Research ethics
Internet measurement touches real networks and real people. This study follows the field's established ethical norms — and holds itself to them publicly.
Frameworks we follow
Conduct is guided by two touchstones of the internet-measurement community: the Menlo Report (ethical principles for information & communication technology research) and the ZMap scanning best practices. Everything below is a commitment we invite you to hold us to.
Menlo Report principles
| Principle | How this study applies it |
|---|---|
| Respect for persons | Only data an anonymous visitor could already see is collected; no individuals are targeted or profiled. The scanning agent's own source is anonymized in each record. Captures are point-in-time and can be removed on request. |
| Beneficence | Harm is minimized: a deliberately slow scan rate, only five common web ports, no authentication / exploitation / fuzzing, and an honored exclusion list. The aim is to understand exposure, not to increase it. |
| Justice | Sampling is uniform and untargeted, so no network or region is singled out for scrutiny; findings and data are shared openly rather than held privately. |
| Respect for law & public interest | Transparent about who is scanning and why, responsive to abuse reports via a human-monitored contact, and committed to responsible disclosure of what is found. |
ZMap best-practices checklist
| Practice | Status |
|---|---|
| Minimize scan rate & footprint | Commitment — slow, continuous sampling on five ports only. |
| Signal intent (rDNS, WHOIS, a webpage) | Partial — every HTTP fetch uses a self-identifying User-Agent and links here. The scanner address is not currently published. |
| Provide an opt-out mechanism | Commitment — CIDR exclusion list, honored within two days (below). |
| Test new scanning code locally first | Commitment — changes are exercised against our own systems before release. |
| Coordinate with local network operators | Commitment — scanning runs from infrastructure whose operator is aware of it. |
| Responsibly disclose findings | Commitment — see the disclosure policy. |
Opt out
Operators who do not want their addresses observed can be excluded permanently. Send the IP or CIDR range you control to the abuse contact; it is added to the exclusion list and agents stop capturing it within two days. Existing records for those addresses can be removed on request — there is no automatic expiry. Full instructions and the current traffic identification method are on the scan-info page.