Internet mapping and research outfit Censys reveals state-based abuse, harassment
- Reference: 1756878307
- News link: https://www.theregister.co.uk/2025/09/03/censys_abuse_sigcomm_paper/
- Source link:
Censys started life in 2015 as an academic project that aimed to scan the internet and provide data to the research community. In 2017 the project formed a company that now provides a comprehensive map of the internet that it says can help cyber-defenders to find threats and respond before they create a problem.
Universities are being used to proxy offensive government operations, turning research access decisions political
The company continues to provide data to researchers, but in a [1]paper [PDF] it will present at the SIGCOMM conference next week, admits “Equitably operating a research program is more challenging than we anticipated.”
“While it is easy to verify the identity of well-established researchers with a Google Scholar profile or presentations at conferences like Blackhat or BSides, these constitute only a small fraction of requests,” the paper states.
Most requests come from “independent researchers and students who have no public reputation,” the paper states. Censys has therefore established evaluation criteria that include submission of a clear research plan, researchers’ intention to publicly disseminate results, and receiving confirmation that work is conducted independently or as part of a non-profit or academic institution. An internal team reviews applications from researchers and applies those criteria.
[2]
But the work isn’t easy.
[3]
[4]
“Many students lack coherent research plans and without significant back-and-forth, it is difficult to discern between poorly written requests, requests from first-time researchers exploring, and fabricated plans,” the paper states.
[5]8,000+ Asus routers popped in 'advanced' mystery botnet plot
[6]Mobsters now overlap with cybercrime gangs and use AI for evil, Europol warns
[7]Here's what happens if you don't layer network security – or remove unused web shells
[8]Thousands of Juniper Networks devices vulnerable to critical RCE bug
“We struggle to process many international requests because of language barriers and mounting evidence that universities are being used to proxy offensive government operations in some countries, turning research access decisions political,” it continues, before observing that Censys staff have recently seen “malicious actors use the research program to identify vulnerable systems.”
The company has responded by establishing “multiple access tiers that provide delayed access or access to a subset of data.”
Sometimes the process turns nasty.
[9]
“Much to our surprise, it is not uncommon for researchers to send vitriolic messages, accusations, and, in rare cases, threats,” the paper reveals, noting that such abuse “can quickly turn program administration into a thankless job, similar to the experiences expressed by open source maintainers.”
The purpose of the paper is to inform the networking and security communities about the evolution of Censys, because the company feels it hasn’t documented its history in research literature. The paper therefore reveals that Censys can now see 794 million IPv4 services, up from 275 million in 2015, and has improved its ability to scan for IPv6 systems and name-addressed HTTP(S) services.
The document also explains how Censys scans the internet, and asserts its data is more accurate than rivals like Shodan, Fofa, ZoomEye, and Netlas. ®
Get our [10]Tech Resources
[1] https://dl.acm.org/doi/pdf/10.1145/3718958.3754344
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aLgRt0u3TLTJ2bCdtmElvQAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aLgRt0u3TLTJ2bCdtmElvQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aLgRt0u3TLTJ2bCdtmElvQAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/05/29/8000_asus_routers_popped_in/
[6] https://www.theregister.com/2025/03/24/modern_mafiosos_wield_ai/
[7] https://www.theregister.com/2024/11/22/cisa_red_team_exercise/
[8] https://www.theregister.com/2024/01/15/juniper_networks_rce_flaw/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aLgRt0u3TLTJ2bCdtmElvQAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: How ironic!
100% agree.
Ydy for instance 1372 connection attempts from censys to my dual-homed mail server. 775 over one connection, 597 over the other.
Connections (ydy) were from 6 /24's
162.142.125.0
167.94.138.0
167.94.145.0
167.94.146.0
199.45.154.0
206.168.34.0
48% of attempts resolved to censys-scanner.com, 52% to nxd.
And this goes on day after day, and has done for years.
Connections attempts from censys total 7% of all connections attempts I see, and I imagine it'll be about same for everyone else not behind CGNAT.
Censys (and others doing same) have a complete flippin' cheek doing it.
Even the slowest of slow horses have bolted from that draughty old rotten stable
‘Universities are being used to proxy offensive government operations, turning research access decisions political’
Such is long ago well known to be both the destiny and fate of any illuminating research, and thus be why nowadays is access to sensitive and top secret research/information/intelligence a closed private affair for exclusive global executive administration being diligently denied by all means possible and imaginable to offensive government officers/bellicose political puppets and pathetic public muppets.
And that is not a question shared for future verification. It is a current and presently difficult unverifiable fact and poses any perverse elite and corrupted political office systems a dire straits existential threat if not treated and afforded with every necessary courtesy acknowledging the radical fundamental and revolutionary change of state in universal circumstances.
Re: Even the slowest of slow horses have bolted from that draughty old rotten stable
Machine translation? Try new software, doesn't read well in English.
Re: Re: Even the slowest of slow horses have bolted from that draughty old rotten stable
Machine translation? Try new software, doesn't read well in English. .... Anonymous Coward
The English is easily read, AC, therefore the difficulty you have is probably private and certainly personal and shared as you apparently displaying a deficit of comprehensive understanding. Tackle it in smaller bits and/or byte size pieces and that can be helpful.
Would it be easier for you if Google Translated into Chinese (traditional) ‽ .....
眾所周知,任何啟發性的研究都注定要經歷這樣的命運。正因如此,如今獲取敏感且絕密的研究/資訊/情報,已成為全球行政部門專屬的私人事務,並被竭盡所能地拒絕讓那些咄咄逼人的政府官員/好戰的政治傀儡和可悲的公眾傀儡獲取。
而這個問題並非為了將來的驗證而公開。這是一個當下難以驗證的事實,如果不以一切必要的禮遇來對待和承認普遍情況下國家發生的根本性和革命性變革,它將對任何腐敗的精英和腐敗的政治辦公系統構成可怕的生存威脅。
.... or how about a DeepL leap with a translation into Russian ....
Давно известно, что это судьба и рок любого просветительского исследования, и именно поэтому в настоящее время доступ к конфиденциальной и строго секретной информации/разведданным является закрытым частным делом, доступным исключительно для глобальной исполнительной власти, который всеми возможными и мыслимыми средствами тщательно скрывают от агрессивных правительственных чиновников/воинственных политических марионеток и жалких публичных марионеток.
И это не вопрос, который можно проверить в будущем. Это актуальный и в настоящее время труднопроверяемый факт, который представляет собой серьезную угрозу существованию любой извращенной элиты и коррумпированной политической системы, если к нему не отнестись с должным уважением и не признать радикальные фундаментальные и революционные изменения в государстве в универсальных обстоятельствах.
Переведено с помощью DeepL.com (бесплатная версия)
...... or are those also somewhat too alien for you to make good and great use of?
How ironic!
My server logs showed Censys-based abuse and harassment - talk about pounding on the door. Even to the point of attempting logins on certain services. That got shut down proper quick, feckin leeches.