Internet-scanning U-M startup offers new approach to cybersecurity

January 25, 2018
Written By:
News Service
Contact:
  • umichnews@umich.edu
Screenshots of the Censys homepage and of a report generated with the tool. Image courtesy: Censys

Screenshots of the Censys homepage and of a report generated with the tool. Image courtesy: Censys

ANN ARBOR—Rolling out what it’s calling a “street view for cyberspace,” Censys—a tech startup based on technology developed at the University of Michigan—has launched a commercially available version of its internet-wide scanning tool.

Based on technology developed in the lab of U-M computer science and engineering professor J. Alex Halderman, Censys continuously scans the internet, analyzing every publicly visible server and device. It uses the data that comes back to create a dynamic, searchable snapshot of the entire internet.

Censys is designed to be a cybersecurity defense tool for IT experts working to secure large networks, which are composed of a constantly changing array of devices ranging from servers to smartphones and internet-of-things devices.

One unsecured device is all it takes for a hacker to break in, and there’s currently no good way for IT experts to get a comprehensive view of their own networks. Today, they must often battle hackers and other online threats without a complete understanding of their network’s vulnerabilities. Censys aims to change that.

Alex Halderman. Image credit: Joseph Xu, Michigan Engineering

Alex Halderman. Image credit: Joseph Xu, Michigan Engineering

“Network security doesn’t have to be black magic,” Halderman said. “So much of security practice is based on untested assumptions, but in fact security can be quantified and studied the same way we use data to study human health.”

Censys has been available for free to noncommercial users since it began as a U-M research project in 2015. During that time, it’s been used in hundreds of peer-reviewed studies and helped researchers better understand some of the most significant internet security threats of recent years, Halderman said.

Over the past six months, the team worked closely with the U-M Office of Technology Transfer to license the technology and form a new company, making it available to commercial customers. Now, IT experts can use it to search for every device on their domain and get back a detailed view of their public internet footprint, as well as analytics outlining vulnerabilities.

The data that powers Censys will also be available for license by companies who wish to build their own applications around it. Censys data will remain available free of charge for noncommercial use.

During the scanning process, Censys performs a brief data exchange called an “application-layer handshake” with every device that has a public internet address. It then dissects the data that comes back, pulling out useful nuggets of information like protocol, device type, manufacturer, software version and age.

Censys also has tools that can scan for specific vulnerabilities. The system is designed so that additional scanners can be added as new threats emerge.

Halderman says that internet-wide scanning isn’t new—hackers have known about it for years. In fact, it’s relatively common for them to use collections of hijacked machines called botnets to troll for vulnerable systems. In Halderman’s view, Censys levels the playing field by making global scanning data available to internet defenders, including IT professionals and researchers.

ZMap is an open-source tool that can perform a scan of the entire public IPv4 address space on the internet in fewer than 45 minutes, aiding researchers in their probing of public digital space. Image credit: Joseph Xu, Michigan Engineering

ZMap is an open-source tool that can perform a scan of the entire public IPv4 address space on the internet in fewer than 45 minutes, aiding researchers in their probing of public digital space. Image credit: Joseph Xu, Michigan Engineering

“It’s similar to Google Street View, where we’re gathering what’s already publicly visible and making it available in one place,” he said. “To extend the analogy, we just take a picture from the sidewalk. We don’t peek in the door, we don’t jiggle the locks.”

Any network that doesn’t wish to be scanned can opt out, though Halderman says such requests have been rare during the five years that the scans have taken place.

Censys is an outgrowth of the ZMap Project, a suite of open-source internet scanning tools that Halderman’s lab began developing U-M in 2013. While the ZMap Project tools remain freely available, Censys builds on them to provide an easy-to-use service that gathers and analyzes data automatically.

The company is based in Ann Arbor and has nine full-time employees. Censys CEO and co-founder Brian Kelly says that companies like Censys are helping to cement Ann Arbor’s status as a hub for tech security companies.

“It’s great to see that investors are no longer shy about investing in a company that isn’t in Silicon Valley, and the talent pool here is phenomenal,” Kelly said. “U-M in particular has been really helpful in creating an environment where we can take software products out of the lab and into the real world.”

The technology behind Censys is detailed in “A Search Engine Backed by Internet-Wide Scanning,” published in the Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security in 2015. The study was authored by Halderman; former U-M computer science and engineering students Zakir Durumeric, David Adrian and Ariana Mirian; and Michael Bailey of the University of Illinois.

 

More information: