Executive Summary
- Zakir Durumeric is an assistant professor of computer science at Stanford University, a co-founder of Censys and a principal contributor to the ZMap measurement ecosystem
- ZMap and related tools turn responses from internet-facing systems into structured evidence about services, domains and certificates, but they do not establish ownership or vulnerability by themselves
- Censys commercialises continuous external measurement for security and attack-surface analysis, making coverage, attribution, freshness and correction processes part of the product
- Durumeric’s wider significance lies in making systemic deployment failures observable while exposing the ethical and institutional limits of large-scale active measurement
In 2013, ZMap changed the time scale of internet measurement
In 2013, a University of Michigan research team showed that the public IPv4 address space could be surveyed on a single port in less than an hour over a gigabit connection under suitable conditions. The achievement did not mean that the internet had been completely mapped. It changed how quickly researchers could ask a narrow question of a very large population and repeat the exercise often enough to measure change.
Zakir Durumeric was a central designer and the lead named author of the original ZMap paper, working with Eric Wustrow and within a wider research group that included J. Alex Halderman and other collaborators. Internet scanning existed long before ZMap, and the project was not the work of one person. Its contribution was to redesign broad active measurement around speed, reproducibility and a clear separation between initial discovery and deeper protocol analysis.
That distinction matters because the public internet has no complete, continuously updated inventory. Organisations frequently have an imperfect view even of their own systems. Cloud addresses change, forgotten services remain online and infrastructure can outlive the team that created it. No central authority records every publicly reachable service, certificate, domain and software deployment.
Active measurement approaches the problem from outside. A system sends a controlled probe to a selected address or name and records the response. Repeated across a large population, the method can show how widely a protocol is deployed, how quickly a vulnerability is remediated, whether insecure defaults persist or how certificate practices change.
The resulting evidence is powerful and bounded. A scan shows what a system presented to one measurement point during a defined interval. Firewalls, network routing, anycast, load balancers, geographic policy and rate limits can all alter the result. An address may represent a cloud platform, a shared service, a temporary workload or a customer hidden behind a provider-controlled endpoint.
Durumeric’s contribution was therefore not a claim to possess a perfect copy of the internet. He helped create a method for observing large parts of its exposed surface systematically, while leaving researchers and users responsible for deciding what those observations mean.
Michigan supplied the environment for a different kind of scanner
Durumeric completed his doctoral work in computer science and engineering at the University of Michigan. The institution provided a setting in which network security, systems engineering, cryptography and empirical internet research could be combined. That combination was necessary because internet-wide scanning depends on more than a fast packet generator.
A workable measurement programme needs network access, target-generation methods, receiver performance, data processing, protocol expertise and procedures for dealing with the organisations contacted by the scan. Researchers must also choose a question narrow enough to justify contacting a large population. The engineering and the research design are inseparable.
Conventional scanners commonly maintain state for each target and connection attempt. That approach is appropriate when an administrator wants detailed information about a defined network, but it becomes expensive when the target population contains billions of possible addresses. Memory, timeouts and connection tracking become constraints before the investigation reaches internet scale.
ZMap was designed around stateless, high-speed probing. For a basic TCP survey, it can transmit a carefully constructed packet without retaining a conventional connection object for every destination. The scanner validates returning responses and passes the results into a separate processing pipeline.
The design moves rather than removes complexity. ZMap must construct packets that can be recognised when replies return, distinguish valid responses from unrelated traffic and prevent its own receiving system from becoming the bottleneck. Target generation must distribute traffic across the address space rather than directing a sustained burst at one network.
Pseudorandom target ordering helps spread the operational burden. Sequential scanning could contact every address in one large prefix before moving to the next, creating a concentrated stream towards one organisation. A permutation distributes those probes more broadly and allows a scan to be divided across correctly configured workers without repeatedly contacting the same targets.
The speed mattered because long scans create internally inconsistent datasets. If a survey takes several weeks, services can be created, removed or reconfigured before the run finishes. A shorter collection window gives researchers a more coherent snapshot and allows them to repeat the measurement after a disclosure, policy change or remediation campaign.
Speed also increases responsibility. A scanner can reach many networks within a short period, trigger security alerts and expose defects in fragile equipment. Rate limits, identifiable source infrastructure, public explanatory pages, monitored contact addresses and exclusion procedures therefore belong to the measurement system rather than being optional public-relations measures.
The scanner was only the first stage
A reply to a basic probe rarely answers the research question by itself. A TCP SYN-ACK may indicate that a port is reachable, but it does not establish the application protocol, software version, security configuration or identity of the organisation operating the service. Durumeric’s wider contribution lies partly in treating scanning as a staged data system rather than a single executable.
ZMap identifies responsive endpoints efficiently. ZGrab, and later ZGrab2, perform more expensive application-layer interactions against the smaller population that responded. Related tools query the domain name system, process cryptographic material and evaluate certificates against technical rules.
This separation makes broad measurement more practical. The discovery stage can use a minimal interaction, while deeper handshakes are reserved for systems relevant to the study. It also improves reproducibility because each stage can record its configuration, tool version and structured output.
ZGrab2 can interact with services including HTTP, Transport Layer Security, Secure Shell and email protocols. Its modules establish documented handshakes and record machine-readable fields rather than relying on analysts to inspect individual banners. Researchers can then compare protocol versions, certificate properties and service behaviour across large populations.
The evidence remains specific to the offered interaction. A server may behave differently when it receives another protocol version, a domain name through Server Name Indication, different request content or a client credential. A load balancer or security gateway may answer instead of the underlying application. The accurate claim is that the endpoint produced a particular response to a particular probe.
ZDNS extends the same approach into the naming system. Large query sets can be executed through a reproducible framework and returned as structured records. Researchers can examine record deployment, authoritative infrastructure, resolver behaviour and domain dependencies without adapting a general-purpose lookup tool into an undocumented batch system.
DNS results depend on time, resolver choice, cache state, geography and network policy. Content-delivery systems often direct different clients to different addresses, while authoritative servers can apply rate limits or tailored responses. ZDNS makes those observations easier to collect; it does not turn one answer into a permanent property of a domain.
Cryptographic tooling, including ZCrypto and ZLint, adds another analytical layer. Certificates and related objects can be parsed and checked against defined technical profiles. At scale, researchers can identify malformed objects, weak keys, unusual extensions, repeated issuance errors and changes in certificate-authority practice.
A lint finding has a narrower meaning than a security verdict. Some checks concern standards compliance or interoperability, while others identify conditions with more direct security consequences. The rule, certificate context, software behaviour and date all affect interpretation.
Together, the tools form a pipeline: discover a responsive endpoint, establish a protocol conversation, collect structured evidence and analyse the resulting object. Each stage filters the population and introduces assumptions. Durumeric’s work helped make those assumptions repeatable enough to be inspected rather than hidden inside one monolithic scan.
Population-scale evidence changed security response
The ZMap ecosystem became important because researchers used it to connect protocol and software weaknesses with real deployment. A vulnerability can be severe in theory and rare in practice, or technically simple and present on millions of systems. Internet-wide measurement provides evidence about that difference.
Durumeric’s early work included large-scale studies of HTTPS and public-key infrastructure. Broad surveys could show which protocol versions remained in use, how certificates were issued, where public keys were reused and whether recommended security changes had reached deployed systems. Those questions cannot be answered reliably through a few selected websites or vendor statements.
One early investigation examined cryptographic keys produced during the Debian OpenSSL random-number-generator failure disclosed in 2008. The defect sharply reduced the possible key space, allowing researchers to compare public keys observed on the internet with known weak values. The study showed that vulnerable keys could remain deployed long after the underlying software flaw had become public.
The lesson extended beyond the particular defect. Publication of a patch or advisory does not establish remediation. Keys, certificates and systems can persist across personnel changes, migrations and organisational boundaries. Measurement can test whether a historical weakness is still visible rather than assuming that disclosure ended the risk.
Heartbleed demonstrated the value and difficulty of rapid measurement during an active security event. The OpenSSL vulnerability, disclosed in April 2014, could allow an attacker to retrieve memory from affected TLS services under certain conditions. Researchers used internet-wide scanning to estimate exposure and monitor how the population changed after disclosure.
The response required more than patching software. Potentially compromised keys and certificates also needed replacement, and revocation practices were uneven. Population evidence showed the difference between the availability of a fix and the completion of remediation across deployed infrastructure.
Testing for a vulnerability can be more intrusive than identifying an open port. A probe may exercise the defective behaviour and, in some cases, retrieve data. Researchers must restrict what they collect, minimise retention and weigh the public value of the measurement against the burden placed on remote systems.
The Logjam research combined cryptographic analysis with evidence about the deployment of Diffie-Hellman parameters. It examined weak export-grade configurations and the reuse of common prime groups, showing how expensive precomputation against a widely shared parameter could affect many services rather than one endpoint.
DROWN exposed another form of cross-system dependency. Support for the obsolete SSLv2 protocol on one service could endanger modern TLS connections under specified conditions, particularly where the same RSA key was reused. Internet-wide data helped reveal relationships among services that might have been managed by different teams but shared cryptographic material.
These projects were collective research efforts, and Durumeric should not receive sole credit for their cryptographic or analytical contributions. His significance lies in helping create the measurement capability through which theoretical protocol weaknesses could be compared with large-scale deployment.
The Mirai investigation extended that approach into an abuse ecosystem. The botnet compromised internet-connected devices through widely known default credentials and generated large distributed denial-of-service attacks. Researchers combined scanning with malware analysis, network telemetry and observations of attack infrastructure to study its growth and targets.
Service responses could help identify likely device populations, but product attribution remained uncertain. Banners can be misleading, devices can share public addresses and manufacturers may reuse software components. The research showed the value of population evidence while also demonstrating why a response pattern must not be treated as an unquestionable device identity.
Across these cases, measurement changed the security conversation. Researchers could estimate prevalence, compare remediation over time and identify shared defaults or dependencies. They could not patch the affected systems, compel owners to act or guarantee that each address had been attributed correctly.
Censys turned a research instrument into a commercial service
Internet-wide measurement began to acquire a different operational role when the data became continuously searchable. Censys originated from the University of Michigan research environment and indexed information about hosts, services and certificates so that users could query the results rather than operate the full collection pipeline themselves.
Durumeric co-founded Censys with David Adrian. The company developed commercial products around internet intelligence, attack-surface management and threat investigation. Public material associated with the profile identifies Durumeric as a founder and chief executive alongside his Stanford faculty role.
The transition from research system to company changed what had to be maintained. A research project can demonstrate a method and publish a dataset. A commercial service must collect continuously, operate storage and search infrastructure, update protocol modules, resolve customer questions, protect sensitive activity and provide dependable access.
Censys changes the economics of outside-in visibility. Before shared internet datasets became widely available, an organisation could build its own scanning system or commission periodic assessments. Maintaining global collection, protocol parsers, historical indexes and attribution models required specialised engineers and substantial infrastructure.
A shared platform spreads that cost across customers. Security teams can search for certificates, hostnames, services and addresses associated with their organisation, then compare the results with internal inventories. The difference can reveal forgotten systems, exposed test environments, third-party services and assets created outside normal processes.
The result remains a lead rather than an automatically verified asset record. A cloud address can belong to a provider while the application belongs to one of its customers. A certificate can carry an old corporate name. A domain can point to a supplier, acquisition target or managed service. Organisations need to reconcile the outside-in observation with contracts, cloud accounts and internal ownership records.
The company also commercialises historical evidence. Security investigators often need to know what was visible before an incident, certificate change or disclosure. A record of when a service first appeared, which certificate it presented and how its protocol behaviour changed can help reconstruct an exposure timeline.
Historical data need the same caution as current scans. An endpoint may be missed during one collection cycle because of loss, maintenance or filtering. A change in parser behaviour can create an apparent trend. Absence from a dataset is not proof that a service was unavailable, and presence at an address does not prove that the same organisation controls it today.
Censys is therefore better described as a continuously constructed external evidence layer than as a complete inventory of the internet. Its value depends on coverage, collection frequency, protocol support, attribution, correction procedures and the ability to show users how a conclusion was reached.
The hardest problem begins after a service responds
Finding a responsive endpoint is often easier than deciding what it represents. An address is a network location, not a stable business identity. Routing records can identify the autonomous system announcing a prefix, while registration data can identify a resource holder. Neither necessarily identifies the customer, application or team responsible for the service.
DNS names, certificates, web content and protocol banners can strengthen attribution. They can also be generic, obsolete or deliberately misleading. Cloud providers own address ranges used by thousands of customers, and content-delivery networks terminate connections on behalf of organisations whose origin systems are elsewhere.
Attribution therefore combines several signals and should produce a level of confidence rather than a categorical answer. Acquisitions, subsidiaries, contractors and managed-service providers make the problem harder. A result attributed incorrectly can waste a customer’s time, misdirect a disclosure or damage the reputation of an organisation that does not control the system.
The same caution applies to software identification. A banner can indicate a product and version while a vendor has backported a security fix without changing the displayed string. A reverse proxy may expose its own software rather than the application behind it. A service can imitate another product or be intentionally configured as a honeypot.
A visible version associated with a vulnerability is not proof of exploitability. The relevant feature may be disabled, a compensating control may be in place or the fingerprint may be wrong. Conversely, a generic response can conceal an affected product. Measurement supports prioritisation; confirmation requires additional evidence.
IPv6 makes population coverage more difficult. The public IPv4 address space is large but enumerable. IPv6 is too large to scan address by address, so researchers construct candidate target sets from DNS, routing data, certificates, traceroutes, passive observations and patterns in address assignment.
Those methods introduce selection bias. Systems absent from public naming or certificate sources may remain invisible. One provider’s addressing scheme may be easier to infer than another’s, while privacy-oriented or rapidly changing addresses are difficult to track. An IPv6 survey usually describes the constructed target population rather than the entire protocol address space.
Cloud infrastructure introduces a different form of instability. Addresses can be reassigned quickly, workloads can exist for only a short period and managed services can separate the visible endpoint from the organisation supplying the application. A record that was correct when collected can become misleading if it is presented without time and attribution context.
Certificates provide a second view of infrastructure. Public logs can expose domain names, issuers, keys and validity periods before a service is reachable through scanning. When combined with DNS and host observations, they can identify relationships that no single source reveals.
A certificate still does not prove that every listed name is active or controlled by the current operator. Certificates can outlive services, include internal names or be issued during abandoned deployment work. Cross-source agreement increases confidence, while disagreement often exposes the limitation that needs investigation.
This translation from packet response to organisational claim is both the commercial and analytical bottleneck. Customers do not pay only to know that an address answered. They need to know what asset it may represent, why it has been associated with them, when the evidence was collected and what action the result justifies.
Measurement can expose infrastructure dependency
Once several evidence sources are joined, internet measurement can describe more than individual hosts. A service may depend on a cloud platform, domain name operator, certificate authority, content-delivery network and identity provider. The concentration of those dependencies can matter even when every individual service is correctly configured.
Durumeric’s broader research has examined how visible infrastructure relationships can be formalised and measured. DNS records, certificates, routing information and service responses can show that large populations rely on a limited number of providers. An outage or policy change at one of those providers may therefore affect organisations that appear independent.
Public evidence cannot reveal every contractual or operational arrangement. A DNS record shows the current provider but not the customer’s migration plan. A certificate issuer is part of the trust chain but may not be the only available issuer. A cloud address does not reveal whether a workload can fail over elsewhere.
Measurement can nevertheless make concentration visible enough to investigate. The object of study becomes the service graph around an organisation rather than the address alone. That expands active measurement from vulnerability research into the economics and governance of digital infrastructure.
The same capability can be misused if a visible dependency is presented as permanent control. Organisations can change suppliers, maintain undisclosed backups or use internal systems that an external scanner cannot see. Dependency evidence is strongest when it identifies an observable relationship and weakest when it claims to know the customer’s full resilience strategy.
Responsible scanning is an operating system, not a disclaimer
Internet-wide scanning contacts systems whose operators did not individually request the measurement. Even a technically valid and low-cost probe can trigger an intrusion alert, consume staff time or expose a defect in old equipment. Responsible operation therefore requires a permanent process rather than a statement of good intentions.
Measurement sources should be identifiable. Reverse DNS and a public information page can explain the purpose of the traffic, the protocols involved and how to contact the operator. The contact channel must be monitored, and the organisation needs authority to pause a scan when an unexpected effect is reported.
Exclusion requests create both an ethical safeguard and a methodological limitation. Removing a network from future scans respects the operator’s decision but creates a blind spot. The excluded population may be systematically different from the remaining targets if critical, security-sensitive or fragile networks are more likely to opt out.
Researchers should preserve the blocklist version and explain how exclusions affect the dataset. The accurate population may be the targeted, routable address space remaining after reserved ranges, opt-outs, failures and local restrictions, rather than an unqualified claim about the entire public internet.
Rate is another policy choice. A source with sufficient bandwidth can transmit faster than a small destination network or fragile device can comfortably receive. Randomised ordering spreads traffic, but a network holding a large address block may still receive many probes. Repeated surveys also create cumulative burden.
The content of the probe matters more than the label attached to the tool. A basic handshake is different from an authentication attempt, exploit check or request that retrieves unintended data. ZMap provides a framework for sending packets; the researcher or operator chooses the interaction and bears responsibility for its effect.
Complaint handling also improves measurement quality. An operator may explain that a response came from a middlebox, honeypot or shared platform. The feedback can reveal false assumptions in the collection method. A scanner that treats remote organisations only as targets loses both legitimacy and useful evidence.
The infrastructure performing the scan needs its own security. It processes untrusted packet and application data, so malformed responses can target parsers or consume resources. Measurement platforms need input validation, isolation, dependency management and vulnerability response like any other exposed service.
Access to the data and packet-generation systems also requires control. A compromised scanner could be redirected towards harmful traffic, while a stolen dataset could reveal infrastructure relationships valuable to attackers. Raw observations, target lists and customer searches should not be treated as harmless research artefacts.
Dual use cannot be removed from the field. The same service fingerprints can support inventory and reconnaissance. Historical records can assist incident reconstruction and attacker planning. Publishing tools lowers barriers for legitimate researchers and for abusive users.
Restricting public research tools would not eliminate large-scale scanning by capable attackers. The more realistic governance model is to preserve transparent methods, safe defaults, documented conduct and accountability for each operator. Durumeric does not control every organisation that downloads ZMap, just as the developer of a network utility does not control every packet later generated with it.
Data cleaning can change the result as much as the scan
Internet-wide measurement produces malformed, duplicated, incomplete and contradictory records. Researchers must decide how to handle retries, timeouts, redirects, shared certificates, protocol errors and banners that do not fit the expected schema.
Those decisions alter the population being described. One address may host hundreds of domains. One service may appear through many addresses. A load-balanced application can return different certificates during the same survey. A parser update can classify an old response differently from the software used in an earlier study.
A defensible project records the data-processing pipeline as carefully as the packet-generation configuration. Tool versions, target lists, exclusions, timestamps, retry behaviour and stage-by-stage attrition help other researchers understand how the final count was produced.
Freshness requirements depend on the intended use. A protocol-adoption study may tolerate periodic snapshots, while incident response and attack-surface management require more current observations. Every record should carry a collection time and enough provenance to distinguish a live finding from historical context.
False positives and false negatives also have different operational costs. A false attribution may send a security team towards an asset it does not own. A missed service may leave real exposure undiscovered. Broad research can report uncertainty across a population, whereas automated enforcement or high-severity customer alerts require stronger evidence.
The appropriate threshold therefore depends on the action attached to the data. A search platform can expose possible associations for investigation. It should not convert every weak signal into a definitive organisational asset merely because a categorical result is easier to display.
No measurement point sees the whole internet
Active measurement reaches targets through the routes, filtering and policies available to the scanner’s network. A survey from North America may receive different responses from one conducted in Asia, Africa or the Middle East. Geofencing, censorship, anycast and regional hosting can all change the observed result.
An address announced from several locations may return the instance selected by Border Gateway Protocol routing for the scanner’s source. A route change can alter the response even when no application configuration has changed. Routing information can help interpret a scan, but control-plane records do not reveal every forwarding decision.
Distributed vantage points improve perspective and increase cost. Each source needs secure operation, identifiable contact details and compliance with the law and provider policies in its jurisdiction. More locations do not create a universal view; they produce several views whose differences can themselves become evidence.
This is why “internet-wide” should describe target breadth rather than omniscience. A platform can contact a large share of the public IPv4 space and still see only the version of each service available from its selected paths.
Passive measurement provides a useful contrast. It records traffic crossing an observation point and can show how real users interact with protocols. It is limited to the links available to the researcher and can involve far more sensitive user data than a controlled active probe.
The two methods answer different questions. Active scanning can show how many endpoints respond to a defined interaction. Passive data can show how much observed traffic uses a protocol. One heavily used service and one million rarely used services produce very different results under those measures.
Institutional diversity also matters. The Center for Applied Internet Data Analysis, or CAIDA, develops topology, routing and measurement infrastructure from a separate institutional base at the University of California San Diego. The ZMap ecosystem concentrates more directly on internet-facing services, cryptographic deployment and exposed infrastructure.
The projects can complement each other without sharing organisational control. Independent instruments and datasets allow researchers to identify blind spots and prevent one collector from becoming the unquestioned source of truth about the internet.
Stanford broadened the measurement agenda
Durumeric is an assistant professor of computer science at Stanford University, where his work covers internet security, trust, safety and measurement. The university gives him a new institutional base for students, collaborators and long-term research while Censys operates the commercial collection and product environment.
The two roles are connected but distinct. Academic research is expected to produce generalisable knowledge and withstand public scrutiny. A company must protect customers, maintain services, differentiate products and generate revenue. Transparency about funding, affiliation and data access is important where research uses commercial infrastructure.
Durumeric’s later work extends beyond exposed hosts and cryptographic deployment. Active measurements can examine censorship by comparing how protocols, domains and services behave across networks and regions. A failed connection may result from filtering, routing, congestion or server policy, so the strongest studies use repeated experiments and several vantage points.
The same empirical approach has expanded into harassment, misinformation and other harmful online systems. Those subjects involve people, platforms and content rather than only packets. The data can be more sensitive, and automated classifications can affect vulnerable individuals or political speech.
This broader agenda shows continuity in method rather than sameness of subject. Researchers construct a dataset about a distributed system, test an observable behaviour and state what the evidence can and cannot establish. The ethical obligations increase when the objects of measurement are people and social activity rather than public protocol responses.
Teaching distributes the capability beyond one laboratory. Students trained in measurement move into universities, security companies, public institutions and technology platforms. The infrastructure impact of an academic group includes the tools and papers it produces, but also the researchers who carry those methods elsewhere.
Durumeric’s awards reflect the establishment of the field. His recognition has included selection for MIT Technology Review’s Innovators Under 35 in 2015 and a Sloan Research Fellowship. A 2024 retrospective on ten years of ZMap documented its adoption across academic and industrial research.
Awards do not validate every dataset or commercial claim. Their significance is that internet-wide active measurement has moved from an unusual systems experiment into a recognised component of security and infrastructure research.
Open tools and proprietary maps now coexist
ZMap and many related tools are open-source software. Researchers can inspect their behaviour, reproduce methods and adapt modules without depending entirely on a commercial provider. Organisations with the necessary capacity can operate their own measurements.
Open availability does not make internet-wide scanning inexpensive or simple. It requires network access, computing, storage, protocol engineering, operational contacts and ethical review. A badly managed deployment can cause harm even when the underlying code is public and technically sound.
Maintenance is another concentration point. Protocols change, parsers need security fixes and new operating systems affect performance. Legal permission to fork a project does not create the engineers required to maintain a credible alternative.
Censys adds continuous operation, product support, attribution and a searchable interface. Subscription revenue can fund engineering and infrastructure that short research grants may not sustain. Customers receive convenience and depend on the provider’s collection choices, update cadence and data model.
Commercial operation also changes disclosure. A research team may publish methods and selected datasets, while a company has reasons to protect proprietary enrichment, customer activity and product logic. The tension is not resolved by labelling one side open and the other closed.
The relevant questions are which collection methods remain inspectable, how errors can be challenged and whether public-interest research retains meaningful access. A commercial map can be valuable without being accepted as a neutral public authority.
Concentration could become a larger issue as security teams, governments and researchers rely on a small number of external intelligence providers. Shared data can reduce duplicated scanning traffic and create a measurement monoculture. If one provider changes coverage or classification, many users may inherit the same blind spot.
A plural system would include open tools, several commercial and academic collectors, transparent methods and mechanisms for comparison. Independent datasets impose cost, but they also prevent one platform’s interpretation from becoming the internet’s de facto official inventory.
Durumeric made the internet more observable, not more governable
Durumeric’s infrastructure impact can be traced through several linked stages. Systems research redesigned high-speed scanning; ZMap made the method reusable; ZGrab2, ZDNS and cryptographic tools turned basic responses into structured evidence; security studies connected that evidence to systemic weaknesses; and Censys converted continuous measurement into a service used by defenders and investigators.
Stanford extends the research programme into infrastructure dependency, censorship, abuse and online safety. Each stage involves different collaborators and institutions, and none should be collapsed into one person’s achievement.
Durumeric has direct authority within his research group and executive responsibility at Censys, subject to university, corporate, board and legal constraints. He can influence research questions, product direction, staffing and the operation of measurement systems.
He does not own the hosts, networks, domains or certificates recorded by those systems. He cannot compel an organisation to patch a service, respond to a disclosure or accept an attribution. He does not control every scan performed with ZMap or every interpretation built from its output.
His authority is methodological, institutional and commercial. He helped define how observations can be gathered and made useful at scale. The consequences remain distributed among system owners, network operators, cloud providers, researchers, customers and public institutions.
That boundary is the central fact of the profile. Internet-wide measurement can reveal systemic failures that no single operator can observe. It cannot supply the governance needed to correct them. Visibility may create pressure, evidence and accountability, but remediation still depends on people and organisations with authority over the affected infrastructure.
Why BTW tracks Zakir Durumeric
BTW tracks Durumeric because digital infrastructure cannot be secured or governed effectively when its externally visible surface is unknown. His work helped turn broad scanning from a slow specialist exercise into a repeatable measurement capability used by researchers and commercial defenders.
The same work exposes the limits of data-driven authority. A map can be incomplete, stale or incorrectly attributed. A reachable service is not necessarily vulnerable, and an address is not a stable organisational identity. A measurement platform can improve accountability while creating new privacy, dual-use and concentration risks.
Durumeric’s career is therefore a case study in measurement becoming infrastructure. Michigan supplied the research environment, the ZMap community created a reusable technical base, Censys added continuous commercial operation and Stanford supports further inquiry and training.
The result is not a central inventory of the internet. It is a powerful external evidence layer whose value depends on transparent methods, current data, responsible operation and institutional plurality.
The next test is not whether scanning can become faster. It is whether the organisations producing these maps can make consequential findings traceable, correctable and comparable without allowing one partial view to harden into unquestioned ground truth.
Principal evidence and unresolved questions
The principal evidence for this profile includes Stanford University records, Durumeric’s professional and publication history, ZMap project documentation, Censys leadership and product material, and peer-reviewed studies using the measurement ecosystem. Together, these sources establish his roles, the design and influence of ZMap, his involvement in Censys and the broader programme of internet-security research.
Project and company sources describe their own tools and operations. They should not be treated as independent proof of complete coverage, accurate attribution in every case or the effectiveness of every commercial product feature.
The unresolved questions concern both measurement quality and institutional power. External coverage remains difficult across IPv6, short-lived cloud systems, regionally filtered services and networks that exclude scanners. Attribution errors can affect research findings, customer workflows and public claims, yet comprehensive error rates are not publicly established.
Commercial development raises further questions. It is not always clear which datasets, collection methods and correction procedures will remain publicly inspectable as paid services expand. Independent collectors face substantial operating costs, while reliance on one shared dataset can reduce methodological diversity.
Measured organisations also need credible ways to contest or correct inaccurate records without turning opt-out into a means of hiding legitimate public evidence. Search platforms must prevent the same capabilities used for defence from becoming a low-cost source of harmful reconnaissance.
Those tensions will determine whether active internet measurement develops as a plural public evidence layer or consolidates into a small number of proprietary maps.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
