
A Scan-Based Analysis of Internet-Exposed IoT Devices Using Shodan Data
DOI:
https://doi.org/10.30564/jeis.v8i2.13448Abstract
Determining whether scan-observable network configurations capture meaningful characteristics of security exposure across large-scale Internet of Things (IoT) populations remains an open problem in measurement research. This study analyzes Internet-exposed IoT endpoints associated with the TR-069 protocol across a global population exceeding 37 million hosts, using a structured sample of 7,634 hosts derived from approximately 10,000 hosts identified via Shodan Search and Shodan InternetDB. Data were collected during a fixed observation window in April 2026 across ten countries with the highest observed prevalence of transmission control protocol (TCP) port 7547 exposure. Scan-derived metadata, including open ports, service indicators, customer premises equipment (CPE) identifiers, vulnerability-associated fields, and network attribution metadata, were used to construct a composite exposure proxy representing externally observable service-surface characteristics. The analysis combines descriptive statistics, the Kruskal–Wallis H test, and exploratory feature separability analysis to assess geographic variation and whether service-level characteristics differentiate exposure groups. Results show statistically significant cross-country variation in exposure structure. Logistic regression and random forest analyses produced limited feature separability, with the random forest approach achieving a balanced accuracy of 0.58. These findings suggest that Internet-wide scan data can support systematic population-level analysis of IoT exposure while highlighting the limitations of port-based features as indicators of broader exposure characteristics. The study provides a reproducible framework for large-scale exposure measurement using passive scan data without requiring device interaction or exploit-based validation.
Keywords:
Internet of Things; Security; Risk Assessment; Data Analysis; Cybersecurity; Artificial Intelligence for IT Operations (AIOps)References
[1] Bakhshi, T., Ghita, B., Kuzminykh, I., 2024. A review of IoT firmware vulnerabilities and auditing techniques. Sensors. 24(2), 708.
[2] Alshammari, B.M., 2025. A machine learning-based framework for measuring attack surfaces of IoT systems. IEEE Access. 13, 134297–134311.
[3] Rajasekar, V.R., Rajkumar, S., 2023. A study on internet of things devices vulnerabilities using shodan. International Journal of Computing. 22(2), 149–158.
[4] Yaben, R., Vasilomanolakis, E., 2025. Digital ghost ships: Abandoned, neglected, and obsolete IoT and OT devices exposed to the internet. TechRxiv. DOI: https://doi.org/10.36227/techrxiv.174838052.25233921/v1
[5] Li, R., Li, Q., Lin, T., et al., 2024. Deviceradar: Online iot device fingerprinting in isps using programmable switches. IEEE/ACM Transactions on Networking. 32(5), 3854–3869.
[6] Liang, B.-H., Hwang, R.-H., Lin, J.-Y., et al., 2025. Comprehensive vulnerability detection and malware infection testing strategies for IoT devices. IEEE Internet of Things Journal. 12(12), 20556–20571.
[7] Haseeb, J., Mansoori, M., Welch, I., 2020. A measurement study of IoT-based attacks using IoT kill chain. In Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guangzhou, China, 29 December 2020–1 January 2021; pp. 557–567.
[8] Srinivasa, S., Pedersen, J.M., Vasilomanolakis, E., 2021. Open for hire: Attack trends and misconfiguration pitfalls of IoT devices. In Proceedings of the 21st ACM Internet Measurement Conference, Online, 2–4 November 2021; pp. 195–215.
[9] Mishra, R., Mishra, A., 2025. Current research on internet of things (IoT) security protocols: A survey. Computers & Security. 151, 104310.
[10] Dritsas, E., Trigka, M., 2025. A survey on cybersecurity in IoT. Future Internet. 17(1), 30.
[11] Durumeric, Z., Adrian, D., Stephens, P., et al., 2024. Ten years of ZMap. In Proceedings of the 2024 ACM Internet Measurement Conference, Madrid, Spain, 4–6 November 2024; pp. 139–148.
[12] Kayas, G., Hossain, M., Payton, J., et al., 2021. Supnp: Secure access and service registration for upnp-enabled internet of things. IEEE Internet of Things Journal. 8(14), 11561–11580.
[13] Antonakakis, M., April, T., Bailey, M., et al., 2017. Understanding the Mirai Botnet. In Proceedings of the USENIX Security Symposium, Vancouver, BC, Canada, 16–18 August 2017.
[14] Alfahaid, A., Alalwany, E., Almars, A.M., et al., 2025. Machine learning-based security solutions for IoT networks: A comprehensive survey. Sensors. 25(11), 3341.
[15] Raja, S., Manikandasaran, S.S., Doss, R., 2022. Threat modeling and IoT attack surfaces. In: Aurelia, S., Paiva, S. (Eds.). Immersive Technology in Smart Cities: Augmented and Virtual Reality in IoT. Springer: Cham, Switzerland. pp. 229–258.
[16] Coston, I., Plotnizky, E., Nojoumian, M., 2025. Comprehensive study of IoT vulnerabilities and countermeasures. Applied Sciences. 15(6), 3036.
[17] Lu, Y., Xu, L.D., 2019. Internet of things (IoT) cybersecurity research: A review of current research topics. IEEE Internet of Things Journal. 6(2), 2103–2115.
[18] Ali, R.F., Muneer, A., Dominic, P.D.D., et al., 2021. Internet of things (IoT) security challenges and solutions: A systematic literature review. In: Abdullah, N., Manickam, S., Anbar, M. (Eds.). Advances in Cyber Security. Springer: Singapore. pp. 128–154.
[19] Virtanen, P., Gommers, R., Oliphant, T.E., et al., 2020. SciPy 1.0: Fundamental algorithms for scientific computing in python. Nature Methods. 17(3), 261–272.
[20] Pedregosa, F., Varoquaux, G., Gramfort, A., et al., 2011. Scikit-learn: Machine learning in Python. Journal of Machine Learning Research. 12, 2825–2830.
[21] Owusu-Adjei, M., Hayfron-Acquah, J.B., Frimpong, T., et al., 2023. Imbalanced class distribution and performance evaluation metrics: A systematic review of prediction accuracy for determining model performance in healthcare systems. PLOS Digital Health. 2(11), e0000290.
[22] Waqdan, M., Louafi, H., Mouhoub, M., 2025. Security risk assessment in IoT environments: A taxonomy and survey. Computers & Security. 154, 104456.
[23] AlSalem, T.S., Almaiah, M.A., Lutfi, A., 2023. Cybersecurity risk analysis in the IoT: A systematic review. Electronics. 12(18). DOI: https://doi.org/10.3390/electronics12183958
[24] Kouassi, B.M., Ballo, A.B., Ayikpa, K.J., et al., 2025. Top-K feature selection for IoT intrusion detection: Contributions of XGBoost, Lightgbm, and Random Forest. Future Internet. 17(11). DOI: https://doi.org/10.3390/fi17110529
[25] Chalichalamala, S., Govindan, N., Kasarapu, R., 2023. Logistic regression ensemble classifier for intrusion detection system in internet of things. Sensors. 23(23), 9583.
Downloads
How to Cite
Issue
Article Type
License
Copyright © 2026 Richelle Williams, Fernando Koch

This is an open access article under the Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0) License.




Richelle Williams