Researchers have discovered a method that allows them to scan the entire Internet in less than an hour. How? With an open-source network scanner called ZMap. Researchers from the University of Michigan created it while looking for a method to discover vulnerabilities in networks and develop appropriate defense mechanisms.
The video we present shows ZMap scanning every IP address on the Internet, a process that usually can take months, in about 45 minutes and from a single machine.
To understand how ZMap works, it is useful to understand the Nmap method. This method is used today for network scanning. Nmap sends individual packets to each IP address and waits for a response while gathering a list of those that have responded. As you can imagine, this takes a very long time.
Additionally, as the Washington Post notes, “maintaining a file for each pending request creates gaps, which slow down the scanning process.”
The ZMap sends requests to IP addresses, but encodes the outgoing request for determining the information, so when the signal returns to ZMap, it can decode the responses. It does not keep a list of pending requests. The Washington Post reports that “the lower overhead of this approach allows ZMap to send packets 1.000 times faster than Nmap did.”
Watch the video

