I pinged every IP address that wasn’t reserved. The image is 8k by 8k and is re-encoded as an AVIF to be friendlier to mobile devices. Like every other survey done, it is using a Hilbert Curve to convert the linear address space to a contiguous 2d space. The hotter the colors (blue is coolest), the denser the ping responses were.
(If you are interested the full-resolution pyramidal-tiled TIFF can be downloaded and viewed in QuPath on desktop. I’ve also compressed the ping response data into its own format down to about 150 MB. PM me for a link)

Here is a 2006 survey to compare.

Some observations: Big Tech (USA) is in the top left. US government allocations, for the most part, did not respond to any pings. And maybe you didn’t realize this before, but Multicast (Class D) & Class E consume a whopping 12% of the IPv4 range.
Nice! Now do the same for ipv6 :p
Any way to determine/estimate if the black squares are unused blocks (“give them back!”) or just not responding to pings?
No. Any proper firewall is going to act as if there nothing there.
This was a ping scan, so it wasn’t probing any TCP/UDP ports (see shodan.io). I suppose you could use ICMP control messages (Destination Unreachable) to determine if something was unused, but that assumes the other side is being friendly.
Hey, I can see my house from here!
I’m in this pic too!
How long did it take to ping the whole world?
Or more specifically, what is the sum of all latencies divided by the number of responses times the total numer of requests sent (to scale up for the ones that didn’t reply, assuming their average latency would have been similar to the total average)?
It’s interesting how certain companies and organizations have such large ranges, 16m IP’s each for both that old printer company and a farmaceutical company is a lot. It really shows the history of the internet and how seemingly certain companies that adopted it first ended up with huge chunks of the available IPv4 space.
Exactly the same thing had been done in this very interesting video I had watched some time ago. Did you get the idea from there?
The Hilbert curve visualization is surprisingly satisfying.
Forgive me if this is an ignorant question. How did you do the incremental address to address search? In my head I would start with “000.000.000.000” and then “000.000.000.001” and so on but that doesn’t account for the “000.000.000.1” scenario, or any combination thereof.
The “.” are just separators. Each segment is a number from 0-255 (1 byte). So you hold three segments static (e.g. 10.10.10.x) and then increment the last segment from 0-255 (so 10.10.10.0 -> 10.10.10.255). Then the next segment increments (10.10.11.0 -> 10.10.11.255).
Thanks to everyone here and this as well.
Python code:
results = {} for ip0 in range(256): ip0_str = to_str( ip0 ) + '.' for ip1 in range(256): ip1_str = ip0_str + to_str( ip1 ) + '.' for ip2 in range(256): ip2_str = ip1_str + to_str( ip2 ) + '.' for ip3 in range(256): ip_vector = [ ip0, ip1, ip2, ip3 ] ip_str = ip2_str + to_str( ip3 ) results[ ip_vector ] = ping( ip_str )Might look a bit nicer using format strings instead. That map will contain on the order of 4 billion entries (one for each value of 2³²), and the actual size will depend on what format the ping function returns, 4 bytes for each key (optimized from my initial version that used the IPs as keys), plus all the internal structures for the map like key hashes and the hash table itself. Ie, this takes more memory to run than viewing OP’s full sized image and I wouldn’t suggest running it with less than 32GB of RAM. Though it would take less memory if it generated the image directly or at least making the keys implicit (which the image does, as they are encoded into the x, y coordinates rather than stored).
Edit: Let’s look at runtime, too, because why not. Assuming every single IP responds in 0.01 seconds (they’ll take longer, especially the ones that time out instead of respond), rounding the total to that nice 4 billion number get us 40 million seconds. An hour is less than 4000 seconds, so it would take over 100 hours to run this script.
Though it could be parallelized, since you can ping many targets at once. Not sure what the maximum number of pings you could have in flight is, but whatever it is, you’d be much better off using a script that did like 80% of that (to leave some margin for the rest of the system to use, also ISPs might not be happy with you maxing out your ICMP traffic).
Thank you!





