Internet Services & Infrastructure Data: Routing Registries, BGP Archives and Domain Intelligence · Head-to-head

RouteViews BGP Archive & API vs Shodan – Search Engine for Internet-Connected Devices

Which internet services & infrastructure data: routing registries, bgp archives and domain intelligence data fits your job: RouteViews BGP Archive & API, or Shodan – Search Engine for Internet-Connected Devices. API, files, or your warehouse. Daily, weekly, or hourly.

Internet Services & Infrastructure Data: Routing Registries, BGP Archives and Domain Intelligence Global - collectors at AMS-IX · Archive reaches to the late 1990s for legacy collectors

RouteViews BGP Archive & API

Internet Services & Infrastructure Data: Routing Registries, BGP Archives and Domain Intelligence Global - every routable IPv4 address plus IPv6 · Present-tense index refreshed by a roughly weekly full-internet sweep

Shodan – Search Engine for Internet-Connected Devices

Coverage, side by side

RouteViews BGP Archive & API Shodan – Search Engine for Internet-Connected Devices
Geographic Global - collectors at AMS-IX, LINX, NAPAfrica, Equinix SG1/SYD1, IX.br Sao Paulo and multi-hop sites in Oregon, across six continents Global - every routable IPv4 address plus IPv6, geolocated to city and postal code
Temporal Archive reaches to the late 1990s for legacy collectors; newer BMP collectors such as amsix.ams from February 2024; near-real-time state alongside Present-tense index refreshed by a roughly weekly full-internet sweep; historical banners retained per host

What each contains

Pick by fit, not by loyalty.

RouteViews BGP Archive & API Shodan – Search Engine for Internet-Connected Devices
Publisher RouteViews (University of Oregon), the long-running route-collection project Shodan, the commercial search engine for internet-connected devices
Subject lens Control plane: BGP RIB snapshots and update streams recorded from route collectors peered at major exchange points Devices: service banners probed across every routable IPv4 address plus IPv6, with software and location metadata
Geographic coverage Global - collectors at AMS-IX, LINX, NAPAfrica, Equinix SG1/SYD1, IX.br Sao Paulo and multi-hop sites in Oregon, across six continents Global - every routable IPv4 address plus IPv6, geolocated to city and postal code
Temporal coverage Archive reaches to the late 1990s for legacy collectors; newer BMP collectors such as amsix.ams from February 2024; near-real-time state alongside Present-tense index refreshed by a roughly weekly full-internet sweep; historical banners retained per host
Detail level Per BGP prefix, per AS-path observation, per peer session and per collector Per IP address and per service banner (host x port x protocol x timestamp)
Formats JSON alongside bz2-compressed MRT capture files JSON
Scale Full IPv4 table above 900k prefixes per peer on well-connected collectors; terabytes of captures across ~20 collectors Billions of indexed banners across hundreds of millions of hosts
Best for Outage detection, hijack and leak forensics, RPKI and AS-path research, topology studies Attack-surface mapping, IoT and device discovery, vulnerability and threat intelligence, market scans of exposed software

What each does better

RouteViews BGP Archive & API

Depth of history. The archive holds terabytes of MRT captures across roughly twenty collectors, reaching back to the late 1990s for legacy vantage points, with newer BMP-based collectors such as amsix.ams joining in February 2024. No scanner corpus offers anything comparable for reconstructing how reachability looked before, during and after a routing event.

Routing-native schema. All thirteen documented fields answer routing questions: origin ASNs, AS paths, communities, RPKI validation states with ROA detail, and per-peer observation arrays that name the collector — the worked example shows prefix 193.0.0.0/21 originated by AS3333, reported valid via peer AS37497 at the Amsterdam exchange point. A single query returns an AS's complete originated set, as in the sample listing five prefixes for AS3333 starting at 193.0.0.0/21.

Scale measured in prefixes, not hosts. A full IPv4 table exceeds 900k prefixes per peer on well-connected collectors, and because dozens of peer sessions report independently, the same announcement can be triangulated across vantage points — the raw material for outage detection, leak forensics and hijack attribution that banner data cannot supply.

Shodan – Search Engine for Internet-Connected Devices

It indexes the machines themselves. Every routable IPv4 address plus IPv6 falls inside the sweep, holding billions of banners across hundreds of millions of hosts, geolocated down to city and postal code. RouteViews never touches devices — it sees prefixes and paths, not the servers, cameras or controllers behind them. The sample lookup for 8.8.8.8 resolves to Google LLC, AS15169, ports 53 and 443, product gws.

Asset metadata is far richer. Each banner record carries identified software and version, operating-system fingerprint, CPE identifiers, parsed HTTP title and Server header, web technology components, reverse-DNS hostnames and derived domains, ISP strings, transport protocol and the raw banner text itself. That combination turns a raw scan into an inventory an analyst can filter, group and trend (see threat intelligence).

Workflow surface beyond the index. Continuous monitoring of your own networks with real-time notification, on-demand probing of specific addresses, domain-to-host resolution, faceted search across the whole corpus and streaming banner feeds exist only on this side. RouteViews answers what was announced; it cannot answer what software version is running on a given box today.

Where they're equivalent

More than their different shapes suggest. Both field dictionaries were verified during research — a bar all ten pooled records in this slice clear. Both score above the catalog-wide average of 7.81 on Datadory's rubric, RouteViews at 9/10 and Shodan at 8/10. Both cover their subject globally with no geographic carve-outs: collectors on six continents at major exchange points on one side, every routable IPv4 address plus IPv6 on the other. Both publish documented, machine-readable structures rather than prose reports, in JSON as the common format — RouteViews pairing it with MRT capture files, Shodan staying JSON-only. And both attribute every row to an accountable operator, whether the autonomous system originating a route or the organisation and ISP behind a scanned host.

They share blind spots too. Neither catalogs companies or consumer sentiment, and neither answers the other's core question: RouteViews cannot say what software runs on 8.8.8.8, while Shodan cannot say whether the prefix containing it passed RPKI origin validation. Attribution expectations apply on both sides — the University of Oregon project asks researchers to cite it, and Shodan requires its data attributed in commercial use.

The verdict

Verdict: sample both, pick by fit — they are different instruments pointed at different layers of the same industry.

Did reachability to this prefix collapse mid-morning, who originates this address space and through which paths, how many routes fail RPKI validation after a policy change, what did the table look like during a past hijack — anything answered by an announcement, a path or a validation state. Accept that it never sees individual machines.

Take Shodan – Search Engine for Internet-Connected Devices if your question lives on the devices. Which industrial controllers are reachable from the internet in this region, what versions of a given server software are exposed, how does an organisation's exposure shift month to month, where are the cameras on this carrier's network — anything answered by a banner, a port list or a software fingerprint (see attack-surface management). Accept that it cannot explain why traffic stopped flowing between networks.

Network engineers and NOC teams usually start on the routing side; security researchers and exposure-management groups start on the banner side; developers and builders tend to prototype against whichever layer their product sits on.

Sample both, pick by fit. See RouteViews BGP Archive & API · See Shodan – Search Engine for Internet-Connected Devices

Or take both in one feed

Yes — they meet at the autonomous system, and the join is one field wide. Start on the device side: an exposed host carries its owning network in Shodan's asn and org fields. Cross to the routing side with that ASN and you receive the full originated prefix set, the longest-match entry for any single prefix, RPKI validation state and ROAs, and the per-collector peers that observe the announcement. An asset inventory gains a legitimacy check; a routing investigation gains a picture of what was actually running on the affected space.

In a hijack or outage review the split of labour is clean: the routing record shows how reachability changed and which paths carried the space before and after; the banner index shows what changed on the machines themselves — new services, shifted ports, updated software. Mind the join keys: one side keys prefixes and origin ASNs, the other keys IP addresses whose network assignment moves over time, so timestamp both sides of any merged artifact. Neither dataset needs the other to be useful, but the pair covers control plane and devices together in a way neither half manages alone. Browse the rest of the shelf at the internet services & infrastructure data hub.

Datadory ships either record alone or both merged onto one calendar, delivered daily, weekly, or hourly — your call. Or take both in one feed.

API, files, or your warehouse. Daily, weekly, or hourly.

Fair questions

Do the two datasets cover the same ground?

Only along one edge. Both are global, both attribute rows to accountable operators, and both share JSON as a format and the autonomous system as a concept. But their units never meet: a RouteViews row is a prefix announced and observed by a named collector peer, while a Shodan row is a banner returned by one host on one port. The ASN is the only bridge, and it needs timestamping on both sides.

Which dataset reaches further back?

Its MRT archive stretches to the late 1990s for legacy collectors, with terabytes of captures across roughly twenty vantage points — enough to replay historical hijacks and outages announcement by announcement. Shodan's index describes the current weekly sweep, keeping historical banners per host rather than a comparable public longitudinal series.

Which should a security team sample first?

Start with Shodan – Search Engine for Internet-Connected Devices: its banner index maps what an organisation exposes — products, versions, ports, locations — which is precisely the attack-surface question. Asset discovery without the routing check misses prefix-level problems entirely.

Can Datadory deliver both datasets together?

Yes — alone or merged onto one calendar, delivered daily, weekly, or hourly, your call. Each arrives normalized to its verified field dictionary (thirteen documented fields on the RouteViews side, seventeen on Shodan's) with sample rows for inspection before anything ships. The joining work is the ASN crosswalk described above, and we can pre-join it for you.