Skip to content

Trust but Verify: An Assessment of Vulnerability Tagging Services

This is a draft agenda: changes are still being made.

Speaker:
Szu-Chun Huang, TU Delft
Date:
Time:
Room:
Side Room
Session:
Security
Duration:
15 min
Transcript:
Not Available
Meetecho chat:
Not Available
Type:
Talk
Slides:
Add to calendar

Abstract

Internet-wide scanning services are widely used for attack surface discovery across organizations and the Internet. Enterprises, government agencies, and researchers rely on these tools to assess risks to Internet-facing infrastructure. However, their reliability and trustworthiness remain largely unexamined. This work addresses this gap by comparing results from three commercial scanners – Shodan, ONYPHE, and LeakIX – with findings from our independent experiments using verified Nuclei templates, designed to identify specific vulnerabilities through crafted benign requests. We found that the payload-based detections of Shodan are mostly confirmed. Yet, Nuclei finds many more vulnerable endpoints, so defenders might face massive underreporting. For Shodan’s banner-based detections, the opposite issue arises: a significant overreporting of false positives. This indicates that banner-based detections are unreliable. Moreover, three commercial services and Nuclei scans exhibit significant discrepancies. Our work has implications for industry users, policymakers, and the many academic researchers who rely on the results provided by these attack surface management services. By highlighting their shortcomings in vulnerability monitoring, this work serves as a call for action to advance and standardize such services to enhance their trustworthiness.

Recording

Video will be added soon.

Speaker

Szu-Chun Huang

Szu-Chun Huang

Szu-Chun has a background in Computer Science and began her PhD in Feb 2023. Her research focuses on scanning and benchmarking internet-wide vulnerabilities and aims to investigate the hidden factors influencing security patching behaviors.

Rate this talk

Rating will open: Monday, 18 May 2026 09:00 (+0100).