ZMap (software)

ZMap
Original author(s)University of Michigan[1]
Developer(s)The ZMap Team[1]
Initial releaseAugust 16, 2013; 11 years ago (2013-08-16)[2]
Stable release
4.2.0 / July 10, 2024; 6 months ago (2024-07-10)[2]
Repositorygithub.com/zmap/zmap
Written inC[2]
Operating systemCross-platform
Available inEnglish
Typecomputer security, network management
LicenseApache License 2.0[2]
Websitezmap.io

ZMap is a free and open-source security scanner that was developed as a faster alternative to Nmap. ZMap was designed for information security research and can be used for both white hat and black hat purposes. The tool is able to discover vulnerabilities and their impact, and detect affected IoT devices.

Using one gigabit per second of network bandwidth, ZMap can scan the entire IPv4 address space in 44 minutes on a single port.[3] With a ten gigabit connection, ZMap scan can complete a scan in under five minutes.[4]

Operation

ZMap architecture[5]

ZMap iterates on techniques utilized by its predecessor, Nmap, by altering the scanning method in a few key areas. Nmap sends out individual signals to each IP address and waits for a reply. As replies return, Nmap compiles them into a database to keep track of responses, a process that slows down the scanning process. In contrast, ZMap uses cyclic multiplicative groups, which allows ZMap to scan the same space roughly 1,300 times faster than Nmap.[6] The ZMap software takes every number from 1 to 232-1 and creates an iterative formula that ensures that each of the possible 32-bit numbers is visited once in a pseudorandom order.[3] Building the initial list of numbers for every IP address takes upfront time, but it is a fraction of what is required to aggregate a list of every sent and received probe. This process ensures that once ZMap starts sending probes out to different IPs, an accidental denial of service could not occur because an abundance of transmissions would not converge on one subnet at the same time.[7]

ZMap also speeds up the scanning process by sending a probe to every IP address only once by default, whereas Nmap resends a probe when it detects a connection delay or fails to get a reply.[8] This results in about 2% of IP addresses being missed during a typical scan, but when processing billions of IP address, or potential IoT devices being targeted by cyberattackers, 2% is an acceptable tolerance.[5]

Usage

ZMap can be used for both vulnerability detection and exploitation.[9][6]

The application has been used for port 443 scans to estimate power outages during Hurricane Sandy in 2013.[5] One of the developers of ZMap, Zakir Durumeric, used his software to determine a computer's online state, vulnerabilities, operating system, and services.[10][11] ZMap has also been used to detect vulnerabilities in universal plug and play devices and search for weak public keys in HTTPS website logs.[12]

See also

References

  1. ^ a b "About the Project". The ZMap Project. Retrieved 10 Aug 2018.
  2. ^ a b c d "GitHub - zmap/zmap". GitHub. 2 Jul 2018. Retrieved 10 Aug 2018.
  3. ^ a b Ducklin, Paul (20 Aug 2013). "Welcome to Zmap, the "one hour turnaround" internet scanner". Sophos. Retrieved 10 Aug 2018.
  4. ^ Adrian, David (2014). "Zippier ZMap: Internet-Wide Scanning at 10 Gbps" (PDF). USENIX Workshop on Offensive Technologies.
  5. ^ a b c Durumeric, Zakir; Wustrow, Eric; Halderman, J. Alex (Aug 2013). "ZMap: Fast Internet-Wide Scanning and its Security Applications" (PDF). Retrieved 9 Aug 2018.
  6. ^ a b De Santis, Giulia (2018). Modeling and Recognizing Network Scanning Activities with Finite Mixture Models and Hidden Markov Models (PDF). Université de Lorraine.
  7. ^ Berko, Lex (19 Aug 2013). "Now You Can Scan the Entire Internet in Under an Hour". Motherboard. Retrieved 10 Aug 2018.
  8. ^ De Santis, Giulia; Lahmadi, Abdelkader; Francois, Jerome; Festor, Olivier (2016). "Modeling of IP Scanning Activities with Hidden Markov Models: Darknet Case Study". 2016 8th IFIP International Conference on New Technologies, Mobility and Security (NTMS). pp. 1–5. doi:10.1109/NTMS.2016.7792461. ISBN 978-1-5090-2914-3. S2CID 12786563.
  9. ^ Durumeric, Zakir; Adrian, David; Mirian, Ariana; Bailey, Michael; Halderman, J. Alex (2015). "A Search Engine Backed by Internet-Wide Scanning". Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security - CCS '15 (PDF). pp. 542–553. doi:10.1145/2810103.2813703. ISBN 9781450338325. S2CID 9808635.
  10. ^ Lee, Seungwoon; Im, Sun-Young; Shin, Seung-Hun; Roh, Byeong-hee; Lee, Cheolho (2016). "Implementation and vulnerability test of stealth port scanning attacks using ZMap of censys engine". 2016 International Conference on Information and Communication Technology Convergence (ICTC). pp. 681–683. doi:10.1109/ICTC.2016.7763561. ISBN 978-1-5090-1325-8. S2CID 13876287.
  11. ^ De Santis, Giulia; Lahmadi, Abdelkader; François, Jérôme; Festor, Olivier. "Internet-Wide Scanners Classification using Gaussian Mixture and Hidden Markov Models". 2018 9th IFIP International Conference on New Technologies, Mobility and Security (NTMS). IEEE: 1–5.
  12. ^ Arzhakov, Anton V; Babalova, Irina F (2017). "Analysis of current internet wide scan effectiveness". 2017 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (EICon Rus). pp. 96–99. doi:10.1109/EIConRus.2017.7910503. ISBN 978-1-5090-4865-6. S2CID 44797603.

Read other articles:

Erick Davis Perempatfinal Piala Emas CONCACAF 2015 di Metlife StadiumInformasi pribadiNama lengkap Erick DavisTanggal lahir 31 Maret 1991 (umur 32)Tempat lahir Colón, PanamaTinggi 180 cm (5 ft 11 in)Posisi bermain BekInformasi klubKlub saat ini Dunajská StredaNomor 31Karier senior*Tahun Tim Tampil (Gol)2015 – Dunajská Streda 61 (6)Tim nasional2010 – Panama 40 (0) * Penampilan dan gol di klub senior hanya dihitung dari liga domestik Erick Davis (lahir 31 Maret 1991)...

 

Halaman ini berisi artikel tentang serial gim video. Untuk gim video pertama serial ini, lihat Air Combat. Ace CombatLogo yang digunakan dari tahun 2004 hingga sekarangAliranSimulasi pertarungan udaraPengembang Project Aces (2001-) Bandai Namco Entertainment (sebelumnya Namco) Access Games (portabel)PenerbitBandai Namco EntertainmentPelantar List of platforms Game Boy AdvanceiOSMicrosoft WindowsNintendo 3DSPlayStationPlayStation 2PlayStation 3PlayStation 4PlayStation PortableXbox 360Xbox One ...

 

Antonov AirlinesBerkas:AntonovAirlines Logo.png IATA ICAO Kode panggil – ADB ANTONOV BUREAU DidirikanApril 1989; 34 tahun lalu (1989-04)PenghubungBandar Udara Leipzig/HalleArmada8-10* (lihat ringkasan armada)Perusahaan indukAntonovKantor pusatKyiv, UkrainaSitus webantonov.com Antonov Airlines adalah maskapai kargo Ukraina, sebuah divisi dari perusahaan penerbangan Antonov. Ini mengoperasikan layanan charter internasional di pasar kargo besar. Basis utamanya adalah Bandara Hostomel deka...

يفتقر محتوى هذه المقالة إلى الاستشهاد بمصادر. فضلاً، ساهم في تطوير هذه المقالة من خلال إضافة مصادر موثوق بها. أي معلومات غير موثقة يمكن التشكيك بها وإزالتها. (يوليو 2020) دوري كرة القدم الإسكتلندي 1915–16 تفاصيل الموسم دوري كرة القدم الإسكتلندي  البلد المملكة المتحدة لبريطان...

 

German politician Karoline Linnert (2014) Karoline Linnert (born 30 August 1958) is a German politician of the Alliance '90/The Greens. From 2007 until 2019, she served as Senator of Finance and Mayor of the city-state of Bremen. During her time in office, she was one of two people holding the title Mayor, the other being Carsten Sieling, the President of the Senate of Bremen.[1] Early life and education Linnert studied psychology at the University of Bielefeld and the University of O...

 

Konsulat Jenderal Republik Indonesia di DubaiKoordinat25°14′53″N 55°16′51″E / 25.248032°N 55.280723°E / 25.248032; 55.280723Lokasi Dubai, Uni Emirat ArabAlamatAl Hudaiba, Community 322, Villa No. 1Bur Dubai, Uni Emirat ArabYurisdiksi Daftar Ajman Dubai Fujairah Ras Al Khaimah Sharjah Konsul JenderalKartika Candra NegaraSitus webkemlu.go.id/dubai/id Konsulat Jenderal Republik Indonesia di Dubai (KJRI Dubai) adalah perwakilan konsuler Indonesia di Dubai, Uni ...

Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Cet article ne s'appuie pas, ou pas assez, sur des sources secondaires ou tertiaires (janvier 2024). Pour améliorer la vérifiabilité de l'article ainsi que son intérêt encyclopédique, il est nécessaire, quand des sources primaires sont citées, de les associer à des analyses faites par des sources secondaires. Institut national des sciences appliquées de StrasbourgHistoireFondation 3 mai 2003Dates-clés ...

 

Синелобый амазон Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:ВторичноротыеТип:ХордовыеПодтип:ПозвоночныеИнфратип:ЧелюстноротыеНадкласс:ЧетвероногиеКлада:АмниотыКлада:ЗавропсидыКласс:Пт�...

 

Pengujian tanah oleh pakar ilmu tanah Analisis tanah atau pengujian tanah adalah aktivitas menganalisis sampel tanah untuk mengetahui kondisi dan karakteristik tanah, seperti nutrien, kontaminasi, komposisi, keasaman, dan sebagainya. Analisis tanah menentukan tingkat kecocokan tanah terhadap aktivitas pertanian dan jenis tanaman yang ditanam. Keberadaan mineral tertentu yang berlebih dapat menyebabkan keracunan bagi tumbuhan, tetapi tumbuhan jenis lain mungkin dapat bertahan.[1] Berba...

2019 American sitcom created by Abby McEnany Work in ProgressOfficial release posterGenreComedyCreated by Abby McEnany Tim Mason Starring Abby McEnany Karin Anglin Celeste Pechous Julia Sweeney Theo Germaine ComposerEthan StollerCountry of originUnited StatesOriginal languageEnglishNo. of seasons2No. of episodes18 (list of episodes)ProductionExecutive producers Abby McEnany Tim Mason Lisa Masseur (pilot) Lilly Wachowski Lawrence Mattis Josh Adler Ashley Berns Julia Sweeney Tony Hernandez Prod...

 

Европейская сардина Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:ВторичноротыеТип:ХордовыеПодтип:ПозвоночныеИнфратип:ЧелюстноротыеГруппа:Костные рыбыКласс:Лучепёрые рыбыПодкласс:Новопёры...

 

Tugboat of the United States Navy USS Segwarusa (YTM-365) and USS Ganadoga (YTM-390) Help USS Canberra (CAG-2) move into position for the International Naval Review, in Hampton Roads, VA, 12 June 1957. History United States NameUSS Segwarusa (YTM-365) BuilderConsolidated Shipbuilding Corporation, Morris Heights, New York Laid down6 March 1944 Launched22 April 1944 In service25 September 1944 Reclassified Harbor Tug (Large), YTB-365, 15 May 1944 District...

1958 American filmPaul BunyanDirected byLes ClarkStory by Lance Nolley Ted Berman Produced byWalt DisneyStarring Thurl Ravenscroft Dal McKennon Narrated byParley BaerMusic byGeorge BrunsAnimation by John Sibley George Nicholas Bob Youngouist George Goepper Fred Kopietz Ken Hultgren Jerry Hathcock Jack Parr Jack Boyd (effects animation) Layouts by Homer Jonas Jack Huber Backgrounds byWalt PeregoyProductioncompanyWalt Disney ProductionsDistributed byBuena Vista DistributionRelease date August&#...

 

محمد بن محمود الآملي معلومات شخصية الميلاد سنة 1300   آمل تاريخ الوفاة سنة 1352 (51–52 سنة)  مواطنة إيران  الحياة العملية المهنة رياضياتي،  وشاعر،  وطبيب  اللغات الفارسية  تعديل مصدري - تعديل   محمد بن محمود الآملي (بالفارسية: محمد بن محمود آملی) طبيب وفيلسوف ...

 

Ethnic group Ukrainian Jewsיהדות אוקראינה‎Українськi євреїThe location of Ukraine in EuropeTotal population2010 est. 71,500 core – 200,000 enlarged [1] 360,000–400,000 by 2014 est. [1][2]Regions with significant populationsKyiv110,000[3]Dnipro60,000[3]Kharkiv45,000[3]Odesa45,000[3]LanguagesRussian (83.0%), Ukrainian[4][5][6][7] (13.4%), Yiddish[4][...

У этой статьи надо проверить нейтральность. На странице обсуждения должны быть подробности.Джахан Поллыева РуководительАппарата Государственной Думы Федерального Собрания Российской Федерации 13 января 2012 года — 5 октября 2016 года Предшественник Сигуткин, Алексей А�...

 

  لمعانٍ أخرى، طالع كوكب القردة (توضيح). كوكب القردةPlanet of the Apes (بالإنجليزية) معلومات عامةالتصنيف فيلم ريبوت الصنف الفني  القائمة ... فيلم خيال علمي[1][2][3] — فيلم ما بعد الكارثة — فيلم أكشن — فيلم خيال تأملي — فيلم ديستوبيا — فيلم مقتبس من رواية — فيلم سفر �...

 

FruttosioFormula di struttura e modello Nomi alternativiD-(-)-fruttosio, L-(+)-fruttosio, levulosio Caratteristiche generaliFormula bruta o molecolareC6H12O6 Massa molecolare (u)180,16 g/mol Aspettosolido da incolore a bianco Numero CAS57-48-7 Numero EINECS200-333-3 PubChem11769129 SMILESC(C(C(C(C(=O)CO)O)O)O)O Proprietà chimico-fisicheDensità (g/cm3, in c.s.)~ 1,65 g/cm³ (20 °C) Solubilità in acqua3760 g/L (20 °C) Temperatura di fusione100 °C (373 K) (decomposizione) In...

American college basketball season 1962–63 Bowling Green Falcons men's basketballMAC ChampionsNCAA tournamentConferenceMid-American ConferenceDivisionEastRankingCoachesNo. 18Record19–8 (9–3 MAC)Head coachHarold AndersonSeasons← 1961–621963–64 → 1962–63 Mid-American Conference men's basketball standings vte Conf Overall Team W   L   PCT W   L   PCT Bowling Green 9 – 3   .750 19 – 8   .704 Ohio 8 – 4 &#...

 

Halaman ini membahas Holandia sebagai sebuah daerah di Belanda. Untuk kegunaan lain silakan melihat Holandia (disambiguasi) Holandia atau Holland adalah nama sebuah daerah di sebelah barat Belanda, yang sekarang terletak di provinsi Holland Selatan dan Holland Utara. Namun kedua provinsi ini tidaklah sama dengan wilayah Holandia. Nama ini berasal dari Holtland atau Holdland, yang artinya adalah tanah kayu dan sekarang kurang lebih terletak di sekitar Leiden. Di luar negeri nama ini terutama d...