DEV Community

StarkMan
StarkMan

Posted on

48,183 and 42,025: Building and Industrial Protocols on the Public Internet

48,183 and 42,025: Building and Industrial Protocols on the Public Internet

Protocols with no authentication layer to enable

Enterprise security discussions concentrate on systems that can be patched, authenticated, and monitored. Building automation and industrial control protocols occupy a different category, because the security model was never part of the protocol design. Measuring their reachable population is therefore a measurement of a different kind of problem.

The measurements

Queried on 25 September 2026 through the ZoomEye SDK using port-based queries: port="47808", the standard port for BACnet, returned 48,183 matching assets, and port="44818", the standard port for EtherNet/IP used in industrial automation, returned 42,025.
Both are port matches, which identify listeners on those ports rather than confirmed devices of those protocol families. The important property is that both protocols were designed for isolated networks and are served by equipment with long service lives, so the population reachable from the internet is unlikely to change quickly after a disclosure.

Why these counts are different in character

An exposed web application can be patched, moved behind an authenticating proxy, or retired. An exposed building management controller or programmable logic controller is typically in service for a decade or more, is maintained by a facilities or operations team rather than by the IT security organisation, and may not support a method of authentication at all.
That means the remediation path is structural rather than per-device. Either the network is segmented so that the device is not reachable from untrusted networks, or the device remains reachable and the protocol remains what it always was.

What defence looks like here

  • Establish whether operational technology networks have any path to the internet, and treat any discovered path as a project rather than a ticket.
  • Enumerate the devices on those networks, because the inventory frequently sits with a facilities contractor rather than in the IT asset system.
  • Plan for compensating controls that do not depend on the device: network segmentation, a unidirectional gateway for telemetry, and monitoring for protocol traffic that appears outside its expected segment.

Limitations

Port matches do not confirm the device type or the protocol version, and honeypots deliberately listen on industrial ports. The counts are single-date observations and will differ on another day. They also do not reveal whether the reachable devices are production systems or test benches.

References

Top comments (0)