation of network security risks. While previous research has used these tools to detect devices and assess vulnerabilities, there remains uncertainty regarding the assets they scan, the strategies they employ, and whether they adhere to ethical guidelines.
This study presents the first comprehensive examination of these engines’ operational and ethical dimensions. We developed a novel framework to trace the IP addresses utilized by these engines and collected 1,407 scanner IPs. By uncovering their IPs, we gain deep insights into the actions of device search engines for the first time and gain original findings. By employing 28 honeypots to monitor their scanning activities extensively in one year, we demonstrate that users can hardly evade scans by blocklisting scanner IPs or migrating service ports. Our findings reveal significant ethical concerns, including a lack of transparency, harmlessness, and anonymity. Notably, these engines often fail to provide transparency and do not allow users to opt out of scans. Further, the engines send malformed requests, attempt to access excessive details without authorization, and even publish personally identifiable information(PII) and screenshots on search results. These practices compromise user privacy and expose devices to further risks by potentially aiding malicious entities. This paper emphasizes the urgent need for stricter ethical standards and enhanced transparency in the operations of device search engines, offering crucial insights into safeguarding against invasive scanning practices and protecting digital infrastructures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Censys: A Map of Internet Hosts and ServicesZakir Durumeric, Hudson Clark, Jeff Cody, Elliot Cubit 等SIGCOMM 2025 · 被引用 6 次
- Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version IdentificationJinsong Chen, Mengying Wu, Geng Hong, Baichao An 等USENIX Security 2025
- Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level RisksAnna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah 等CCS 2026
它引用的顶会 Paper6
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Resident Evil: Understanding Residential IP Proxy as a Dark ServiceXianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu 等S&P 2019 · 被引用 80 次
- Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove MiraiOrçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama 等NDSS 2019 · 被引用 57 次
- Good Bot, Bad Bot: Characterizing Automated Browsing ActivityXigao Li, Babak Amin Azad, Amir Rahmati, Nick NikiforakisS&P 2021 · 被引用 45 次
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten 等S&P 2022 · 被引用 41 次
相关 Paper
- Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network DataRyan Pickren, Animesh Chhotaray, Frank Li, Saman A. Zonouz 等CCS 2024 · 被引用 5 次
- Trust but Verify: An Assessment of Vulnerability Tagging ServicesSzu-Chun Huang, Harm Griffioen, Max van der Horst, Georgios Smaragdakis 等USENIX Security 2025
- Landing Reinforcement Learning onto Smart Scanning of The Internet of ThingsJian Qu, Xiaobo Ma, Wenmao Liu, Hongqing Sang 等INFOCOM 2022 · 被引用 9 次
- ScannerGrouper: A Generalizable and Effective Scanning Organization Identification System Toward the Open WorldXin He, Enhuan Dong, Jiyuan Han, Zhiliang Wang 等CCS 2025
- Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy ResearchFlorian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz 等S&P 2024 · 被引用 17 次
