◊ Ethics

Research ethics

Internet measurement touches real networks and real people. This study follows the field's established ethical norms — and holds itself to them publicly.

Frameworks we follow

Conduct is guided by two touchstones of the internet-measurement community: the Menlo Report (ethical principles for information & communication technology research) and the ZMap scanning best practices. Everything below is a commitment we invite you to hold us to.

Menlo Report principles

PrincipleHow this study applies it
Respect for personsOnly data an anonymous visitor could already see is collected; no individuals are targeted or profiled. The scanning agent's own source is anonymized in each record. Captures are point-in-time and can be removed on request.
BeneficenceHarm is minimized: a deliberately slow scan rate, only five common web ports, no authentication / exploitation / fuzzing, and an honored exclusion list. The aim is to understand exposure, not to increase it.
JusticeSampling is uniform and untargeted, so no network or region is singled out for scrutiny; findings and data are shared openly rather than held privately.
Respect for law & public interestTransparent about who is scanning and why, responsive to abuse reports via a human-monitored contact, and committed to responsible disclosure of what is found.

ZMap best-practices checklist

PracticeStatus
Minimize scan rate & footprintCommitment — slow, continuous sampling on five ports only.
Signal intent (rDNS, WHOIS, a webpage)Partial — every HTTP fetch uses a self-identifying User-Agent and links here. The scanner address is not currently published.
Provide an opt-out mechanismCommitment — CIDR exclusion list, honored within two days (below).
Test new scanning code locally firstCommitment — changes are exercised against our own systems before release.
Coordinate with local network operatorsCommitment — scanning runs from infrastructure whose operator is aware of it.
Responsibly disclose findingsCommitment — see the disclosure policy.

Opt out

Operators who do not want their addresses observed can be excluded permanently. Send the IP or CIDR range you control to the abuse contact; it is added to the exclusion list and agents stop capturing it within two days. Existing records for those addresses can be removed on request — there is no automatic expiry. Full instructions and the current traffic identification method are on the scan-info page.

References

Kenneally, E. & Dittrich, D. (2012). The Menlo Report: Ethical Principles Guiding Information and Communication Technology Research. U.S. Dept. of Homeland Security.
Durumeric, Z., Wustrow, E. & Halderman, J. A. (2013). ZMap: Fast Internet-Wide Scanning and its Security Applications. USENIX Security. See "Scanning Best Practices."