VLDB 2026 Research / reviewers in the wild / expert
Kyle Schomp
dblp:142/5366
· DBLP profile ↗
11ranked-venue papers
5as first author
2since 2021 · last 2025
0000-0002-4268-4813ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 2 since 2021Computer networks · 5 · 3 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Characterizing Anycast Flipping: Prevalence and Impact
Shihan Lin, Tingshan Huang, Bruce M. Maggs, Kyle Schomp, Xiaowei Yang 0001 |
PAM | 5 |
| 2022 | Assessing Support for DNS-over-TCP in the Wild
Jiarun Mao, Michael Rabinovich, Kyle Schomp |
PAM | 3 |
| 2020 | Akamai DNS: Providing Authoritative Answers to the World's QueriesabstractWe present Akamai DNS, one of the largest authoritative DNS infrastructures in the world, that supports the Akamai content delivery network (CDN) as well as authoritative DNS hosting and DNS-based load balancing services for many enterprises. As the starting point for a significant fraction of the world's Internet interactions, Akamai DNS serves millions of queries each second and must be resilient to avoid disrupting myriad online services, scalable to meet the ever increasing volume of DNS queries, performant to prevent user-perceivable performance degradation, and reconfigurable to react quickly to shifts in network conditions and attacks. We outline the design principles and architecture used to achieve Akamai DNS's goals, relating the design choices to the system workload and quantifying the effectiveness of those designs. Further, we convey insights from operating the production system that are of value to the broader research community. Kyle Schomp, Onkar Bhardwaj, Eymen Kurdoglu, Mashooq Muhaimen, Ramesh K. Sitaraman |
SIGCOMM | 1 |
| 2019 | A Look at the ECS Behavior of DNS ResolversabstractContent delivery networks (CDNs) commonly use DNS to map end-users to the best edge servers. A recently proposed EDNS0-Client-Subnet (ECS) extension allows recursive resolvers to include end-user subnet information in DNS queries, so that authoritative DNS servers, especially those belonging to CDNs, could use this information to improve user mapping. In this paper, we study the ECS behavior of ECS-enabled recursive resolvers from the perspectives of the opposite sides of a DNS interaction, the authoritative DNS servers of a major CDN and a busy DNS resolution service. We find a range of erroneous (i.e., deviating from the protocol specification) and detrimental (even if compliant) behaviors that may unnecessarily erode client privacy, reduce the effectiveness of DNS caching, diminish ECS benefits, and in some cases turn ECS from facilitator into an obstacle to authoritative DNS servers' ability to optimize user-to-edge-server mappings. Rami Al-Dalky, Michael Rabinovich, Kyle Schomp |
Internet Measurement Conference | 3 |
| 2018 | Characterization of Collaborative Resolution in Recursive DNS Resolvers
Rami Al-Dalky, Kyle Schomp |
PAM | 2 |
| 2016 | Towards a Model of DNS Client Behavior
Kyle Schomp, Michael Rabinovich, Mark Allman |
PAM | 1 |
| 2016 | Is the Web HTTP/2 Yet?
Matteo Varvello, Kyle Schomp, David Naylor, Jeremy Blackburn, Alessandro Finamore, Konstantina Papagiannaki |
PAM | 2 |
| 2015 | Multi-Context TLS (mcTLS): Enabling Secure In-Network Functionality in TLSabstractA significant fraction of Internet traffic is now encrypted and HTTPS will likely be the default in HTTP/2. However, Transport Layer Security (TLS), the standard protocol for encryption in the Internet, assumes that all functionality resides at the endpoints, making it impossible to use in-network services that optimize network resource usage, improve user experience, and protect clients and servers from security threats. Re-introducing in-network functionality into TLS sessions today is done through hacks, often weakening overall security. David Naylor, Kyle Schomp, Matteo Varvello, Ilias Leontiadis, Jeremy Blackburn, Diego R. López, Konstantina Papagiannaki, Pablo Rodriguez 0001, Peter Steenkiste |
SIGCOMM | 2 |
| 2014 | DNS Resolvers Considered HarmfulabstractThe Domain Name System (DNS) is a critical component of the Internet infrastructure that has many security vulnerabilities. In particular, shared DNS resolvers are a notorious security weak spot in the system. We propose an unorthodox approach for tackling vulnerabilities in shared DNS resolvers: removing shared DNS resolvers entirely and leaving recursive resolution to the clients. We show that the two primary costs of this approach---loss of performance and an increase in system load---are modest and therefore conclude that this approach is beneficial for strengthening the DNS by reducing the attack surface. Kyle Schomp, Mark Allman, Michael Rabinovich |
HotNets | 1 |
| 2014 | Assessing DNS Vulnerability to Record Injection
Kyle Schomp, Tom Callahan, Michael Rabinovich, Mark Allman |
PAM | 1 |
| 2013 | On measuring the client-side DNS infrastructureabstractThe Domain Name System (DNS) is a critical component of the Internet infrastructure. It allows users to interact with Web sites using human-readable names and provides a foundation for transparent client request distribution among servers in Web platforms, such as content delivery networks. In this paper, we present methodologies for efficiently discovering the complex client-side DNS infrastructure. We further develop measurement techniques for isolating the behavior of the distinct actors in the infrastructure. Using these strategies, we study various aspects of the client-side DNS infrastructure and its behavior with respect to caching, both in aggregate and separately for different actors. Kyle Schomp, Tom Callahan, Michael Rabinovich, Mark Allman |
Internet Measurement Conference | 1 |