Kevin Vermeulen

dblp:227/2781 · DBLP profile ↗
← Back
19ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0001-6168-7887ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 4 first-author · 12 since 2021Security and privacy · 4 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Unpacking Internet Ossification: A Large-Scale Study of Path-Impairing Middleboxes Across IPv4 and IPv6
Fahad Hilal, Taha Albakour, Oliver Gasser, Kevin Vermeulen
PAM4
2026 HERMES: Repurposing User-Driven Speed Tests to Monitor the Internet
abstract
Diagnosing performance degradations and pinpointing their source is crucial for operators to make informed routing decisions and for policymakers and researchers to assess the Internet's stability, yet no publicly available observatories currently provide this capability. Existing solutions rely on coarse-grained signals that fail to capture end-user performance, while proprietary solutions are inaccessible and offer limited attribution for identifying the source of a problem. We introduce HERMES, the first open system to fill this gap. HERMES uses publicly available M-Lab speed tests—data that has existed for years but has not previously been used to automatically detect and explain end-user performance degradations at scale. To achieve these goals, HERMES combines statistical techniques to detect performance degradation with novel tomography methods and forward and reverse path measurements to localize the source of a problem. Despite relying only on public data, HERMES matches a reimplementation of a large cloud provider's monitoring system for 94.5% of events visible to both systems, agreeing on the degradation source in the path. HERMES also surfaces 11× more publicly discussed events than existing public observatories. We demonstrate its ability to track weather- and cable-cut disruptions, diagnose routing inefficiencies, and identify persistently congested links.
Loqman Salamatian, Kevin Vermeulen, David R. Choffnes, Ethan Katz-Bassett, Phillipa Gill
SIGCOMM2
2025 Poster: Forwarding Score: A New Metric for Assessing the Quality of Internet Route Surveys
abstract
Internet route survey systems such as Ark and IPRS have typically been evaluated on how well they uncover internet topology (nodes and links from consecutive traceroutehops). We present a new metric, the forwarding score, better adapted to assessing how these systems capture routing behavior, and compare this metric over eight days' data.
Ufuk Bombar, Kevin Vermeulen, Olivier Fourmaux, Timur Friedman
IMC2
2025 Autonomous Systems under AReST: Advanced Revelation of Segment Routing Tunnels
abstract
Segment Routing (Sr), an advanced source routing mechanism, is a promising technology with a wide range of applications that has already gained traction from hardware vendors, network operators, and researchers alike. However, despite the abundance of activity surrounding Sr, little is known about how to gauge Sr deployment and its usage by operators.
Florian Dekinder, Kevin Vermeulen, Benoit Donnet
IMC2
2025 Poster: Investigating the Survivability of the Experimental TCP Option
abstract
In this work, we extend Yarrpbox to assess the survivability of the TCP experimental option across paths toward the Tranco Top-100k domains. Our findings highlight middlebox interference and motivate broader Internet-wide studies. This study represents an initial step toward understanding the feasibility of extending TCP in today's Internet, while highlighting potential pitfalls that must be considered by future protocol designers.
Zahra Yazdani, Fahad Hilal, Cecilia Testart, Alberto Dainotti, Kevin Vermeulen, Tiago Heinrich, Taha Albakour
IMC5
2025 Detecting Traffic Engineering from Public BGP Data
Omar Darwich, Cristel Pelsser, Kevin Vermeulen
PAM3
2025 When the weakest model sees the threat: An explainable ensemble learning system for detecting network attacks
Céline Minh, Kevin Vermeulen, Cédric Lefebvre, Philippe Owezarski, William Ritchie
Comput. Networks2
2024 metAScritic: Reframing AS-Level Topology Discovery as a Recommendation System
abstract
Despite prior efforts, the vast majority of the AS-level topology of the Internet remains hidden from BGP and traceroute vantage points. In this work, we introduce metAScritic, a novel system inspired by recommender system literature, designed to infer interconnections within a given metro. metAScritic uses the intuition that the connectivity matrix at a given metro is a low-rank system, since ASes employ similar peering strategies according to their infrastructures, traffic profiles, and business models. This approach allows metAScritic to accurately reconstruct the complete peering connectivity by measuring a strategic subset of interconnections that capture ASes' underlying peering strategies. We evaluate metAScritic's performance across six large metropolitan areas, achieving an average F-score of 0.88 on various validation datasets, including ground truth. metAScritic measures more than 86K edges and infers more than 368K edges, compared to the 13K edges observed for this subset of ASes in public BGP feeds -- an increase of (24X) what is currently seen. We study the impact of our inferred links on Internet properties, illustrating the extent of the Internet's flattening and demonstrating our ability to better predict the impact of route leaks and prefix hijacks, compared to relying only on the existing public view.
Loqman Salamatian, Kevin Vermeulen, Ítalo S. Cunha, Vasileios Giotsas, Ethan Katz-Bassett
IMC2
2023 An Explainable-by-Design Ensemble Learning System to Detect Unknown Network Attacks
abstract
Machine learning (ML) is a promising technology for network intrusion detection systems. There is a wide range of ML algorithms that are potential candidates for network intrusion detection systems, as they exhibit very good detection accuracy in average. However, significant detection differences appear when facing different kinds of attacks, some being prone to better detect some particular attack types. They then often appear to complement each other. The challenge then lies in determining the accurate result when several ML models provide different results, and this without any explanation about their decision. To address this challenge, our system aims to reconstruct attack patterns from the outputs of these ML models and presenting them in an interpretable manner. For that, we propose an approach combining ensemble learning and stacking with a meta-learner that works on graphical representation of traffic flows, that then provides the required explainability level for the decisions made. The evaluation of our system, using the CSE-CIC-IDS2018 dataset, demonstrates a significant improvement achieved through the combination of multiple ML algorithms. Furthermore, we emphasize the importance of explainability in network intrusion detection systems and the need for accurate and interpretable models. Our system goes beyond traditional detection methods by reporting anomalous feature pairs and providing visual representations of attack patterns, empowering analysts to better understand and respond to network threats.
Céline Minh, Kevin Vermeulen, Cédric Lefebvre, Philippe Owezarski, William Ritchie
CNSM2
2023 The Central Problem with Distributed Content: Common CDN Deployments Centralize Traffic In A Risky Way
abstract
Google, Netflix, Meta, and Akamai serve content to users from offnet servers in thousands of ISPs. These offnets benefit both services and ISPs, via better performance and reduced interdomain and WAN traffic. We argue that this widespread distribution of servers leads to a concentration of traffic and a previously unacknowledged risk, as many ISPs colocate offnets from multiple providers. This trend contributes to many Internet users likely accessing multiple popular services and fetching the majority of their Internet traffic from a single facility -- perhaps even a single rack -- creating shared resources and a correlated risk in cases of failures, attacks, and overload. Alternate ways to access the services often lack sufficient capacity and share resources with more services, creating the potential for cascading failures.
Kevin Vermeulen, Loqman Salamatian, Sang Hoon Kim, Matt Calder, Ethan Katz-Bassett
HotNets1
2023 Replication: Towards a Publicly Available Internet Scale IP Geolocation Dataset
abstract
IP geolocation is one of the most widely used forms of metadata for IP addresses, and despite almost twenty years of effort from the research community, the reality is that there is no accurate, complete, up-to-date, and explainable publicly available dataset for IP geolocation. We argue that a central reason for this state of affairs is the impressive results from prior publications, both in terms of accuracy and coverage: up to street level accuracy and locating millions of IP addresses with a few hundred vantage points in months. We believe the community would substantially benefit from a public baseline dataset and code. To encourage future research in IP geolocation, we replicate two geolocation techniques and evaluate their accuracy and coverage. We show that we can neither use the first technique to obtain the previously claimed street level accuracy, nor the second to geolocate millions of IP addresses on today's Internet and with publicly available measurement infrastructure. In addition to this reappraisal, we re-evaluate the fundamental insights that led to these prior results, as well as provide new insights and recommendations to help the design of future geolocation techniques. All of our code and data are publicly available to support reproducibility.
Omar Darwich, Hugo Rimlinger, Milo Dreyfus, Matthieu Gouel, Kevin Vermeulen
IMC5
2023 Poster: Towards a Publicly Available Framework to Process Traceroutes with MetaTrace
abstract
The objective of this research is to contribute towards the development of an open-source framework for processing large-scale traceroute datasets. By providing such a framework, we aim to benefit the community by saving time in everyday traceroute analysis and enabling the design of new scalable reactive measurements [1], where prior traceroute measurements are leveraged to make informed decisions for future ones[8, 12].
Matthieu Gouel, Omar Darwich, Maxime Mouchet, Kevin Vermeulen
IMC4
2023 RPKI Time-of-Flight: Tracking Delays in the Management, Control, and Data Planes
Romain Fontugne, Amreesh Phokeer, Cristel Pelsser, Kevin Vermeulen, Randy Bush
PAM4
2022 Internet scale reverse traceroute
abstract
Knowledge of Internet paths allows operators and researchers to better understand the Internet and troubleshoot problems. Paths are often asymmetric, so measuring just the forward path only gives partial visibility. Despite the existence of Reverse Traceroute, a technique that captures reverse paths (the sequence of routers traversed by traffic from an arbitrary, uncontrolled destination to a given source), this technique did not fulfill the needs of operators and the research community, as it had limited coverage, low throughput, and inconsistent accuracy. In this paper we design, implement and evaluate revtr 2.0, an Internet-scale Reverse Traceroute system that combines novel measurement approaches and studies with a large-scale deployment to improve throughput, accuracy, and coverage, enabling the first exploration of reverse paths at Internet scale. revtr 2.0 can run 15M reverse traceroutes in one day. This scale allows us to open the system to external sources and users, and supports tasks such as traffic engineering and troubleshooting.
Kevin Vermeulen, Ege Gürmeriçliler, Ítalo S. Cunha, David R. Choffnes, Ethan Katz-Bassett
IMC1
2022 The best of both worlds: high availability CDN routing without compromising control
abstract
Content delivery networks (CDNs) provide fast service to clients by replicating content at geographically distributed sites. Most CDNs route clients to a particular site using anycast or unicast with DNS-based redirection. We analyze anycast and unicast and explain why neither of them provides both precise control of user-to-site mapping and high availability in the face of failures, two fundamental goals of CDNs. Anycast compromises control (and hence performance), and unicast compromises availability. We then present new hybrid techniques and demonstrate via experiments on the real Internet that these techniques provide both a high level of traffic control and fast failover following site failures.
Jiangchen Zhu, Kevin Vermeulen, Ítalo S. Cunha, Ethan Katz-Bassett, Matt Calder
IMC2
2021 Towards a traffic map of the Internet Connecting the dots between popular services and users: Connecting the dots between popular services and users
abstract
The impact of Internet phenomena depends on how they impact users, but researchers lack visibility into how to translate Internet events into their impact. Distressingly, the research community seems to have lost hope of obtaining this information without relying on privileged viewpoints. We argue for optimism thanks to new network measurement methods and changes in Internet structure which make it possible to construct an "Internet traffic map". This map would identify the locations of users and major services, the paths between them, and the relative activity levels routed along these paths. We sketch our vision for the map, detail new measurement ideas for map construction, and identify key challenges that the research community should tackle. The realization of an Internet traffic map will be an Internet-scale research effort with Internet-scale impacts that reach far beyond the research community, and so we hope our fellow researchers are excited to join us in addressing this challenge.
Weifan Jiang, Petros Gigis, Kevin Vermeulen, Emile Aben, Matt Calder, Ethan Katz-Bassett, Lefteris Manassakis, Georgios Smaragdakis, Narseo Vallina-Rodriguez
HotNets6
2020 Diamond-Miner: Comprehensive Discovery of the Internet's Topology Diamonds
Kevin Vermeulen, Justin P. Rohrer, Robert Beverly, Olivier Fourmaux, Timur Friedman
NSDI1
2020 Alias Resolution Based on ICMP Rate Limiting
Kevin Vermeulen, Burim Ljuma, Vamsi Addanki, Matthieu Gouel, Olivier Fourmaux, Timur Friedman, Reza Rejaie
PAM1
2018 Multilevel MDA-Lite Paris Traceroute
Kevin Vermeulen, Stephen D. Strowes, Olivier Fourmaux, Timur Friedman
Internet Measurement Conference1