VLDB 2026 Research / reviewers in the wild / expert
Raffaele Sommese
dblp:193/3162
· DBLP profile ↗
21ranked-venue papers
8as first author
18since 2021 · last 2026
0000-0003-3484-9259ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 5 first-author · 9 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Through a Smaller Lens: Revisiting Opportunistic Analysis Using Network Telescopes
Bernhard Degen, Nils Kempen, K. C. Claffy, Ricky K. P. Mok, Ralph Holz, Roland van Rijswijk-Deij, Raffaele Sommese, Mattijs Jonker |
PAM | 7 |
| 2026 | Load-Balancing Versus Anycast: A First Look at Operational ChallengesabstractLoad Balancing (LB) is a routing strategy that increases performance by distributing traffic over multiple outgoing paths. In this work, we introduce a novel methodology to detect the influence of LB on anycast routing, which can be used by operators to detect networks that experience anycast site flipping, where traffic from a single client reaches multiple anycast sites. We use our methodology to measure the effects of LB-behavior on anycast routing at a global scale, covering both IPv4 and IPv6. Our results show that LB-induced anycast site flipping is widespread. The results also show our method can detect LB implementations on the global Internet, including detection and classification of Points-of-Presence (PoP) and egress selection techniques deployed by hypergiants, cloud providers, and network operators. We observe LB-induced site flipping directs distinct flows to different anycast sites with significant latency inflation. In cases with two paths between an anycast instance and a load-balanced destination, we observe an average RTT difference of 30 ms with 8% of load-balanced destinations seeing RTT differences of over 100 ms. Being able to detect these cases can help anycast operators significantly improve their service for affected clients. Remi Hendriks, Mattijs Jonker, Roland van Rijswijk-Deij, Raffaele Sommese |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | 90th Minute: A First Look to Collateral Damages and Efficacy of the Italian Piracy ShieldabstractIn the fight against illegal football streaming, Italy introduced Piracy Shield, a platform through which copyright holders can notify the national regulator (AGCOM), which in turn orders ISPs to block infringing resources -- such as IP addresses and Fully Qualified Domain Names (FQDNs) -- within 30 minutes. In this paper, we present the first investigation into the platform's real-world impact by reconstructing and analyzing its blocking activity. Our analysis shows that the platform causes significant collateral damage. Indiscriminate IP-level blocking has disrupted and continues to disrupt hundreds of legitimate, non-streaming websites. At the same time, the platform's effectiveness may have been undermined by streamers who evaded enforcement by migrating to new infrastructure and unfiltered IP address space. Based on these findings, we call on Italian authorities and policymakers to critically reconsider the platform's core blocking principles. The evidence suggests that its broad impact on legitimate services and the potential national security risks outweigh its intended benefits. Raffaele Sommese, Anna Sperotto, Antonio Prado, Jeroen van der Ham, Antonia Affinito |
CNSM | 1 |
| 2025 | HideMe: Hiding VMs from Co-Residency Attacks Using Network-Level Traffic RedirectionabstractVirtual Machine (VM) co-residency occurs when two virtual machines belonging to different users share the same physical host. Co-residency brings important security implications when one of the VMs is malicious: side-channel leakage, denial of service, and performance degradation are all possible attack vectors that can be leveraged. Achieving co-residency is a two-step process: VM placement and detection. While most of the literature focuses on preventing physical placement, we address the under-explored second step: preventing co-residency confirmation. We present HideMe, a modular, lightweight system that detects malicious probes based on dynamic host behavior and redirects them to decoy VMs. Evaluated in two realistic scenarios, HideMe demonstrates high efficacy, preventing 100% of attacks in consistent traffic environments and 97% in highly variable traffic, all with zero false positives and under strict visibility constraints. As contribution, we also release Hide me under an open-source license, provide deployment instructions for network operators, and outline directions for further improvement. Bogdan-Nicolae Stanculete, Raffaele Sommese |
CNSM | 2 |
| 2025 | Double-Edged Sword: An Empirical Study on the Contribution of Cloud Providers in Malicious InfrastructureabstractCloud computing offers flexibility and costeffectiveness, but can also be abused for malicious activities. In this study, we conduct an empirical analysis of the cloud infrastructure of malicious (blocklisted) domains, with a focus on three core infrastructural components — web hosting, DNS, and email — and we compare them against a baseline of general domains. Our goal is to assess the rate of abuse targeting these components as they represent fundamental pillars of Internet communication. Leveraging DNS data from OpenINTEL, cloud classification from IP2Location, and a curated ground-truth list of cloud providers, we evaluate the role of major providers in hosting malicious infrastructure. Our results show that malicious domains are increasingly shifting toward partial cloud infrastructure outsourcing, with a strong preference for cloud-based web hosting while avoiding full-stack cloud adoption. We also observe a high degree of diversity of malicious infrastructure deployment across all three components. Finally, our country analysis highlights a growing concentration of malicious hosting activity in the Asia-Pacific region. Sousan Tarahomi, Raffaele Sommese, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 2 |
| 2025 | LACeS: An Open, Fast, Responsible and Efficient Longitudinal Anycast Census Systemabstract[1.5.4] - 2026-08-10 Changed Fixed --accuracy quadratic cost - candidate_diameter was computed by comparing every pair of surviving candidates. This was expensive for large MIS discs. We now approximate the distance for large MIS discs using a farthest-point sweep. Documentation Added a section on the accuracy trade-off between disc intersection and single-disc (iGreedy) geolocation. Full Changelog: https://github.com/rhendriks/MiGreedy/compare/v1.5.3...v1.5.4 Remi Hendriks, Matthew J. Luckie, Mattijs Jonker, Raffaele Sommese, Roland van Rijswijk-Deij |
IMC | 4 |
| 2025 | An Empirical Evaluation of Longitudinal Anycast Catchment Stability
Remi Hendriks, Bernhard Degen, Bas Palinckx, Raffaele Sommese, Roland van Rijswijk-Deij |
PAM | 4 |
| 2025 | An Integrated Active Measurement Programming Environment
Matthew J. Luckie, Shivani Hariprasad, Raffaele Sommese, Brendon Jones, Ken Keys, Ricky K. P. Mok, K. C. Claffy |
PAM | 3 |
| 2024 | Is a Name Enough? A First Look into Detecting Clouds Using DNS Pointer RecordsabstractThe flexibility and scalability of cloud services have led to their adoption across various industries. While it is easy to identify deployments of very large cloud providers (hypergiants) as they often publish the allocation of their network resources, this is much less commonly the case for smaller providers. Despite efforts by commercial IP intelligence providers to bridge this gap, it is not clear how complete and reliable their data is, which is compounded by the lack of transparency surrounding their identification methods. In this early study, we utilize reverse DNS, a public data source provided and used by network operators, to identify the IP cloud space. We develop a Markov chain-based classifier to identify patterns and structures in the reverse DNS naming schemes of cloud providers. Our results indicate that cloud infrastructure naming often differs significantly from that of residential IP space, although there are some overlaps that require further investigation. We believe that our model can be used by network operators to identify cloud deployments with varying levels of confidence. Sousan Tarahomi, Raffaele Sommese, Pieter-Tjerk de Boer, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 2 |
| 2024 | The Wisdom of the Measurement Crowd: Building the Internet Yellow Pages a Knowledge Graph for the InternetabstractThe Internet measurement community has significantly advanced our understanding of the Internet by documenting its various components. Subsequent research often builds on these efforts, using previously published datasets. This process is fundamental for researchers, but a laborious task due to the diverse data formats, terminologies, and areas of expertise involved. Additionally, the time-consuming task of merging datasets is undertaken only if the expected benefits are worthwhile, posing a barrier to simple exploration and innovation. In this paper we present the Internet Yellow Pages (IYP), a knowledge graph for Internet resources. By leveraging the flexibility of graph databases and ontology-based data integration, we compile datasets (currently 46) from diverse and independent sources into a single harmonized database where the meaning of each entity and relationship is unequivocal. Using simple examples, we illustrate how IYP allows us to seamlessly navigate data coming from numerous underlying sources. As a result, IYP significantly reduces time to insight, which we demonstrate by reproducing two past studies and extending them by incorporating additional datasets available in IYP. Finally, we discuss how IYP can foster the sharing of datasets as it provides a universal platform for querying and describing data. This is a seminal effort to bootstrap what we envision as a community-driven project where dataset curation and ontology definitions evolve with the Internet measurement community. Romain Fontugne, Malte Tashiro, Raffaele Sommese, Mattijs Jonker, Zachary S. Bischof, Emile Aben |
IMC | 3 |
| 2024 | DarkDNS: Revisiting the Value of Rapid Zone UpdateabstractMalicious actors exploit the DNS namespace to launch spam campaigns, phishing attacks, malware, and other harmful activities. Combating these threats requires visibility into domain existence, ownership and nameservice activity that the DNS protocol does not itself provide. To facilitate visibility and security-related study of the expanding gTLD namespace, ICANN introduced the Centralized Zone Data Service (CZDS) that shares daily zone file snapshots of new gTLD zones. However, a remarkably high concentration of malicious activity is associated with domains that do not live long enough make it into these daily snapshots. Using public and private sources of newly observed domains, we discover that even with the best available data there is a considerable visibility gap in detecting short-lived domains. We find that the daily snapshots miss at least 1% of newly registered and short-lived domains, which are frequently registered with likely malicious intent. In reducing this critical visibility gap using public sources of data, we demonstrate how more timely access to TLD zone changes can provide valuable data to better prevent abuse. We hope that this work sparks a discussion in the community on how to effectively and safely revive the concept of sharing Rapid Zone Updates for security research. Finally, we release a public live feed of newly registered domains, with the aim of enabling further research in abuse identification. Raffaele Sommese, Gautam Akiwate, Antonia Affinito, Mattijs Jonker, K. C. Claffy |
IMC | 1 |
| 2023 | Poster: Through the ccTLD Looking Glass: Mining CT Logs for Fun, Profit and Domain NamesabstractNo abstract available. Raffaele Sommese, Mattijs Jonker |
IMC | 1 |
| 2022 | Assessing e-Government DNS ResilienceabstractElectronic government (e-gov) enables citizens and residents to digitally interact with their government via the Internet. Underpinning these services is the Internet Domain Name Systems (DNS), which maps e-gov domain names to Internet addresses. Structuring DNS with multiple levels of redundancy that can withstand stress events such as denial-of-service (DoS) attacks is a challenging task. While the operator community has established best practices to this end, adopting them all involves expert knowledge and resources. In this work, we obtain and study a list of e-gov domain names used by four countries (The Netherlands, Sweden, Switzerland, and the United States) and measure the DNS structuring of these domains. We show the adoption of best practices, inter-country differences such as the use of anycast, and provide recommendations to improve DNS service robustness. Raffaele Sommese, Mattijs Jonker, Jeroen van der Ham, Giovane Cesar Moreira Moura |
CNSM | 1 |
| 2022 | Retroactive identification of targeted DNS infrastructure hijackingabstractIn 2019, the US Department of Homeland Security issued an emergency warning about DNS infrastructure tampering. This alert, in response to a series of attacks against foreign government websites, highlighted how a sophisticated attacker could leverage access to key DNS infrastructure to then hijack traffic and harvest valid login credentials for target organizations. However, even armed with this knowledge, identifying the existence of such incidents has been almost entirely via post hoc forensic reports (i.e., after a breach was found via some other method). Indeed, such attacks are particularly challenging to detect because they can be very short lived, bypass the protections of TLS and DNSSEC, and are imperceptible to users. Identifying them retroactively is even more complicated by the lack of fine-grained Internet-scale forensic data. This paper is a first attempt to make progress at this latter goal. Combining a range of longitudinal data from Internet-wide scans, passive DNS records, and Certificate Transparency logs, we have constructed a methodology for identifying potential victims of sophisticated DNS infrastructure hijacking and have used it to identify a range of victims (primarily government agencies), both those named in prior reporting, and others previously unknown. Gautam Akiwate, Raffaele Sommese, Mattijs Jonker, Zakir Durumeric, K. C. Claffy, Geoffrey M. Voelker, Stefan Savage |
IMC | 2 |
| 2022 | Observable KINDNS: validating DNS hygieneabstractThe Internet's naming system (DNS) is a hierarchically structured database, with hundreds of millions of domains in a radically distributed management architecture. The distributed nature of the DNS is the primary factor that allowed it to scale to its current size, but it also brings security and stability risks. The Internet standards community (IETF) has published several operational best practices to improve DNS resilience, but operators must make their own decisions that tradeoff security, cost, and complexity. Since these decisions can impact the security of billions of Internet users, recently ICANN has proposed an initiative to codify best practices into a set of global norms to improve security: the Knowledge-Sharing and Instantiating Norms for DNS and Naming Security (KINDNS) [4]. A similar effort for routing security - Mutually Agreed Norms for Routing Security - provided inspiration for this effort. The MANRS program encourages operators to voluntarily commit to a set of practices that will improve collective routing security - a challenge when incentives to conform with these practices does not generate a clear return on investment for operators. One challenge for both initiatives is independent verification of conformance with the practices. The KINDNS conversation has just started, and stakeholders are still debating what should be in the set of practices. At this early stage, we analyze possible best practices in terms of their measurability by third parties, including a review of DNS measurement studies and available data sets (Table 1). Raffaele Sommese, Mattijs Jonker, K. C. Claffy |
IMC | 1 |
| 2022 | Investigating the impact of DDoS attacks on DNS infrastructureabstractDenial of Service (DDoS) attacks both abuse and target core Internet infrastructures and services, including the Domain Name System (DNS). To characterize recent DDoS attacks against authoritative DNS infrastructure, we join two existing data sets - DoS activity inferred from a sizable darknet, and contemporaneous DNS measurement data - for a 17-month period (Nov. 20 - Mar. 22). Our measurements reveal evidence that millions of domains (up to 5% of the DNS namespace) experienced a DoS attack during our observation window. Most attacks did not substantially harm DNS performance, but in some cases we saw 100-fold increases in DNS resolution time, or complete unreachability. Our measurements captured a devastating attack against a large provider in the Netherlands (TransIP), and attacks against Russian infrastructure. Our data corroborates the value of known best practices to improve DNS resilience to attacks, including the use of anycast and topological redundancy in nameserver infrastructure. We discuss the strengths and weaknesses of our data sets for DDoS tracking and impact on the DNS, and promising next steps to improve our understanding of the evolving DDoS ecosystem. Raffaele Sommese, K. C. Claffy, Roland van Rijswijk-Deij, Arnab Chattopadhyay, Alberto Dainotti, Anna Sperotto, Mattijs Jonker |
IMC | 1 |
| 2022 | Saving Brian's privacy: the perils of privacy exposure through reverse DNSabstractGiven the importance of privacy, many Internet protocols are nowadays designed with privacy in mind (e.g., using TLS for confidentiality). Foreseeing all privacy issues at the time of protocol design is, however, challenging and may become near impossible when interaction out of protocol bounds occurs. One demonstrably not well understood interaction occurs when DHCP exchanges are accompanied by automated changes to the global DNS (e.g., to dynamically add hostnames for allocated IP addresses). As we will substantiate, this is a privacy risk: one may be able to infer device presence and network dynamics from virtually anywhere on the Internet --- and even identify and track individuals --- even if other mechanisms to limit tracking by outsiders (e.g., blocking pings) are in place. Olivier van der Toorn, Roland van Rijswijk-Deij, Raffaele Sommese, Anna Sperotto, Mattijs Jonker |
IMC | 3 |
| 2022 | Hosting Industry Centralization and ConsolidationabstractThere have been growing concerns about the concentration and centralization of Internet infrastructure. In this work, we scrutinize the hosting industry on the Internet by using active measurements, covering 19 Top-Level Domains (TLDs). We show how the market is heavily concentrated: 1/3 of the domains are hosted by only 5 hosting providers, all US-based companies. For the country-code TLDs (ccTLDs), however, hosting is primarily done by local, national hosting providers and not by the large American cloud and content providers. We show how shared languages (and borders) shape the hosting market — German hosting companies have a notable presence in Austrian and Swiss markets, given they all share German as official language. While hosting concentration has been relatively high and stable over the past four years, we see that American hosting companies have been continuously increasing their presence in the market related to high traffic, popular domains within ccTLDs — except for Russia, notably. Luciano Zembruzki, Raffaele Sommese, Lisandro Z. Granville, Arthur Selle Jacobs, Mattijs Jonker, Giovane Cesar Moreira Moura |
NOMS | 2 |
| 2020 | Unresolved Issues: Prevalence, Persistence, and Perils of Lame DelegationsabstractThe modern Internet relies on the Domain Name System (DNS) to convert between human-readable domain names and IP addresses. However, the correct and efficient implementation of this function is jeopardized when the configuration data binding domains, nameservers and glue records is faulty. In particular lame delegations, which occur when a nameserver responsible for a domain is unable to provide authoritative information about it, introduce both performance and security risks. We perform a broad-based measurement study of lame delegations, using both longitudinal zone data and active querying. We show that lame delegations of various kinds are common (affecting roughly 14% of domains we queried), that they can significantly degrade lookup latency (when they do not lead to outright failure), and that they expose hundreds of thousands of domains to adversarial takeover. We also explore circumstances that give rise to this surprising prevalence of lame delegations, including unforeseen interactions between the operational procedures of registrars and registries. Gautam Akiwate, Mattijs Jonker, Raffaele Sommese, Ian D. Foster, Geoffrey M. Voelker, Stefan Savage, K. C. Claffy |
Internet Measurement Conference | 3 |
| 2020 | MAnycast2: Using Anycast to Measure AnycastabstractAnycast addressing - assigning the same IP address to multiple, distributed devices - has become a fundamental approach to improving the resilience and performance of Internet services, but its conventional deployment model makes it impossible to infer from the address itself that it is anycast. Existing methods to detect anycast IPv4 prefixes present accuracy challenges stemming from routing and latency dynamics, and efficiency and scalability challenges related to measurement load. We review these challenges and introduce a new technique we call "MAnycast2" that can help overcome them. Our technique uses a distributed measurement platform of anycast vantage points as sources to probe potential anycast destinations. This approach eliminates any sensitivity to latency dynamics, and greatly improves efficiency and scalability. We discuss alternatives to overcome remaining challenges relating to routing dynamics, suggesting a path toward establishing the capability to complete, in under 3 hours, a full census of which IPv4 prefixes in the ISI hitlist are anycast. Raffaele Sommese, Leandro Marcio Bertholdo, Gautam Akiwate, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
Internet Measurement Conference | 1 |
| 2020 | When Parents and Children Disagree: Diving into DNS Delegation Inconsistency
Raffaele Sommese, Giovane Cesar Moreira Moura, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
PAM | 1 |