Trinh Viet Doan

dblp:234/2479 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0003-4728-746XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 4 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Proliferation of the Service-centric Distributed Consensus Model and its Impact on Ethereum
abstract
In distributed consensus systems (DCSs), a single peer exposes functionality to other peers to agree on a shared state for a computational problem, such as for cryptocurrencies and distributed file systems. We observe, however, that this original, peer-centric model has evolved towards deploying several peers at a single network location, thus exposing the same DCS services many times, driven by the fees and rewards that can be gained by doing so. We refer to this trend as the service-centric model and provide in our paper evidence for this trend, its growth, and its impact on DCS operations, using empirical observations in the Ethereum system. Specifically, we shed light on the opposing observations of increasing reliance on highly available cloud infrastructures and large numbers of non-reachability events in the DCS. We provide recommendations on how to tackle this impact through changes to the Ethereum platform and identifier generation, believing that those recommendations and our empirical observations provide useful insights for building resilient and bias-free DePIN platforms.
David Guzman, Dirk Trossen, Trinh Viet Doan, Jörg Ott
ICBC3
2022 DNS privacy with speed?: evaluating DNS over QUIC and its impact on web performance
abstract
Over the last decade, Web traffic has significantly shifted towards HTTPS due to an increased awareness for privacy. However, DNS traffic is still largely unencrypted, which allows user profiles to be derived from plaintext DNS queries. While DNS over TLS (DoT) and DNS over HTTPS (DoH) address this problem by leveraging transport encryption for DNS, both protocols are constrained by the underlying transport (TCP) and encryption (TLS) protocols, requiring multiple round-trips to establish a secure connection. In contrast, QUIC combines the transport and cryptographic handshake into a single round-trip, which allows the recently standardized DNS over QUIC (DoQ) to provide DNS privacy with minimal latency. In the first study of its kind, we perform distributed DoQ measurements across multiple vantage points to evaluate the impact of DoQ on Web performance. We find that DoQ excels over DoH, leading to significant improvements with up to 10% faster loads for simple webpages. With increasing complexity of webpages, DoQ even catches up to DNS over UDP (DoUDP) as the cost of encryption amortizes: With DoQ being only ~2% slower than DoUDP, encrypted DNS becomes much more appealing for the Web.
Mike Kosek, Luca Schumann, Robin Marx, Trinh Viet Doan, Vaibhav Bajpai
IMC4
2022 One to Rule Them All? A First Look at DNS over QUIC
Mike Kosek, Trinh Viet Doan, Malte Granderath, Vaibhav Bajpai
PAM2
2022 An Empirical View on Consolidation of the Web
abstract
The majority of Web content is delivered by only a few companies that provide Content Delivery Infrastructuress (CDIss) such as Content Delivery Networkss (CDNss) and cloud hosts. Due to increasing concerns about trends of centralization, empirical studies on the extent and implications of resulting Internet consolidation are necessary. Thus, we present an empirical view on consolidation of the Web by leveraging datasets from two different measurement platforms. We first analyze Web consolidation around CDIs at the level of landing webpages, before narrowing down the analysis to a level of embedded page resources. The datasets cover 1(a) longitudinal measurements of DNS records for 166.5 M Web domains over five years, 1(b) measurements of DNS records for Alexa Top 1 M over a month and (2) measurements of page loads and renders for 4.3 M webpages, which include data on 392.3 M requested resources. We then define CDIs penetration as the ratio of CDI-hosted objects to all measured objects, which we use to quantify consolidation around CDIs. We observe that CDI penetration has close to doubled since 2015, reaching a lower bound of 15% for all .com , .net , and .org Web domains as of January 2020. Overall, we find a set of six CDIss to deliver the majority of content across all datasets, with these six CDIss being responsible for more than 80% of all 221.9 M CDI-delivered resources (56.6% of all resources in total). We find high dependencies of Web content on a small group of CDIss, in particular, for fonts, ads, and trackers, as well as JavaScript resources such as jQuery. We further observe CDIss to play important roles in rolling out IPv6 and TLS 1.3 support. Overall, these observations indicate a potential oligopoly, which brings both benefits but also risks to the future of the Web.
Trinh Viet Doan, Roland van Rijswijk-Deij, Oliver Hohlfeld, Vaibhav Bajpai
ACM Trans. Internet Techn.1
2021 Evaluating Public DNS Services in the Wake of Increasing Centralization of DNS
abstract
Recent studies have shown centralization in the Domain Name System (DNS) around public DNS services, which are hosted on centrally managed infrastructure and advertise higher reliability, improved security, and faster response times for name resolutions. However, many of the recently emerged public DNS services have not yet been extensively studied regarding popularity and performance. In light of this, we use 10.6k RIPE Atlas probes and find that 28.3% of the probes (and the their host network by extension) use at least one public DNS service, with Google being the most popular public DNS service among these probes. We further quantify the response time benefits of such public DNS services using ≈2.5k RIPE Atlas probes deployed in home networks (1k of which are IPv6 capable): Overall, we provision around 12.7M DNS requests based on a set of 23 domains and ten centralized public DNS services both over IPv4 and IPv6. For comparison, we additionally resolve the same set of domains using the probes' local resolvers, which are typically managed by the ISP and exhibit lower response times in general. We observe that even though IP and AS paths to local resolvers are generally shorter, some public DNS services (e.g., Cloudflare), achieve faster responses over both IPv4 and IPv6. Across all continents, Cloudflare, Google, and OpenDNS exhibit the lowest response times out of all public resolvers for successful DNS measurements. Probes in Europe (EU) and North America (NA) experience comparable latencies to public and local resolvers, thereby diminishing claimed latency benefits of public resolvers. We also observe inflated path lengths to and response times (over both address families) from most public resolvers for probes in Africa (AF) and South America (SA). Based on our observations, we provide recommendations and discuss situations in which switching to public DNS services may be beneficial.
Trinh Viet Doan, Justus Fries, Vaibhav Bajpai
Networking1
2021 Measuring DNS over TLS from the Edge: Adoption, Reliability, and Response Times
Trinh Viet Doan, Irina Tsareva, Vaibhav Bajpai
PAM1
2020 A Longitudinal View of Netflix: Content Delivery over IPv6 and Content Cache Deployments
abstract
We present an active measurement test (netflix) that downloads content from the Netflix content delivery network. The test measures latency and achievable throughput as key performance indicators when downloading the content from Netflix. We deployed the test on ~100 SamKnows probes connected to dual-stacked networks representing 74 different origin ASes. Using a ~2.75 year-long (Jul 2016-Apr 2019) dataset, we observe Netflix Open Connect Appliance (OCA) infrastructure to be highly available, although some vantage points experience low success rates connecting over IPv6. We witness that clients prefer connecting to Netflix OCAs over IPv6, although the preference over IPv6 tends to drop over certain peak hours during the day. The TCP connect times toward the OCAs have reduced by ~40% and the achievable throughput has increased by 20% over the measurement duration. We also provision scamper right after the netflix test to capture the forwarding path toward the Netflix OCAs. We observe that the Netflix OCA caches deployed inside the ISP are reachable within six IP hops and can reduce IP path lengths by 40% over IPv4 and by half over IPv6. Consequently, TCP connect times are reduced by 64% over both address families. The achieved throughput can~ also increase by a factor of three when such ISP caches are used to stream content. This is the first study to measure Netflix content delivery from residential networks, since the inception of the Netflix CDN infrastructure in 2011. To encourage reproducibility of our work, an anonymized version of the entire longitudinal dataset is publicly released.
Trinh Viet Doan, Vaibhav Bajpai, Sam Crawford
INFOCOM1
2020 Measuring Decentralized Video Streaming: A Case Study of DTube
Trinh Viet Doan, Tat Dat Pham, Markus Oberprieler, Vaibhav Bajpai
Networking1