Talk With an Expert

To Block or not to Block? Impact and Analysis of Actively Blocking Shodan Scans

To Block or not to Block? Impact and Analysis of Actively Blocking Shodan Scans (PDF, 4.99MB)Published: 22 Oct, 2018
Created by
Andre Shori

This paper details an experiment constructed to evaluate the effectiveness of blocking Shodan search engine scans in reducing overall attack traffic volumes. Shodan is considered to be part of an attacker's toolset, and there is a persistent perception that blocking Shodan Scans will reduce an organization's attack surface. An attempt was made to determine what effect, if any, such a block would result in by comparing attacker traffic before and after implementing a block on Shodan scans, and by determining the complexity of performing such a block. The analysis here may provide defenders and managers with useful data when deciding on whether or not to devote resources to blocking Shodan or other similar internet-connected device search engines.