FINDING · EVALUATION
Cloud-hosted services represent an open measurement problem for ZMap because IPs are shared, ephemeral, and behind CDN layers, making traditional IP-to-service attribution unreliable. The paper identifies reconciling scan-based observation with cloud infrastructure as a key challenge for the next decade.
From 2024-durumeric-ten-years-zmap — Ten Years of ZMap · Abstract — open problems · 2024 · Internet Measurement Conference
Implications
- Hosting circumvention infrastructure behind shared cloud or CDN IPs exploits the same measurement gap that makes ZMap attribution unreliable — blocking the IP collaterally blocks thousands of legitimate services, raising the political cost of blocking.
- Domain-fronting and CDN-based tunneling derive their censor-resistance partly from this cloud measurement gap; as censors develop better cloud-attribution techniques, these defenses will need to evolve toward SNI-blind or ECH-protected variants.
Tags
Extracted by claude-sonnet-4-6 — review before relying.