48,183 and 42,025: Building and Industrial Protocols on the Public Internet
Protocols with no authentication layer to enable
Enterprise security discussions concentrate on systems that can be patched, authenticated, and monitored. Building automation and industrial control protocols occupy a different category, because the security model was never part of the protocol design. Measuring their reachable population is therefore a measurement of a different kind of problem.
The measurements
Queried on 25 September 2026 through the ZoomEye SDK using port-based queries: port="47808", the standard port for BACnet, returned 48,183 matching assets, and port="44818", the standard port for EtherNet/IP used in industrial automation, returned 42,025.
Both are port matches, which identify listeners on those ports rather than confirmed devices of those protocol families. The important property is that both protocols were designed for isolated networks and are served by equipment with long service lives, so the population reachable from the internet is unlikely to change quickly after a disclosure.
Why these counts are different in character
An exposed web application can be patched, moved behind an authenticating proxy, or retired. An exposed building management controller or programmable logic controller is typically in service for a decade or more, is maintained by a facilities or operations team rather than by the IT security organisation, and may not support a method of authentication at all.
That means the remediation path is structural rather than per-device. Either the network is segmented so that the device is not reachable from untrusted networks, or the device remains reachable and the protocol remains what it always was.
What defence looks like here
- Establish whether operational technology networks have any path to the internet, and treat any discovered path as a project rather than a ticket.
- Enumerate the devices on those networks, because the inventory frequently sits with a facilities contractor rather than in the IT asset system.
- Plan for compensating controls that do not depend on the device: network segmentation, a unidirectional gateway for telemetry, and monitoring for protocol traffic that appears outside its expected segment.
Limitations
Port matches do not confirm the device type or the protocol version, and honeypots deliberately listen on industrial ports. The counts are single-date observations and will differ on another day. They also do not reveal whether the reachable devices are production systems or test benches.
References
- ZoomEye search, executed 25 September 2026:
port="47808"returned 48,183 matching assets;port="44818"returned 42,025 (SDK, sub_type=all, total count) - MITRE ATT&CK T1133 External Remote Services: https://attack.mitre.org/techniques/T1133
- CISA Known Exploited Vulnerabilities catalog, referenced for context on exposed-service exploitation: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Top comments (0)