VLDB 2026 Research / reviewers in the wild / expert
Robert Beverly
dblp:12/1817
· DBLP profile ↗
32ranked-venue papers
10as first author
7since 2021 · last 2026
0000-0002-5005-7350ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 4 first-author · 4 since 2021Security and privacy · 13 · 5 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly Attacks
Robert Beverly, Erik C. Rye |
NDSS | 1 |
| 2025 | Buy it Now, Track Me Later: Attacking User Privacy via Wi-Fi AP Online AuctionsabstractStatic and hard-coded layer-two network identifiers are well known to present security vulnerabilities and endanger user privacy. In this work, we introduce a new privacy attack against Wi-Fi access points listed on secondhand marketplaces. Specifically, we demonstrate the ability to remotely gather a large quantity of layer-two Wi-Fi identifiers by programmatically querying the eBay marketplace and applying state-of-the-art computer vision techniques to extract IEEE 802.11 BSSIDs from the seller's posted images of the hardware. By leveraging data from a global Wi-Fi Positioning System (WPS) that geolocates BSSIDs, we obtain the physical locations of these devices both pre- and post-sale. In addition to validating the degree to which a seller's location matches the location of the device, we examine cases of device movement–once the device is sold and then subsequently re-used in a new environment. Our work highlights a previously unrecognized privacy vulnerability and suggests, yet again, the strong need to protect layer-two network identifiers. Steven Su, Erik C. Rye, Dave Levin, Robert Beverly |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Illuminating Router Vendor Diversity Within Providers and Along Network PathsabstractThe Internet architecture has facilitated a multi-party, distributed, and heterogeneous physical infrastructure where routers from different vendors connect and inter-operate via IP. Such vendor heterogeneity can have important security and policy implications. For example, a security vulnerability may be specific to a particular vendor and implementation, and thus will have a disproportionate impact on particular networks and paths if exploited. From a policy perspective, governments are now explicitly banning particular vendors-or have threatened to do so. Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis |
IMC | 3 |
| 2023 | IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level GeolocationabstractWe present IPvSeeYou, a privacy attack that permits a remote and unprivileged adversary to physically geolocate many residential IPv6 hosts and networks with street-level precision. The crux of our method involves: 1) remotely discovering wide area (WAN) hardware MAC addresses from home routers; 2) correlating these MAC addresses with their WiFi BSSID counterparts of known location; and 3) extending coverage by associating devices connected to a common penultimate provider router.We first obtain a large corpus of MACs embedded in IPv6 addresses via high-speed network probing. These MAC addresses are effectively leaked up the protocol stack and largely represent WAN interfaces of residential routers, many of which are all-in-one devices that also provide WiFi. We develop a technique to statistically infer the mapping between a router’s WAN and WiFi MAC addresses across manufacturers and devices, and mount a large-scale data fusion attack that correlates WAN MACs with WiFi BSSIDs available in wardriving (geolocation) databases. Using these correlations, we geolocate the IPv6 prefixes of >12M routers in the wild across 146 countries and territories. Selected validation confirms a median geolocation error of 39 meters. We then exploit technology and deployment constraints to extend the attack to a larger set of IPv6 residential routers by clustering and associating devices with a common penultimate provider router. While we responsibly disclosed our results to several manufacturers and providers, the ossified ecosystem of deployed residential cable and DSL routers suggests that our attack will remain a privacy threat into the foreseeable future. Erik C. Rye, Robert Beverly |
SP | 2 |
| 2021 | Third time's not a charm: exploiting SNMPv3 for router fingerprintingabstractIn this paper, we show that adoption of the SNMPv3 network management protocol standard offers a unique---but likely unintended---opportunity for remotely fingerprinting network infrastructure in the wild. Specifically, by sending unsolicited and unauthenticated SNMPv3 requests, we obtain detailed information about the configuration and status of network devices including vendor, uptime, and the number of restarts. More importantly, the reply contains a persistent and strong identifier that allows for lightweight Internet-scale alias resolution and dual-stack association. By launching active Internet-wide SNMPv3 scan campaigns, we show that our technique can fingerprint more than 4.6 million devices of which around 350k are network routers. Not only is our technique lightweight and accurate, it is complementary to existing alias resolution, dual-stack inference, and device fingerprinting approaches. Our analysis not only provides fresh insights into the router deployment strategies of network operators worldwide, but also highlights potential vulnerabilities of SNMPv3 as currently deployed. Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis |
Internet Measurement Conference | 3 |
| 2021 | AS-level BGP community usage classificationabstractBGP communities are a popular mechanism used by network operators for traffic engineering, blackholing, and to realize network policies and business strategies. In recent years, many research works have contributed to our understanding of how BGP communities are utilized, as well as how they can reveal secondary insights into real-world events such as outages and security attacks. However, one fundamental question remains unanswered: "Which ASes tag announcements with BGP communities and which remove communities in the announcements they receive?" A grounded understanding of where BGP communities are added or removed can help better model and predict BGP-based actions in the Internet and characterize the strategies of network operators. Thomas Krenc, Robert Beverly, Georgios Smaragdakis |
Internet Measurement Conference | 2 |
| 2021 | Follow the scent: defeating IPv6 prefix rotation privacyabstractIPv6's large address space allows ample freedom for choosing and assigning addresses. To improve client privacy and resist IP-based tracking, standardized techniques leverage this large address space, including privacy extensions and provider prefix rotation. Ephemeral and dynamic IPv6 addresses confound not only tracking and traffic correlation attempts, but also traditional network measurements, logging, and defense mechanisms. We show that the intended anti-tracking capability of these widely deployed mechanisms is unwittingly subverted by edge routers using legacy IPv6 addressing schemes that embed unique identifiers. Erik C. Rye, Robert Beverly, K. C. Claffy |
Internet Measurement Conference | 2 |
| 2020 | Keep your communities clean: exploring the routing message impact of BGP communitiesabstractBGP communities are widely used to tag prefix aggregates for policy, traffic engineering, and inter-AS signaling. Because individual ASes define their own community semantics, many ASes blindly propagate communities they do not recognize. Prior research has shown the potential security vulnerabilities when communities are not filtered. This work sheds light on a second unintended side-effect of communities and permissive propagation: an increase in unnecessary BGP routing messages. Due to its transitive property, a change in the community attribute induces update messages throughout established routes, just updating communities. We ground our work by characterizing the handling of updates with communities, including when filtered, on multiple real-world BGP implementations in controlled laboratory experiments. We then examine 10 years of BGP messages observed in the wild at two route collector systems. In 2020, approximately 25% of all announcements modify the community attribute, but retain the AS path of the most recent announcement; an additional 25% update neither community nor AS path. Using predictable beacon prefixes, we demonstrate that communities lead to an increase in update messages both at the tagging AS and at neighboring ASes that neither add nor filter communities. This effect is prominent for geolocation communities during path exploration: on a single day, 63% of all unique community attributes are revealed exclusively due to global withdrawals. Thomas Krenc, Robert Beverly, Georgios Smaragdakis |
CoNEXT | 2 |
| 2020 | Reading In-Between the Lines: An Analysis of DissenterabstractEfforts by content creators and social networks to enforce legal and policy-based norms, e.g. blocking hate speech and users, has driven the rise of unrestricted communication platforms. One such recent effort is Dissenter, a browser and web application that provides a conversational overlay for any web page. These conversations hide in plain sight -- users of Dissenter can see and participate in this conversation, whereas visitors using other browsers are oblivious to their existence. Further, the website and content owners have no power over the conversation as it resides in an overlay outside their control. Erik C. Rye, Jeremy Blackburn, Robert Beverly |
Internet Measurement Conference | 3 |
| 2020 | Diamond-Miner: Comprehensive Discovery of the Internet's Topology Diamonds
Kevin Vermeulen, Justin P. Rohrer, Robert Beverly, Olivier Fourmaux, Timur Friedman |
NSDI | 3 |
| 2020 | Discovering the IPv6 Network Periphery
Erik C. Rye, Robert Beverly |
PAM | 2 |
| 2019 | Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetabstractThe Spoofer project has collected data on the deployment and characteristics of IP source address validation on the Internet since 2005. Data from the project comes from participants who install an active probing client that runs in the background. The client automatically runs tests both periodically and when it detects a new network attachment point. We analyze the rich dataset of Spoofer tests in multiple dimensions: across time, networks, autonomous systems, countries, and by Internet protocol version. In our data for the year ending August 2019, at least a quarter of tested ASes did not filter packets with spoofed source addresses leaving their networks. We show that routers performing Network Address Translation do not always filter spoofed packets, as 6.4% of IPv4/24 tested in the year ending August 2019 did not filter. Worse, at least two thirds of tested ASes did not filter packets entering their networks with source addresses claiming to be from within their network that arrived from outside their network. We explore several approaches to encouraging remediation and the challenges of evaluating their impact. While we have been able to remediate 352 IPv4/24, we have found an order of magnitude more IPv4/24 that remains unremediated, despite myriad remediation strategies, with 21% unremediated for more than six months. Our analysis provides the most complete and confident picture of the Internet's susceptibility to date of this long-standing vulnerability. Although there is no simple solution to address the remaining long-tail of unremediated networks, we conclude with a discussion of possible non-technical interventions, and demonstrate how the platform can support evaluation of the impact of such interventions over time. Matthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys, Joshua A. Kroll, K. C. Claffy |
CCS | 2 |
| 2019 | Sundials in the Shade - An Internet-Wide Perspective on ICMP Timestamps
Erik C. Rye, Robert Beverly |
PAM | 2 |
| 2018 | In the IP of the Beholder: Strategies for Active IPv6 Topology Discovery
Robert Beverly, Ramakrishnan Durairajan, David Plonka, Justin P. Rohrer |
Internet Measurement Conference | 1 |
| 2018 | BGP Communities: Even more Worms in the Routing Can
Florian Streibelt, Franziska Lichtblau, Robert Beverly, Anja Feldmann, Cristel Pelsser, Georgios Smaragdakis, Randy Bush |
Internet Measurement Conference | 3 |
| 2017 | The Impact of Router Outages on the AS-level InternetabstractWe propose and evaluate a new metric for understanding the dependence of the AS-level Internet on individual routers. Whereas prior work uses large volumes of reachability probes to infer outages, we design an efficient active probing technique that directly and unambiguously reveals router restarts. We use our technique to survey 149,560 routers across the Internet for 2.5 years. 59,175 of the surveyed routers (40%) experience at least one reboot, and we quantify the resulting impact of each router outage on global IPv4 and IPv6 BGP reachability. Matthew J. Luckie, Robert Beverly |
SIGCOMM | 2 |
| 2016 | Decomposition of MAC address structure for granular device inference
Jeremy Martin, Erik C. Rye, Robert Beverly |
ACSAC | 3 |
| 2016 | Yarrp'ing the Internet: Randomized High-Speed Active Topology Discovery
Robert Beverly |
Internet Measurement Conference | 1 |
| 2015 | Resilience of Deployed TCP to Blind AttacksabstractAs part of TCP's steady evolution, recent standards have recommended mechanisms to protect against weaknesses in TCP. But adoption, configuration, and deployment of TCP improvements can be slow. In this work, we consider the resilience of deployed TCP implementations to blind in-window attacks, where an off-path adversary disrupts an established connection by sending a packet that the victim believes came from its peer, causing data corruption or connection reset. We tested operating systems (and middleboxes deployed in front) of webservers in the wild in September 2015 and found 22% of connections vulnerable to in-window SYN and reset packets, 30% vulnerable to in-window data packets, and 38.4% vulnerable to at least one of three in-window attacks we tested. We also tested out-of-window packets and found that while few deployed systems were vulnerable to reset and SYN packets, 5.4% of connections accepted in-window data with an invalid acknowledgment number. In addition to evaluating commodity TCP stacks, we found vulnerabilities in 12 of 14 of the routers and switches we characterized -- critical network infrastructure where the potential impact of any TCP vulnerabilities is particularly acute. This surprisingly high level of extant vulnerabilities in the most mature Internet transport protocol in use today is a perfect illustration of the Internet's fragility. Embedded in historical context, it also provides a strong case for more systematic, scientific, and longitudinal measurement and quantitative analysis of fundamental properties of critical Internet infrastructure, as well as for the importance of better mechanisms to get best security practices deployed. Matthew J. Luckie, Robert Beverly, Tiange Wu, Mark Allman, K. C. Claffy |
Internet Measurement Conference | 2 |
| 2015 | Server Siblings: Identifying Shared IPv4/IPv6 Infrastructure Via Active Fingerprinting
Robert Beverly, Arthur W. Berger |
PAM | 1 |
| 2015 | Measuring and Characterizing IPv6 Router Availability
Robert Beverly, Matthew J. Luckie, Lorenza Mosley, K. C. Claffy |
PAM | 1 |
| 2014 | Uncovering network tarpits with degreaserabstractNetwork tarpits, whereby a single host or appliance can masquerade as many fake hosts on a network and slow network scanners, are a form of defensive cyber-deception. In this work, we develop degreaser, an efficient fingerprinting tool to remotely detect tarpits. In addition to validating our tool in a controlled environment, we use degreaser to perform an Internet-wide scan. We discover tarpits of non-trivial size in the wild (prefixes as large as/16), and characterize their distribution and behavior. We then show how tarpits pollute existing network measurement surveys that are tarpit-naïve, e.g. Internet census data, and how degreaser can improve the accuracy of such surveys. Lastly, our findings suggest several ways in which to advance the realism of current network tarpits, thereby raising the bar on tarpits as an operational security mechanism. Lance Alt, Robert Beverly, Alberto Dainotti |
ACSAC | 2 |
| 2014 | Ingress Point Spreading: A New Primitive for Adaptive Active Network Mapping
Guillermo Baltra, Robert Beverly, Geoffrey G. Xie |
PAM | 2 |
| 2014 | A middlebox-cooperative TCP for a non end-to-end internetabstractUnderstanding, measuring, and debugging IP networks, particularly across administrative domains, is challenging. One particularly daunting aspect of the challenge is the presence of transparent middleboxes---which are now common in today's Internet. In-path middleboxes that modify packet headers are typically transparent to a TCP, yet can impact end-to-end performance or cause blackholes. We develop TCP HICCUPS to reveal packet header manipulation to both endpoints of a TCP connection. HICCUPS permits endpoints to cooperate with currently opaque middleboxes without prior knowledge of their behavior. For example, with visibility into end-to-end behavior, a TCP can selectively enable or disable performance enhancing options. This cooperation enables protocol innovation by allowing new IP or TCP functionality (e.g., ECN, SACK, Multipath TCP, Tcpcrypt) to be deployed without fear of such functionality being misconstrued, modified, or blocked along a path. HICCUPS is incrementally deployable and introduces no new options. We implement and deploy TCP HICCUPS across thousands of disparate Internet paths, highlighting the breadth and scope of subtle and hard to detect middlebox behaviors encountered. We then show how path diagnostic capabilities provided by HICCUPS can benefit applications and the network. Ryan Craven, Robert Beverly, Mark Allman |
SIGCOMM | 2 |
| 2013 | Internet nameserver IPv4 and IPv6 address relationshipsabstractThe modern Domain Name System (DNS) provides not only resolution, but also enables intelligent client routing, e.g. for Content Distribution Networks (CDNs). The adoption of IPv6 presents CDNs the opportunity to utilize different paths when optimizing traffic, and the challenge of appropriately mapping IPv6 DNS queries. This work seeks to discover the associations between Internet DNS client resolver IPv6 address(es) and IPv4 address(es). We design and implement two new techniques, one passive and one active, to gather resolver pairings. The passive technique, deployed in Akamai's production DNS infrastructure, opportunistically discovered 674k (IPv4, IPv6) associated address pairs within a six-month period. We find that 34% of addresses are one-to-one, i.e. appear in no other pair, a fraction that increases to ~50% when aggregating IPv6 addresses into /64 prefixes. The one-to-one associations are suggestive, but not a sufficient condition, of dual-stack DNS recursive resolvers. We further substantiate our inferences via PTR records and software versions, and manual verification of sample pairings by three major Network Operators. Complex associations, where e.g. distributed DNS resolution leads to inferred address groupings that span continents and many autonomous systems exist, a subset of which we explore in more depth using the active probing technique. Among potential uses, Akamai is currently utilizing screened output from the passive technique, in conjunction with prior knowledge of IPv4, to inform IPv6 geolocation within its CDN. Arthur W. Berger, Nicholas Weaver, Robert Beverly, Larry Campbell |
Internet Measurement Conference | 3 |
| 2013 | Speedtrap: internet-scale IPv6 alias resolutionabstractImpediments to resolving IPv6 router aliases have precluded understanding the emerging router-level IPv6 Internet topology. In this work, we design, implement, and validate the first Internet-scale alias resolution technique for IPv6. Our technique, speedtrap, leverages the ability to induce fragmented IPv6 responses from router interfaces in a particular temporal pattern that produces distinguishing per-router fingerprints. Our algorithm surmounts three fundamental challenges to Internet-scale IPv6 alias resolution using fragment identifier values: (1) unlike for IPv4, the identifier counters on IPv6 routers have no natural velocity, (2) the values of these counters are similar across routers, and (3) the packet size required to collect inferences is 46 times larger than required in IPv4. We demonstrate the efficacy of the technique by producing router-level Internet IPv6 topologies using measurements from CAIDA's distributed infrastructure. Our preliminary work represents a step toward understanding the Internet's IPv6 router-level topology, an important objective with respect to IPv6 network resilience, security, policy, and longitudinal evolution. Matthew J. Luckie, Robert Beverly, William Brinkmeyer, K. C. Claffy |
Internet Measurement Conference | 2 |
| 2013 | IPv6 Alias Resolution via Induced Fragmentation
Robert Beverly, William Brinkmeyer, Matthew J. Luckie, Justin P. Rohrer |
PAM | 1 |
| 2011 | Measuring the state of ECN readiness in servers, clients, and routersabstractBetter exposing congestion can improve traffic management in the wide-area, at peering points, among residential broadband connections, and in the data center. TCP's network utilization and efficiency depends on congestion information, while recent research proposes economic and policy models based on congestion. Such motivations have driven widespread support of Explicit Congestion Notification (ECN)in modern operating systems. We reappraise the Internet's ECN readiness, updating and extending previous measurements. Across large and diverse server populations, we find a three-fold increase in ECN support over prior studies. Using new methods, we characterize ECN within mobile infrastructure and at the client-side, populations previously unmeasured. Via large-scale path measurements, we find the ECN feedback loop failing in the core of the network 40% of the time, typically at AS boundaries. Finally, we discover new examples of infrastructure violating ECN Internet standards, and discuss remaining impediments to running ECN while suggesting mechanisms to aid adoption. Steven J. Bauer, Robert Beverly, Arthur W. Berger |
Internet Measurement Conference | 2 |
| 2010 | Primitives for active internet topology mapping: toward high-frequency characterizationabstractCurrent large-scale topology mapping systems require multiple days to characterize the Internet due to the large amount of probing traffic they incur. The accuracy of maps from existing systems is unknown, yet empirical evidence suggests that additional fine-grained probing exposes hidden links and temporal dynamics. Through longitudinal analysis of data from the Archipelago and iPlane systems, in conjunction with our own active probing, we examine how to shorten Internet topology mapping cycle time. In particular, this work develops discriminatory primitives that maximize topological fidelity while being efficient. Robert Beverly, Arthur W. Berger, Geoffrey G. Xie |
Internet Measurement Conference | 1 |
| 2009 | Understanding the efficacy of deployed internet source address validation filteringabstractIP source address forgery, or “spoofing, ” is a long-recognized consequence of the Internet’s lack of packet-level authenticity. Despite historical precedent and filtering and tracing efforts, attackers continue to utilize spoofing for anonymity, indirection, and amplification. Using a distributed infrastructure and approximately 12,000 active measurement clients, we collect data on the prevalence and efficacy of current bestpractice source address validation techniques. Of clients able to test their provider’s source-address filtering rules, we find 31 % able to successfully spoof an arbitrary, routable source address, while 77 % of clients otherwise unable to spoof can forge an address within their own /24 subnetwork. We uncover significant differences in filtering depending upon network geographic region, type, and size. Our new tracefilter tool for filter location inference finds 80 % of filters implemented a single IP hop from sources, with over 95 % of blocked packets observably filtered within the source’s autonomous system. Finally, we provide initial longitudinal results on the evolution of spoofing revealing no mitigation improvement over four years of measurement. Our analysis provides an empirical basis for evaluating incentive and coordination issues surrounding existing and future Internet packet authentication strategies. Robert Beverly, Arthur W. Berger, Young Hyun, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2007 | The Internet Is Not a Big Truck: Toward Quantifying Network Neutrality
Robert Beverly, Steven J. Bauer, Arthur W. Berger |
PAM | 1 |
| 2002 | RTG: A Scalable SNMP Statistics Architecture for Service Providers
Robert Beverly |
LISA | 1 |