How does Spur classify infrastructure that serves more than one purpose, such as a legitimate corporate network also exposed through a public VPN service?
Spur classifies based on the most security-relevant observable behavior, not the primary or most benign use case. If otherwise-legitimate infrastructure is being publicly exposed through anonymizing or proxy services, it's labeled according to that exposure, since that's the behavior most relevant to a security decision.
Similar questions
What Proxy or VPN services are known bad?
Some services tend to be more abuse than others. It is important to remember that because abuse is ultimately driven by the users of a service, this can ebb and flow depending on different threat actors, techniques, and targets. We recommend looking for services that explicitly enable anonymous purchases without logging and services that are frequently sourced by malware.
Can a single IP address be associated with more than one proxy or anonymization service?
Yes. Shared infrastructure, reseller arrangements, and overlapping proxy ecosystems can result in an IP being associated with multiple services. Determining the exact service responsible for a specific event often requires additional context and investigation.
How quickly can Spur identify and classify newly discovered VPN or proxy infrastructure?
Spur continuously researches emerging infrastructure and updates classifications as new intelligence becomes available. New infrastructure is often identified and incorporated rapidly, allowing customers to benefit from current intelligence through the API and data products.
Does Spur identify legitimate privacy-focused users as well as malicious actors?
Spur identifies infrastructure characteristics and anonymization technologies, not intent. Organizations determine how to use those signals based on their business requirements, risk tolerance, and policies.
How does Spur detect VPNs, residential proxies, and ISP proxies?
Spur uses a combination of network intelligence, infrastructure analysis, behavioral signals, routing characteristics, historical observations, and proprietary research to identify and classify IP addresses. Multiple signals are evaluated together to determine the likelihood that an IP belongs to a VPN, residential proxy network, ISP proxy service, hosting provider, or other category.