Temporal Characterization of Device Vulnerabilities on the Brazilian Internet Using Shodan Data

Abstract


Understanding how vulnerabilities evolve in Internet-connected devices is important so that network operators can prioritize security efforts. In this paper, we perform a temporal characterization of vulnerabilities in devices exposed on the Brazilian Internet using Shodan data. The main challenge is to reliably identify the same physical device across multiple observations, since IP addresses may change over time. To address this, we combine the identification of static IPs, used as ground truth, with a device identifier derived from SSL/TLS attributes (the SHA-256 fingerprint and the common name field of X.509 certificates), validated with a specificity of 0.99 and an AUC of 0.72. Applying this approach to devices exposed between 2024 and mid-2025, we observe that critical vulnerabilities are the most persistent, remaining active for more than eight months, and that sectors outside the technology hub, such as Education and Public Administration, concentrate the highest proportions of critical risk.

References

Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J. A., Invernizzi, L., Kallitsis, M., Kumar, D., Lever, C., Ma, Z., Mason, J., Menscher, D., Seaman, C., Sullivan, N., Thomas, K., and Zhou, Y. (2017). Understanding the Mirai Botnet. In 26th USENIX Security Symposium (USENIX Security 17).

Bai, K. Z. and Fossaceca, J. M. (2025). EM-AUC: A Novel Algorithm for Evaluating Anomaly Based Network Intrusion Detection Systems. Sensors, 25(1):21.

Bennett, C., Abdou, A., and van Oorschot, P. C. (2021). Empirical scanning analysis of Censys and Shodan. In Proceedings of the 2021 Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb).

Cardoso, G., Oliveira, L., and Ítalo Cunha (2024). Identificação de Endereços IP Dinâmicos com Dados Públicos. In Anais do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais.

Durumeric, Z., Wustrow, E., and Halderman, J. A. (2013). ZMap: Fast internet-wide scanning and its security applications. In Proceedings of the 22nd USENIX Security Symposium.

Genge, B. and Enăchescu, C. (2016). ShoVAT: Shodan-based vulnerability assessment tool for internet-facing services. Security and Communication Networks, 9(15):2696–2714.

Georg, M., Rodrigues, W., Alves, C., Silveira Junior, A., and Nunes, R. (2023). Os desafios da Segurança Cibernética no setor público federal do Brasil: estudo sob a ótica de gestores de tecnologia da informação. RISTI - Revista Ibérica de Sistemas e Tecnologias de Informação, E54:602–616.

Liang, C., Yu, B., Xie, W., Wang, B., and Peng, W. (2022). Fine-grained identification for large-scale iot devices: A smart probe-scheduling approach based on information feedback. Applied Sciences, 12(16).

Lopes, B. S. (2026). Segurança da Informação em Ambientes de Internet das Coisas (IoT): Desafios, Vulnerabilidades e Estratégias de Proteção. Revista Ibero-Americana de Humanidades, Ciências e Educação, 12(3):1–22.

Matherly, J. (2015). Complete Guide to Shodan: Collect. Analyze. Visualize. Make Internet Intelligence Work for You. Leanpub.

O’Hare, J., Macfarlane, R., and Lo, O. (2019). Identifying Vulnerabilities Using Internet-Wide Scanning Data. In Proceedings of the IEEE 12th International Conference on Global Security, Safety and Sustainability (ICGS3).

Ponce, L., Cunha, I., Matos, I., Ítalo Cunha, Fazzion, E., Hoepers, C., Steding-Jessen, K., Chaves, M., Guedes, D., and Meira Jr., W. (2024). Arcabouço Multi-motor para Detecção de Vulnerabilidades na Internet Brasileira. In Anais do XLII Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos. SBC.

Qu, J., Ma, X., Liu, W., Sang, H., Li, J., Xue, L., Luo, X., Li, Z., Feng, L., and Guan, X. (2024). On Smartly Scanning of the Internet of Things. IEEE/ACM Transactions on Networking, 32(2):1019–1034.

Safi, M., Dadkhah, S., Shoeleh, F., Mahdikhani, H., Molyneaux, H., and Ghorbani, A. (2022). A Survey on IoT Profiling, Fingerprinting, and Identification. ACM Transactions on Internet of Things, 3(4):1–22.
Published
2026-09-01
MATOS, Isabelle et al. Temporal Characterization of Device Vulnerabilities on the Brazilian Internet Using Shodan Data. In: BRAZILIAN SYMPOSIUM ON CYBERSECURITY (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 332-347. DOI: https://doi.org/10.5753/sbseg.2026.29323.

Most read articles by the same author(s)

<< < 1 2 3 4 5 6 > >>