Introducing Shodan Trends

Shodan was originally designed as a tool to understand how technology use is changing on the Internet. The information collected from the Shodan crawlers would be able to provide users with a data-driven view of what the Internet looks like; i.e. not based on surveys or sampling of popular websites. Which FTP software is most popular? How quickly is my hosting provider patching services? Which countries are running most of the VPNs? There were others that provided the information for web servers but I wanted to offer it for everything that's online - not just the web. I'm happy to announce that we now have a website that does that and more:

https://trends.shodan.io

At Shodan, we've always kept a full history for every IP that we've ever seen on the Internet. You can look at the history for individual IPs using the?new website?or the?API/ CLI. However, we never indexed that historical data in the search engine so you couldn't see how results have changed over time unless you wrote your own scripts to periodically query Shodan. With?Shodan Trends?you can now search the historical data to answer large-scale questions about the Internet. And we're making this new feature available to all members at no additional cost (see FAQ below).

Technology Trends

Shodan Trends shines when looking up the history of more complex queries but you can just as easily also get a?breakdown of web server software. It turns out that in 2021, nginx overtook Apache as the most popular web server software on the Internet.

No alt text provided for this image

And of course we can do the same for other software as well. For example, here is a breakdown of?FTP software:

No alt text provided for this image

The sharp increase in 2018 for?Pure-FTPd?is due to GoDaddy's use of the software.

We can also detect protocol-level trends such as the?decline in Telnet?use across the Internet:

No alt text provided for this image

Telnet has seen a 33% decline over the past year and 63% over the past 2 years. And at the same time there's been a significant increase in?services that are using Let's Encrypt:

No alt text provided for this image

Both of those are trends are positive and show that encrypted services are becoming the norm.

However, we're also seeing that some users are increasingly putting services on non-standard ports instead of properly securing them. The following is a chart of Modbus services running on port 503 (the standard port is 502). Note that the Modbus protocol doesn't support authentication or encryption and should never be directly exposed to the Internet:

No alt text provided for this image

Mysteries of the Internet

Sometimes weird things happen on the Internet and it's not exactly clear why. For example, below is a trend chart for VPN services (tag:vpn):

No alt text provided for this image

Why was there such a huge spike in 2018? Lets break it down by country and see if that provides any insights:

No alt text provided for this image

It looks like an ISP in China for a short time was responding to all VPN handshake requests. The practice stopped after a few months and it's unclear why they did so.

FAQ

  1. How much does it cost? A trend search uses 1 query credit if that search isn't yet cached. Any Shodan account that has query credits is able to use Shodan Trends - there aren't any additional costs.
  2. Can I download the trend data? Yes, you can export the trend information as a CSV.
  3. How far back does it go? We've indexed data going back to 2017. Technically, Shodan has data from as old as 2015 but we haven't yet indexed it in Shodan Trends. We will be adding older data over time.

要查看或添加评论,请登录

John Matherly的更多文章

  • Trends in Internet Exposure

    Trends in Internet Exposure

    More companies are going remote due to COVID-19 and as a result there's been a lot of speculation around how this…

    8 条评论
  • Analyzing Post-WannaCry SMB Exposure

    Analyzing Post-WannaCry SMB Exposure

    It's been a month since the WannaCry ransomware attack wrecked havoc across Windows networks via SMB and I'd like to…

    5 条评论
  • Understanding SSL Usage by Country

    Understanding SSL Usage by Country

    Real-world borders don't necessarily translate to the Internet but it can still reveal useful information as shown by…

    2 条评论
  • 49,153 PB of Memory Available

    49,153 PB of Memory Available

    I've written and presented on the topic of insecure databases for nearly 2 years now. The example I use the most to…

  • 684.8 TB of Data Exposed by Publicly Accessible MongoDB Servers

    684.8 TB of Data Exposed by Publicly Accessible MongoDB Servers

    In light of the recent incident of MacKeeper exposing 13 million accounts through a public, unauthenticated MongoDB…

    2 条评论
  • Tracking HTTP/2.0 Adoption

    Tracking HTTP/2.0 Adoption

    HTTP/2.0 is the next version of the protocol powering websites and it promises many improvements over HTTP/1.

    5 条评论
  • Top 10 Website Hackers for June

    Top 10 Website Hackers for June

    I wanted to revisit the results of an earlier post this year on how to track website defacements and see how things…

    4 条评论
  • Challenges in Taking Things Offline

    Challenges in Taking Things Offline

    Shodan has been in the news for the past few years largely due to the discoveries that security researchers have made…

    8 条评论
  • Hiding in Plain Sight

    Hiding in Plain Sight

    A common reaction I get when talking about devices exposed on the Internet is something like the following:…

    2 条评论

社区洞察

其他会员也浏览了