programming:internet_scanning
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| programming:internet_scanning [2026/09/17 02:09] – Hand audit of the 173 scan_fold HAND verdicts + ZMap/XMap reconciliation with design:dns; ACTIVE 245->242; 40 figures refreshed. Authored by Claude karel.kubicek.claude | programming:internet_scanning [2026/09/17 02:37] (current) – Review passes applied: Spoki's ZMap is a closed veth loop, so ACTIVE 242->241; fixed a 174/173 self-contradiction and a 46-vs-44 denominator. Authored by Claude karel.kubicek.claude | ||
|---|---|---|---|
| Line 15: | Line 15: | ||
| ^ Name ^ Definition ^ Papers ^ | ^ Name ^ Definition ^ Papers ^ | ||
| | **SCAN** | '' | | **SCAN** | '' | ||
| - | | **ACTIVE** | names, as a tool it **used or produced**, an instrument //of active scanning//: an address-space scanner, a banner grabber, a reachability sweep, a remote censorship-probing platform, or an IPv6 target generator. Two edges of that rule are judgement calls, stated here rather than buried: a **censorship platform** (OONI, Censored Planet, Quack, Satellite — 23 papers) counts whether the paper ran the probes or re-analysed the platform' | + | | **ACTIVE** | names, as a tool it **used or produced**, an instrument //of active scanning//: an address-space scanner, a banner grabber, a reachability sweep, a remote censorship-probing platform, or an IPv6 target generator. Two edges of that rule are judgement calls, stated here rather than buried: a **censorship platform** (OONI, Censored Planet, Quack, Satellite — 23 papers) counts whether the paper ran the probes or re-analysed the platform' |
| - | **ACTIVE** is this page's population and it is a **floor**, not a census. It is decided by the instrument, not by the extractor' | + | **ACTIVE** is this page's population and it is a **floor**, not a census. It is decided by the instrument, not by the extractor' |
| - | The gap between the two numbers is itself a result. **534 of the 930 SCAN papers (57.4%) never name a '' | + | The gap between the two numbers is itself a result. **534 of the 930 SCAN papers (57.4%) never name a '' |
| ===== Which instrument ===== | ===== Which instrument ===== | ||
| - | Folded families over the 242 ACTIVE papers. The share column is of ACTIVE, and a paper can name several. | + | Folded families over the 241 ACTIVE papers. The share column is of ACTIVE, and a paper can name several. |
| - | ^ Family ^ What it does ^ Papers ^ Share of 242 ^ Spellings in the corpus ^ | + | ^ Family ^ What it does ^ Papers ^ Share of 241 ^ Spellings in the corpus ^ |
| - | | **ZMap** | stateless IPv4 address-space scanner: sends one probe per target and keeps no per-connection state, so a single machine can walk the whole space. IPv6 comes from forks and successors — the '' | + | | **ZMap** | stateless IPv4 address-space scanner: sends one probe per target and keeps no per-connection state, so a single machine can walk the whole space. IPv6 comes from forks and successors — the '' |
| - | | nmap | host and service discovery on a target list; keeps per-target state and does far more per host, so it does not scale to the address space — see the 1300x figure below | 45 | 18.6% | 10 | | + | | nmap | host and service discovery on a target list; keeps per-target state and does far more per host, so it does not scale to the address space — see the 1300x figure below | 45 | 18.7% | 10 | |
| - | | **ZGrab / ZGrab2** | application-layer follow-up: opens its own connection to the hosts ZMap found (ZMap itself is stateless and RSTs), completes the protocol handshake and records the transcript | **32** | 13.2% | 7 | | + | | **ZGrab / ZGrab2** | application-layer follow-up: opens its own connection to the hosts ZMap found (ZMap itself is stateless and RSTs), completes the protocol handshake and records the transcript | **32** | 13.3% | 7 | |
| - | | //a home-grown scanner// | the paper wrote its own, or called it "a custom scanner" | + | | //a home-grown scanner// | the paper wrote its own, or called it "a custom scanner" |
| - | | ping / fping / hping | reachability sweeps | 18 | 7.4% | 7 | | + | | ping / fping / hping | reachability sweeps | 18 | 7.5% | 7 | |
| | **XMap** | ZMap-family scanner built for IPv6 as well as IPv4 | **16** | 6.6% | 3 | | | **XMap** | ZMap-family scanner built for IPv6 as well as IPv4 | **16** | 6.6% | 3 | | ||
| - | | TLS banner grabbers | sslscan, sslyze, testssl.sh, TLS-Scanner, | + | | TLS banner grabbers | sslscan, sslyze, testssl.sh, TLS-Scanner, |
| | OONI | volunteer-run censorship measurement | 7 | 2.9% | 3 | | | OONI | volunteer-run censorship measurement | 7 | 2.9% | 3 | | ||
| | Geneva | evolves packet sequences that evade a censor | 6 | 2.4% | 1 | | | Geneva | evolves packet sequences that evade a censor | 6 | 2.4% | 1 | | ||
| Line 40: | Line 40: | ||
| | Goscanner, LZR, QScanner, Karma | Go and QUIC grabbers, IoT scanners | 2 each | | | | | Goscanner, LZR, QScanner, Karma | Go and QUIC grabbers, IoT scanners | 2 each | | | | ||
| - | **Thirty-seven more families are named by exactly one paper each** — but only **20** of those are a tool the paper itself // | + | **Thirty-seven more families are named by exactly one paper each** — but only **20** of those are a tool the paper itself // |
| <WRAP tip> | <WRAP tip> | ||
| Line 46: | Line 46: | ||
| </ | </ | ||
| - | **These counts are corpus-wide, | + | **These counts are corpus-wide, |
| ==== Current, historical, superseded — dated 2026-09-10 ==== | ==== Current, historical, superseded — dated 2026-09-10 ==== | ||
| Line 56: | Line 56: | ||
| | 2014–2017 | 45 | 27 (60.0%) | 4 (8.9%) | 8 (17.8%) | 0 | 1 | 7 (15.6%) | | | 2014–2017 | 45 | 27 (60.0%) | 4 (8.9%) | 8 (17.8%) | 0 | 1 | 7 (15.6%) | | ||
| | 2018–2021 | 55 | 21 (38.2%) | 9 (16.4%) | 15 (27.3%) | 0 | 0 | 5 (9.1%) | | | 2018–2021 | 55 | 21 (38.2%) | 9 (16.4%) | 15 (27.3%) | 0 | 0 | 5 (9.1%) | | ||
| - | | 2022–2024 | 86 | 25 (29.1%) | 9 (10.5%) | 13 (15.1%) | 10 (11.6%) | 3 | 6 (7.0%) | | + | | 2022–2024 | 85 | 24 (28.2%) | 9 (10.6%) | 13 (15.3%) | 10 (11.8%) | 3 | 6 (7.1%) | |
| | 2025–2026* | 44 | 21 (47.7%) | 10 (22.7%) | 4 (9.1%) | 6 (13.6%) | 0 | 4 (9.1%) | | | 2025–2026* | 44 | 21 (47.7%) | 10 (22.7%) | 4 (9.1%) | 6 (13.6%) | 0 | 4 (9.1%) | | ||
| Line 63: | Line 63: | ||
| * **Masscan is historical in this corpus.** Four papers, none after 2024, and its newest GitHub Release is **1.3.2, from 2021-01-31** (the repository is not archived and was pushed 2026-04-23). {[durumeric2024_years]} also relays a measured reason to prefer ZMap, from Adrian et al.: //" | * **Masscan is historical in this corpus.** Four papers, none after 2024, and its newest GitHub Release is **1.3.2, from 2021-01-31** (the repository is not archived and was pushed 2026-04-23). {[durumeric2024_years]} also relays a measured reason to prefer ZMap, from Adrian et al.: //" | ||
| * **XMap is the newcomer, and it is an IPv6 story.** Sixteen papers, **all of them 2023 or later**, 6 in the provisional window. It exists because the ZMap design does not extend to a 128-bit address space unchanged. | * **XMap is the newcomer, and it is an IPv6 story.** Sixteen papers, **all of them 2023 or later**, 6 in the provisional window. It exists because the ZMap design does not extend to a 128-bit address space unchanged. | ||
| - | * **Rolling your own has not gone away** — 4 of the 46 papers in the provisional window still do — but it has fallen from a quarter of the earliest bucket to under a tenth. | + | * **Rolling your own has not gone away** — 4 of the 44 papers in the provisional window still do — but it has fallen from a quarter of the earliest bucket to under a tenth. |
| ===== The invocation a reviewer accepts ===== | ===== The invocation a reviewer accepts ===== | ||
| Line 145: | Line 145: | ||
| The wire-rate column assumes **84 bytes of wire time per probe** — a bare TCP SYN is 54 bytes, ZMap's default '' | The wire-rate column assumes **84 bytes of wire time per probe** — a bare TCP SYN is 54 bytes, ZMap's default '' | ||
| - | **What the literature reports.** Two probes over the 242 ACTIVE papers' | + | **What the literature reports.** Two probes over the 241 ACTIVE papers' |
| <file python scan_budget.py> | <file python scan_budget.py> | ||
| Line 392: | Line 392: | ||
| {[durumeric2024_years]}' | {[durumeric2024_years]}' | ||
| - | **How rare is this?** The loose blocklist probe fires on **104 of 242 ACTIVE papers (43.0%)** and the first-person one on **89 (36.8%)**, but hand-reading | + | **How rare is this?** The loose blocklist probe fires on **103 of 241 ACTIVE papers (42.7%)** and the first-person one on **88 (36.5%)**, but hand-reading |
| Two figures worth carrying. Durumeric et al. {[durumeric2014_view]} report that after years of running the largest academic scanning operation of its day, //" | Two figures worth carrying. Durumeric et al. {[durumeric2014_view]} report that after years of running the largest academic scanning operation of its day, //" | ||
| Line 409: | Line 409: | ||
| {[durumeric2015_search]} describes exactly this for Censys' | {[durumeric2015_search]} describes exactly this for Censys' | ||
| - | **In the corpus**: the loose source-address probe matches **168 of 242 (69.4%)** and the first-person one **113 (46.7%)**, with **6 of a 10-paper sample** genuine — about **68 papers, a little over a quarter**, describe any of this. Abuse-complaint handling is discussed by **45 (18.6%)** on the first-person probe (upper bound; no precision measured). Two more probes, both loose and neither hand-audited, | + | **In the corpus**: the loose source-address probe matches **167 of 241 (69.3%)** and the first-person one **112 (46.5%)**, with **6 of a 10-paper sample** genuine — about **67 papers, a little over a quarter**, describe any of this. Abuse-complaint handling is discussed by **45 (18.7%)** on the first-person probe (upper bound; no precision measured). Two more probes, both loose and neither hand-audited, |
| <WRAP tip> | <WRAP tip> | ||
| Line 427: | Line 427: | ||
| ^ Query ^ Population ^ Papers ^ Share ^ | ^ Query ^ Population ^ Papers ^ Share ^ | ||
| | mentions IPv6 anywhere | SCAN 930 | 281 | 30.2% | | | mentions IPv6 anywhere | SCAN 930 | 281 | 30.2% | | ||
| - | | mentions IPv6 anywhere | ACTIVE | + | | mentions IPv6 anywhere | ACTIVE |
| | names an IPv6-targeting instrument in '' | | names an IPv6-targeting instrument in '' | ||
| | full text says " | | full text says " | ||
| Line 442: | Line 442: | ||
| ZMap hands you a column of source addresses. That is not a result, and the step that turns it into one is where scanning papers most often overreach. | ZMap hands you a column of source addresses. That is not a result, and the step that turns it into one is where scanning papers most often overreach. | ||
| - | * **An address is not an organisation.** The [[Design:IP classification]] page exists for the join — ASN, geolocation, | + | * **An address is not an organisation.** The [[Design:IP classification]] page exists for the join — ASN, geolocation, |
| * **An address is not a name.** Reverse DNS is not injective and is often absent; a certificate' | * **An address is not a name.** Reverse DNS is not injective and is often absent; a certificate' | ||
| * **A responding address is not a distinct machine.** In IPv6 this is aliasing, above. In IPv4 it is anycast, load balancers and CDNs: the same content answers from thousands of addresses, and "N hosts run X" quietly becomes "N addresses answered" | * **A responding address is not a distinct machine.** In IPv6 this is aliasing, above. In IPv4 it is anycast, load balancers and CDNs: the same content answers from thousands of addresses, and "N hosts run X" quietly becomes "N addresses answered" | ||
| Line 450: | Line 450: | ||
| ===== What to report ===== | ===== What to report ===== | ||
| - | The methods paragraph a reviewer should be able to find, and how often the 242 ACTIVE papers actually contain each part. Schema fields are counted from the extraction; probe rows are the hand-corrected estimates from the sections above and are marked. | + | The methods paragraph a reviewer should be able to find, and how often the 241 ACTIVE papers actually contain each part. Schema fields are counted from the extraction; probe rows are the hand-corrected estimates from the sections above and are marked. |
| - | ^ What ^ ACTIVE (242) ^ SCAN (930) ^ | + | ^ What ^ ACTIVE (241) ^ SCAN (930) ^ |
| | The **scanner and its version** — version of the scanner itself, not of some tool | **20 (8.3%)** | 20 (2.2%) | | | The **scanner and its version** — version of the scanner itself, not of some tool | **20 (8.3%)** | 20 (2.2%) | | ||
| - | | Any used-or-produced tool version at all | 116 (47.9%) | 401 (43.1%) | | + | | Any used-or-produced tool version at all | 115 (47.7%) | 401 (43.1%) | |
| - | | **Vantage location** you scanned from | 135 (55.8%) | 487 (52.4%) | | + | | **Vantage location** you scanned from | 134 (55.6%) | 487 (52.4%) | |
| - | | Vantage infrastructure (cloud, university, residential) | 165 (68.2%) | 612 (65.8%) | | + | | Vantage infrastructure (cloud, university, residential) | 164 (68.0%) | 612 (65.8%) | |
| | **Probe rate** //(probe estimate)// | ~34 (~14%) | — | | | **Probe rate** //(probe estimate)// | ~34 (~14%) | — | | ||
| - | | **Exclusion list honoured** //(probe estimate)// | ~45 (~19%) | — | | + | | **Exclusion list honoured** //(probe estimate)// | ~48 (~20%) | — | |
| | **Opt-out offered** //(probe estimate)// | ~63 (~26%) | — | | | **Opt-out offered** //(probe estimate)// | ~63 (~26%) | — | | ||
| - | | **Source-address hygiene** //(probe estimate)// | ~68 (~28%) | — | | + | | **Source-address hygiene** //(probe estimate)// | ~67 (~28%) | — | |
| - | | Ethics review outcome | 92 (38.0%) | 290 (31.2%) | | + | | Ethics review outcome | 92 (38.2%) | 290 (31.2%) | |
| - | | Notified affected parties | 184 (76.0%) | 560 (60.2%) | | + | | Notified affected parties | 184 (76.3%) | 560 (60.2%) | |
| - | | Harm mitigation described | 209 (86.4%) | 700 (75.3%) | | + | | Harm mitigation described | 208 (86.3%) | 700 (75.3%) | |
| - | | Measurement start date | 193 (79.8%) | 656 (70.5%) | | + | | Measurement start date | 192 (79.7%) | 656 (70.5%) | |
| - | | Own artifact URL | 145 (59.9%) | 506 (54.4%) | | + | | Own artifact URL | 144 (59.8%) | 506 (54.4%) | |
| **Eight per cent name the version of the scanner they ran.** That is the worst row on the table and the easiest to fix: ZMap's behaviour has changed materially inside the version range this corpus covers — {[durumeric2024_years]} records that //"In early 2024, ZMap changed its default behavior to use random per-probe IP IDs"//, | **Eight per cent name the version of the scanner they ran.** That is the worst row on the table and the easiest to fix: ZMap's behaviour has changed materially inside the version range this corpus covers — {[durumeric2024_years]} records that //"In early 2024, ZMap changed its default behavior to use random per-probe IP IDs"//, | ||
| Line 498: | Line 498: | ||
| ===== Methodology and limitations of these figures ===== | ===== Methodology and limitations of these figures ===== | ||
| - | Every number above is a count of **papers**, from the 5,859-paper extraction, with its denominator in the same sentence or table header. Sentinels ('' | + | Every number above is a count of **papers**, from the 5,859-paper extraction, with its denominator in the same sentence or table header. Sentinels ('' |
| Four limitations to carry: | Four limitations to carry: | ||
| * **ACTIVE is a floor.** A paper that scanned and named its scanner something unique outside '' | * **ACTIVE is a floor.** A paper that scanned and named its scanner something unique outside '' | ||
| - | * **The four practice rows are probe estimates on samples of 10–12.** Read "about a fifth", | + | * **The four practice rows are probe estimates on samples of 10–12.** Read "about a fifth", |
| * **'' | * **'' | ||
| - | * **The hand verdicts have been read once, by one reader.** All 173 were audited against each tool's '' | + | * **The hand verdicts have been read once, by one reader.** All 173 were audited against each tool's '' |
| * **2025–2026 venue-years are provisional** and the corpus is seven venues. Network-measurement work also appears at PAM, TMA, ANRW, CoNEXT and ACSAC, **none of which are in this corpus** — for scanning specifically that is a bigger gap than for the web pages on this site, and several instrument papers this literature leans on are published there. Do not take that as a claim about any specific tool above — Yarrp' | * **2025–2026 venue-years are provisional** and the corpus is seven venues. Network-measurement work also appears at PAM, TMA, ANRW, CoNEXT and ACSAC, **none of which are in this corpus** — for scanning specifically that is a bigger gap than for the web pages on this site, and several instrument papers this literature leans on are published there. Do not take that as a claim about any specific tool above — Yarrp' | ||
programming/internet_scanning.txt · Last modified: by karel.kubicek.claude
