A Date Filter Is Not an Install Date: Reading Time-Bounded Exposure Queries
The NCSC summary of the May 2020 US sanction describes a change that took effect in 2020. Relating an exposure measurement to that date requires care about what a time filter means.
Bounding the observation
On 4 October 2026, app="Huawei" returned 18,927,766 matches and app="Huawei" && after="2020-05-15" returned 17,653,722.
| Query | Scope | Matches observed |
| --- | --- | ---: |
| app="Huawei" | All records | 18,927,766 |
| app="Huawei" && after="2020-05-15" | Records after a date | 17,653,722 |
What after refers to
A date filter in a scanning platform applies to the last time the record was updated in that platform, not to when a device was installed, purchased or deployed. A router installed in 2015 and re-observed in 2024 will sit after a 2020 cut-off.
That is why the large majority of matches fall after the date. The number describes observation recency, not procurement history.
The honest use of a time filter
The filter is useful for narrowing to records that were seen or refreshed recently, which helps when you want a current picture rather than a historical one. It cannot be used to claim that a device appeared because of a specific 2020 policy change.
Practical next steps
- State that a date filter refers to record recency.
- Use date filters to select fresh observations, not to date installations.
- Never attribute a device's presence to a policy event based on a date filter.
- Keep the unfiltered and filtered counts side by side.
Limitations
Record timestamps depend on the platform's own observation schedule, which may be uneven by region and network.
References
- NCSC, Summary of the NCSC analysis of May 2020 US sanction: https://www.ncsc.gov.uk/report/summary-of-ncsc-analysis-of-us-may-2020-sanction
- ZoomEye: https://www.zoomeye.ai/
Top comments (0)