Patrick Sattler

dblp:202/1845 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0001-9375-3113ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 5 since 2021Security and privacy · 3 · 3 since 2021
YearPublicationVenuePosition
2025 Lazy Eye Inspection: Capturing the State of Happy Eyeballs Implementations
abstract
While transitioning to an IPv6-only communication, many devices settled on a dual-stack setup. IPv4 and IPv6 are available to these hosts for new connections. Happy Eyeballs (HE) describes a mechanism to prefer IPv6 for such hosts while ensuring a fast fallback to IPv4 when IPv6 fails. The IETF is currently working on the third version of HE. While the standards include recommendations for HE parameter choices, it is up to the client and OS to implement HE. In this paper, we investigate the state of HE in various clients, particularly web browsers and recursive resolvers. We introduce a framework to analyze and measure clients' HE implementations and parameter choices. According to our evaluation, only Safari supports all HE features. Safari is also the only client implementation in our study that uses a dynamic IPv4 connection attempt delay, a resolution delay, and interlaces addresses. We further show that problems with the DNS A record lookup can even delay and interrupt the network connectivity despite a fully functional IPv6 setup with Chrome and Firefox. We operate a publicly available website ( www.happy-eyeballs.net ) which measures the browser's HE behavior, and we publish our testbed measurement framework.
Patrick Sattler, Matthias Kirstein, Lars Wüstrich, Johannes Zirngibl, Georg Carle
IMC1
2024 QUIC Hunter: Finding QUIC Deployments and Identifying Server Libraries Across the Internet
Johannes Zirngibl, Florian Gebauer, Patrick Sattler, Markus Sosnowski, Georg Carle
PAM (2)3
2024 EFACTLS: Effective Active TLS Fingerprinting for Large-Scale Server Deployment Characterization
abstract
Active measurements allow the collection of server characteristics on a large scale that can aid in discovering hidden relations and commonalities among server deployments. Finding these relations opens up new possibilities for clustering and classifying server deployments; for example, identifying a previously unknown cybercriminal infrastructure can be valuable cyber-threat intelligence. In this work, we propose a methodology based on active measurements to acquire Transport Layer Security (TLS) metadata from servers and leverage it for fingerprinting. Our fingerprints capture characteristic behavior of the TLS stack, primarily influenced by the server’s implementation, configuration, and hardware support. Using an empirical optimization strategy that maximizes information gained from every handshake to minimize measurement costs, we generated 10 general-purpose Client Hellos. They served as scanning probes to create an extensive database of TLS configurations to classify servers. We propose the Shannon Entropy to measure collected information and compare different approaches. This study fingerprinted 8 million servers from the Tranco top list and two Command and Control (C2) blocklists over 60 weeks with weekly snapshots. The resulting data formed the foundation for two long-term case studies: classification of Content Delivery Network and C2 servers. Moreover, the detection was fine-grained enough to detect C2 server families. The proposed methodology demonstrated a precision of 99% and enabled a stable identification of new servers over time. This study shows how active measurements can provide valuable security-relevant insights and improve our understanding of the Internet.
Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle, Claas Grohnfeldt, Michele Russo, Daniele Sgandurra
IEEE Trans. Netw. Serv. Manag.3
2023 On the Accuracy of Active Capacity Estimation in the Internet
abstract
Estimating the capacity of network paths is a frequently and versatilely used technique for network and flow analysis used by service providers and researchers to analyze available bandwidth, performance limitations of connections, or infrastructure deployments. While researchers evaluated different capacity estimation approaches in the early 2000s, there are no recent studies on the accuracy of estimates and capacity deployments in today’s Internet.This paper is purposed to survey the accuracy of actively conducted capacity estimation in today’s Internet. We implement passive packet pair dispersion-based capacity estimation according to the PPrate algorithm and conduct active measurements with TCP and ICMP traffic on controlled targets in the Internet and on public web servers to analyze the accuracy and stability of estimated capacities in the Internet.Our study confirms the general accuracy of PPD-based measurements through the Internet while we observe and discuss impacts by interrupt coalescence, receive offloading, and ICMP rate limiting of middleboxes. Measurements to over 3500 web servers taken from the Alexa top 1M list indicate capacities of at least 1 Gbit/s for the majority of paths to measurement targets, while ICMP-based measurements frequently result in significant underestimation due to ICMP rate limiting.
Janluka Janelidze, Benedikt Jaeger, Patrick Sattler, Patryk Brzoza, Georg Carle
NOMS4
2023 DissecTLS: A Scalable Active Scanner for TLS Server Configurations, Capabilities, and TLS Fingerprinting
abstract
Abstract Collecting metadata from Transport Layer Security (TLS) servers on a large scale allows to draw conclusions about their capabilities and configuration. This provides not only insights into the Internet but it enables use cases like detecting malicious Command and Control (C &C) servers. However, active scanners can only observe and interpret the behavior of TLS servers, the underlying configuration and implementation causing the behavior remains hidden. Existing approaches struggle between resource intensive scans that can reconstruct this data and light-weight fingerprinting approaches that aim to differentiate servers without making any assumptions about their inner working. With this work we propose DissecTLS, an active TLS scanner that is both light-weight enough to be used for Internet measurements and able to reconstruct the configuration and capabilities of the TLS stack. This was achieved by modeling the parameters of the TLS stack and derive an active scan that dynamically creates scanning probes based on the model and the previous responses from the server. We provide a comparison of five active TLS scanning and fingerprinting approaches in a local testbed and on toplist targets. We conducted a measurement study over nine weeks to fingerprint C &C servers and analyzed popular and deprecated TLS parameter usage. Similar to related work, the fingerprinting achieved a maximum precision of 99 % for a conservative detection threshold of 100 %; and at the same time, we improved the recall by a factor of 2.8.
Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle
PAM3
2023 How Ready is DNS for an IPv6-Only World?
abstract
Abstract DNS is one of the core building blocks of the Internet. In this paper, we investigate DNS resolution in a strict IPv6-only scenario and find that a substantial fraction of zones cannot be resolved. We point out, that the presence of an resource record for a zone’s nameserver does not necessarily imply that it is resolvable in an IPv6-only environment since the full DNS delegation chain must resolve via IPv6 as well. Hence, in an IPv6-only setting zones may experience an effect similar to what is commonly referred to as lame delegation. Our longitudinal study shows that the continuing centralization of the Internet has a large impact on IPv6 readiness, i.e., a small number of large DNS providers has, and still can, influence IPv6 readiness for a large number of zones. A single operator that enabled IPv6 DNS resolution–by adding IPv6 glue records–was responsible for around 20.3% of all zones in our dataset not resolving over IPv6 until January 2017. Even today, 10% of DNS operators are responsible for more than 97.5% of all zones that do not resolve using IPv6 .
Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig
PAM2
2022 Towards a tectonic traffic shift?: investigating Apple's new relay network
abstract
Apple recently published its first Beta of the iCloud Private Relay, a privacy protection service with promises resembling the ones of VPNs. The architecture consists of two layers (ingress and egress), operated by disjoint providers. The service is directly integrated into Apple's operating systems, providing a low entry-level barrier for a large user base. It seems to be set up for significant adoption with its relatively moderate entry-level price.
Patrick Sattler, Juliane Aulbach, Johannes Zirngibl, Georg Carle
IMC1
2022 Rusty clusters?: dusting an IPv6 research foundation
abstract
The long-running IPv6 Hitlist service is an important foundation for IPv6 measurement studies. It helps to overcome infeasible, complete address space scans by collecting valuable, unbiased IPv6 address candidates and regularly testing their responsiveness. However, the Internet itself is a quickly changing ecosystem that can affect long-running services, potentially inducing biases and obscurities into ongoing data collection means. Frequent analyses but also updates are necessary to enable a valuable service to the community.
Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle
IMC3
2021 It's over 9000: analyzing early QUIC deployments with the standardization on the horizon
abstract
After nearly five years and 34 draft versions, standardization of the new connection oriented transport protocol QUIC was finalized in May 2021. Designed as a fundamental network protocol with increased complexity due to the combination of functionality from multiple network stack layers, it has the potential to drastically influence the Internet ecosystem. Nevertheless, even in its early stages, the protocol attracted a variety of parties including large providers. Our study shows, that more than 2.3 M IPv4 and 300k IPv6 addresses support QUIC hosting more than 30 M domains.
Johannes Zirngibl, Philippe Buschmann, Patrick Sattler, Benedikt Jaeger, Juliane Aulbach, Georg Carle
Internet Measurement Conference3
2019 Prefix Top Lists: Gaining Insights with Prefixes from Domain-based Top Lists on DNS Deployment
abstract
Domain-based top lists such as the Alexa Top 1M strive to portray the popularity of web domains. Even though their shortcomings (e.g., instability, no aggregation, lack of weights) have been pointed out, domain-based top lists still are an important element of Internet measurement studies.
Johannes Naab, Patrick Sattler, Jonas Jelten, Oliver Gasser, Georg Carle
Internet Measurement Conference2