Skip to content

Network exposure

An operator's internet footprint can be characterized without scanning it: resolve its public domain and find out, from the routing records (BGP), which autonomous system that presence lives in. This layer does that over a sample of 21 operators and answers a question of structural hygiene, not point vulnerability: does the operator run its own address space, or does its public presence sit on a foreign cloud, a telco, or a registrar?

Classification of 21 operators by the holder of the autonomous system hosting their public presence. Source: public DNS resolution and RIPEstat (BGP). The IP is used to resolve the autonomous system and then discarded: it is not published.

Where the sector lives

Only 3 of the 21 operators surveyed host their public presence in their own Argentine address space. The rest split between foreign cloud, mostly Amazon and Microsoft, CDN or hosting, and local telcos. That split is itself an attack-surface fact, with two opposing readings. Leaning on a large cloud outsources part of the perimeter to whoever has the scale to hold it, and that plays in favor. But it leaves the sector's presence concentrated in a few foreign providers, so a problem in one of them, or in its supply chain, touches several operators at once. It is the systemic vulnerability of the other layers, now on the digital side.

Exposed industrial ports: the missing sub-layer

The sharpest question is how many industrial control devices (Modbus, DNP3, S7) in the country are exposed to the internet, and it carries a trap. Counting hosts with port 502 open gives an inflated, false number: in Argentina, the vast majority of what answers on that port is not industrial control but mislabeled MikroTik routers, VPN concentrators, and web servers. A by-hand sweep confirms it: of 29 hosts with port 502 open, not one spoke Modbus.

The count that matters filters by the detected protocol, not the port, and that data, on both Shodan and Censys, sits behind a paid plan. So the sub-layer stays declared, not shown: it is the site's best example of why interpretation beats raw data. The rest of the layer is built from free sources, which ask the right question.

Here the rule is literal

This is the layer where one slip turns the map into a target list. The published artifact keeps, per operator, only the autonomous system, its holder, the hosting classification, and, if it runs its own space, the count of prefixes and addresses. There is no IP, no host, no port, and the pipeline check fails the build if one appears.

Limits of this layer

  • The classification reflects the hosting of the public web front end, which may sit behind a CDN different from the rest of the operator's infrastructure, and may resolve differently on another day.
  • The sample is 21 operators chosen for relevance, not the sector's universe.
  • "Own infrastructure" does not mean "more secure" or "less": it means the operator controls its own address space. The risk reading depends on how it manages it, which this layer does not observe.

All of the above looks at the infrastructure from the network. Satellite activity looks at it from orbit: what is switched on.