BREAKING  Zakir Durumeric maps the entire internet in minutes ZMAP  Scans ~4 billion devices in about five minutes CENSYS  University project became a leading internet intelligence platform HONORS  MIT Technology Review 35 Innovators Under 35 STANFORD  Assistant Professor of Computer Science HEARTBLEED  Used internet-wide scanning to map the 2014 flaw
Profile / Internet Security

Zakir Durumeric

He built a scanner that sees the whole internet at once, then turned it into one of security's most-used intelligence platforms.

Zakir Durumeric, co-founder and CEO of Censys
Zakir Durumeric - Co-Founder & CEO, Censys; Assistant Professor, Stanford
~5 min
To scan the IPv4 internet
2017
Censys founded
35 U 35
MIT Tech Review, 2015
$198M+
Total funding raised

In 2013, a graduate student at the University of Michigan asked a question that sounded almost naive: how fast could you look at every device on the internet? The honest answer at the time was weeks. Zakir Durumeric decided that was too slow.

The tool his research group built was called ZMap. Where earlier scanners plodded through the internet's roughly four billion IPv4 addresses one careful step at a time, ZMap treated the whole address space as a single sweep. Presented at the 2013 USENIX Security Symposium, it could ping the entire public internet in about five minutes. For researchers who study networks, that was not an incremental improvement. It changed what was possible to know.

Durumeric, then in his mid-twenties, was the son of a Turkish mathematician and had grown up around the habit of taking a messy problem and reducing it to something measurable. That instinct sits at the center of everything he has built since. He describes himself as an empiricist - someone who builds systems to measure complex networked ecosystems, then uses those measurements to find weaknesses, design better defenses, and inform policy.

ZMap fundamentally changed researchers' visibility into the hosts on the internet. - Zakir Durumeric

The Heartbleed moment

The abstract promise of fast scanning became concrete in April 2014, when the Heartbleed vulnerability tore through OpenSSL, the encryption library that quietly protects a huge share of the web. Suddenly the urgent question was not whether the flaw was serious - it was how far it reached. Which servers were exposed? Who needed to patch, and now?

Durumeric and his collaborators turned their scanners on the problem, measuring the internet's exposure in near real time and notifying administrators about the sites still at risk. It was a live demonstration of a simple idea he keeps returning to: you cannot defend what you cannot see. Measurement is not an academic luxury. In a crisis, it is the difference between guessing and knowing.

From a research project to a company

ZMap answered a one-time question well. But the internet does not hold still. Hosts appear and vanish, services move, new devices come online every second. A scanner built for a snapshot was never meant to track a moving picture. That gap became Censys - a platform that continuously scans and catalogs the internet's infrastructure so defenders can search it the way you would search the web.

Founded in 2017 as it grew out of University of Michigan research, Censys turned an academic toolkit into a commercial product used for threat hunting, exposure management, and attack surface visibility. Under Durumeric's leadership as co-founder and CEO, it has raised more than $198 million in total funding and become one of the leading internet intelligence platforms in the security industry. His team also maintains the broader open toolkit the field relies on - ZMap, ZGrab, ZDNS, ZLint, and LZR among them.

Our critical infrastructure is increasingly under attack, and we lack solutions for ensuring the integrity of these devices.

Zakir Durumeric

Two jobs, one telescope

Most people would treat running a growing company as a full-time commitment. Durumeric also holds a second one. In 2018 he joined Stanford University as an Assistant Professor of Computer Science, where he directs the Empirical Security Research Group and advises a roster of PhD students. He teaches the university's flagship security course, CS155 Computer and Network Security, along with graduate seminars and a class on the modern internet.

The two roles are less divided than they look. The lab and the company point the same instrument at the same subject - the live internet - and ask what is broken before an attacker finds out first. The academic work feeds new measurement techniques into the field; the company puts them in front of the people who defend networks for a living.

That dual output has been recognized on both sides. MIT Technology Review named him one of its 35 Innovators Under 35 in 2015 for making internet scanning fast. His research has collected best-paper awards at ACM CCS and ACM IMC, honorable mentions at USENIX Security, multiple IRTF Applied Networking Research Prizes, a Sloan Research Fellowship, a Test of Time Award, and an NSF CAREER Award. In 2026 he also joined the board of directors of the security startup zeroRISC.

Why it matters

Internet measurement is not glamorous work. It produces no viral app, no consumer gadget, no obvious headline. What it produces is visibility - the unglamorous foundation that every other security decision rests on. Durumeric's career is a bet that if you can see the internet clearly and quickly, you can make it meaningfully safer. A decade after ZMap, with Censys watching global infrastructure around the clock, that bet keeps paying off.

Speed record. ZMap can survey all ~4 billion IPv4 addresses in roughly five minutes - a task that once took weeks.
Roots. Censys began life as an academic research project at the University of Michigan.
Teacher. He leads Stanford's flagship CS155 Computer and Network Security course.
Toolkit. He maintains ZMap, ZGrab, ZDNS, ZLint, and LZR - staples of internet measurement.
2013Co-creates ZMap as a Michigan PhD student; presented at USENIX Security
2014Uses internet-wide scanning to measure the reach of the Heartbleed flaw
2015Named to MIT Technology Review's 35 Innovators Under 35
2017Completes PhD; Censys founded to commercialize internet-wide scanning
2018Joins Stanford as Assistant Professor; founds Empirical Security Research Group
2022Receives a Test of Time Award for foundational measurement work
2026Earns an NSF CAREER Award; joins the board of zeroRISC