VLDB 2026 Research / reviewers in the wild / expert
Arian Akhavan Niaki
dblp:208/4182
· DBLP profile ↗
9ranked-venue papers
2as first author
3since 2021 · last 2021
0000-0002-4050-7012ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 3 since 2021Computer networks · 3Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Cache Me Outside: A New Look at DNS Cache Probing
Arian Akhavan Niaki, William R. Marczak, Sahand Farhoodi, Andrew McGregor 0001, Phillipa Gill, Nicholas Weaver |
PAM | 1 |
| 2021 | How Great is the Great Firewall? Measuring China's DNS Censorship
Nguyen Phong Hoang, Arian Akhavan Niaki, Jakub Dalek, Jeffrey Knockel, Pellaeon Lin, William R. Marczak, Masashi Crete-Nishihata, Phillipa Gill, Michalis Polychronakis |
USENIX Security Symposium | 2 |
| 2021 | Domain name encryption is not enough: privacy leakage via IP-based website fingerprintingabstractAlthough the security benefits of domain name encryption technologies such as DNS over TLS (DoT), DNS over HTTPS (DoH), and Encrypted Client Hello (ECH) are clear, their positive impact on user privacy is weakened by—the still exposed—IP address information. However, content delivery networks, DNS-based load balancing, co-hosting of different websites on the same server, and IP address churn, all contribute towards making domain–IP mappings unstable, and prevent straightforward IP-based browsing tracking. Nguyen Phong Hoang, Arian Akhavan Niaki, Phillipa Gill, Michalis Polychronakis |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | Assessing the Privacy Benefits of Domain Name EncryptionabstractAs Internet users have become more savvy about the potential for their Internet communication to be observed, the use of network traffic encryption technologies (e.g., HTTPS/TLS) is on the rise. However, even when encryption is enabled, users leak information about the domains they visit via DNS queries and via the Server Name Indication (SNI) extension of TLS. Two recent proposals to ameliorate this issue are DNS over HTTPS/TLS (DoH/DoT) and Encrypted SNI (ESNI). Nguyen Phong Hoang, Arian Akhavan Niaki, Nikita Borisov, Phillipa Gill, Michalis Polychronakis |
AsiaCCS | 2 |
| 2020 | ICLab: A Global, Longitudinal Internet Censorship Measurement PlatformabstractResearchers have studied Internet censorship for nearly as long as attempts to censor contents have taken place. Most studies have however been limited to a short period of time and / or a few countries; the few exceptions have traded off detail for breadth of coverage. Collecting enough data for a comprehensive, global, longitudinal perspective remains challenging.In this work, we present ICLab, an Internet measurement platform specialized for censorship research. It achieves a new balance between breadth of coverage and detail of measurements, by using commercial VPNs as vantage points distributed around the world. ICLab has been operated continuously since late 2016. It can currently detect DNS manipulation and TCP packet injection, and overt "block pages" however they are delivered. ICLab records and archives raw observations in detail, making retrospective analysis with new techniques possible. At every stage of processing, ICLab seeks to minimize false positives and manual validation.Within 53,906,532 measurements of individual web pages, collected by ICLab in 2017 and 2018, we observe blocking of 3,602 unique URLs in 60 countries. Using this data, we compare how different blocking techniques are deployed in different regions and/or against different types of content. Our longitudinal monitoring pinpoints changes in censorship in India and Turkey concurrent with political shifts, and our clustering techniques discover 48 previously unknown block pages. ICLab's broad and detailed measurements also expose other forms of network interference, such as surveillance and malware injection. Arian Akhavan Niaki, Shinyoung Cho, Zachary Weinberg, Nguyen Phong Hoang, Abbas Razaghpanah, Nicolas Christin, Phillipa Gill |
SP | 1 |
| 2020 | Modeling and Evaluation of Service Composition in Commercial Multiclouds Using Timed Colored Petri NetsabstractThe increasing demand for Web services encourages commercial cloud service providers to publish their own services with various functional and nonfunctional capabilities in different cloud platforms. The aggregation of atomic services from multiple service repositories is the main idea of the service composition concept in multiclouds. The cloud Web service composition is a suitable way for satisfying users' complex requests by integrating services from different clouds in order to create a new value-added composite service. The time required to serve a composite service by a multicloud environment is an important parameter, which depends on different factors, ranging from the service composition and selection algorithm to the number of atomic services published in the clouds. In this paper, a model based on timed colored Petri nets (TCPNs) is proposed to evaluate the service composition in multicloud environments while minimizing the number of clouds involved in serving a composite service request. The proposed TCPN graphically models the process of request submission, composite service analysis, service selection, and service provisioning in a multicloud environment. It also assesses both mean response time of the environment and probability of dropping composite requests. The verification of the accuracy of the proposed model is done by comparing the results obtained from the TCPN model, in two different scenarios, with the results from the CloudSim framework. These results confirm that our proposed TCPN model can appropriately model the system and evaluate its performance more efficiently than the CloudSim. Reza Entezari-Maleki, Ehsan Etesami, Negar Ghorbani, Arian Akhavan Niaki, Leonel Sousa, Ali Movaghar-Rahimabadi |
IEEE Trans. Syst. Man Cybern. Syst. | 4 |
| 2019 | A large-scale analysis of deployed traffic differentiation practicesabstractNet neutrality has been the subject of considerable public debate over the past decade. Despite the potential impact on content providers and users, there is currently a lack of tools or data for stakeholders to independently audit the net neutrality policies of network providers. In this work, we address this issue by conducting a one-year study of content-based traffic differentiation policies deployed in operational networks, using results from 1,045,413 crowdsourced measurements conducted by 126,249 users across 2,735 ISPs in 183 countries/regions. We develop and evaluate a methodology that combines individual per-device measurements to form high-confidence, statistically significant inferences of differentiation practices, including fixed-rate bandwidth limits (i.e., throttling) and delayed throttling practices. Using this approach, we identify differentiation in both cellular and WiFi networks, comprising 30 ISPs in 7 countries. We also investigate the impact of throttling practices on video streaming resolution for several popular video streaming providers. Fangfan Li, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove |
SIGCOMM | 2 |
| 2017 | Studying TLS Usage in Android AppsabstractTransport Layer Security (TLS), has become the de-facto standard for secure Internet communication. When used correctly, it provides secure data transfer, but used incorrectly, it can leave users vulnerable to attacks while giving them a false sense of security. Numerous efforts have studied the adoption of TLS (and its predecessor, SSL) and its use in the desktop ecosystem, attacks, and vulnerabilities in both desktop clients and servers. However, there is a dearth of knowledge of how TLS is used in mobile platforms. In this paper we use data collected by Lumen, a mobile measurement platform, to analyze how 7,258 Android apps use TLS in the wild. We analyze and fingerprint handshake messages to characterize the TLS APIs and libraries that apps use, and also evaluate weaknesses. We see that about 84% of apps use default OS APIs for TLS. Many apps use third-party TLS libraries; in some cases they are forced to do so because of restricted Android capabilities. Our analysis shows that both approaches have limitations, and that improving TLS security in mobile is not straightforward. Apps that use their own TLS configurations may have vulnerabilities due to developer inexperience, but apps that use OS defaults are vulnerable to certain attacks if the OS is out of date, even if the apps themselves are up to date. We also study certificate verification, and see low prevalence of security measures such as certificate pinning, even among high-risk apps such as those providing financial services, though we did observe major third-party tracking and advertisement services deploying certificate pinning. Abbas Razaghpanah, Arian Akhavan Niaki, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Johanna Amann, Phillipa Gill |
CoNEXT | 2 |
| 2017 | lib•erate, (n): a library for exposing (traffic-classification) rules and avoiding them efficientlyabstractMiddleboxes implement a variety of network management policies (e.g., prioritizing or blocking traffic) in their networks. While such policies can be beneficial (e.g., blocking malware) they also raise issues of network neutrality and freedom of speech when used for application-specific differentiation and censorship. There is a poor understanding of how such policies are implemented in practice, and how they can be evaded efficiently. As a result, most circumvention solutions are brittle, point solutions based on manual analysis. Fangfan Li, Abbas Razaghpanah, Arash Molavi Kakhki, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove |
Internet Measurement Conference | 4 |