VLDB 2026 Research / reviewers in the wild / expert
Cecilia Testart
dblp:234/7672
· DBLP profile ↗
17ranked-venue papers
2as first author
15since 2021 · last 2025
0000-0002-2993-5059ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 1 first-author · 13 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Replication: A Two Decade Review of Policy Atoms - Tracing the Evolution of AS Path Sharing PrefixesabstractAfek et al. characterized the formation and stability of policy atoms, groups of prefixes that share the same Autonomous System (AS) paths as observed by BGP collectors, a concept initially defined by Broido and Claffy in 2001. Policy atoms provide a valuable perspective on the inter-domain routing policies in the Internet. With the rapid growth and increasing complexity of the Internet since these studies, we believe it is important to reassess the implications and applicability of policy atoms. In this paper, we revisit the policy atom concept after two decades and replicate the study performed by Afek et al. to assess the current state of AS path sharing and shed light on the evolution of policy atoms. We demonstrate that the Internet still operates on the level of policy atoms rather than individual ASes, as prefixes within the same atom tend to experience changes in AS path simultaneously. We apply the concept of policy atoms in IPv6 and find that this observation also holds true for IPv6 prefixes. We also relate trends in the characteristics of policy atoms with the development of inter-domain routing policies. We highlight new insights generated by the perspective of policy atoms and their potential for further applications. Our code is publicly available to support reproducibility and to encourage future research on this topic. Weili Wu 0004, Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
IMC | 3 |
| 2025 | Prefix2Org: Mapping BGP Prefixes to OrganizationsabstractAccurately mapping Internet address space to organizations is critical to understanding the Internet's organizational ecosystem. Traditional approaches, which rely on individual WHOIS queries often suffer from unclear ownership structure of IP addresses and inconsistent organization names, resulting in ambiguous inferences. Alternative methods that map BGP prefixes to Autonomous Systems Numbers (ASNs) and ASNs to organizations are also inaccurate since ASes often originate prefixes on behalf of their customers. This paper introduces Prefix2Org, a comprehensive prefix-to-organization mapping framework. We introduce a taxonomy for the holders of IP addresses and a methodology to map IP addresses to organizations, based on the operational rights over them. We develop string processing heuristics and leverage RPKI Certificates and routing data to address inconsistencies in organizational names and aggregate prefixes under unified management. Our public dataset covers 99.96% (99.99%) of IPv4 (IPv6) prefixes. We validate 9.3% of routed IPv4 addresses with a 99% recall, and 5.6% of IPv6 prefixes with a 99.34% recall. For the two large organizations where we obtained complete ground truth, Prefix2Org produced no false positives. Finally, in two case studies, (i) we characterize organizations that hold address space without an ASN and (ii) demonstrate how RPKI adoption measured through Prefix2Org differs from the previously used AS-centric view. Deepak Gouda, Alberto Dainotti, Cecilia Testart |
IMC | 3 |
| 2025 | ru-RPKI-ready: the Road Left to Full ROA AdoptionabstractResource Public Key Infrastructure (RPKI) has emerged as a standard for enhancing the security of Internet routing. Currently, more than 50% BGP prefixes are covered by RPKI Route Origin Authorizations (ROAs), enabling networks to validate the origin of prefix advertisements in BGP. Despite this progress, ROA adoption remains non-uniform, with key stakeholders encountering significant barriers in the adoption process. In this paper, we combine a product adoption framework with data-driven analysis of global RPKI adoption to identify persistent disparities and pinpoint the stages of the adoption process that hinder broader growth. Our study reveals that, although RPKI awareness has grown, the complexity of planning and deploying ROAs remains a significant challenge. Since no unified workflow and documentation exist for ROA planning, many organizations are left without clear operational guidance. To address this challenge, we propose a systematic framework for ROA planning and introduce ru-RPKI-ready, a platform designed to provide data and insights to facilitate ROA planning. Using ru-RPKI-ready, we characterize the routed address space not covered by RPKI ROAs. We find that 47% IPv4 and 71% IPv6 prefixes not in RPKI could be covered with minimal technical effort. Our analysis also reveals that if as few as ten organizations were to take the necessary actions, the global ROA coverage could increase by 7% for IPv4 and 19% for IPv6. Deepak Gouda, Romain Fontugne, Cecilia Testart |
IMC | 3 |
| 2025 | Poster: Investigating the Survivability of the Experimental TCP OptionabstractIn this work, we extend Yarrpbox to assess the survivability of the TCP experimental option across paths toward the Tranco Top-100k domains. Our findings highlight middlebox interference and motivate broader Internet-wide studies. This study represents an initial step toward understanding the feasibility of extending TCP in today's Internet, while highlighting potential pitfalls that must be considered by future protocol designers. Zahra Yazdani, Fahad Hilal, Cecilia Testart, Alberto Dainotti, Kevin Vermeulen, Tiago Heinrich, Taha Albakour |
IMC | 3 |
| 2024 | Poster: Enhancing Internet Disruption Investigation via Path MonitoringabstractLarge-scale Internet disruptions, ranging from complete disconnections to service degradations, are increasingly common, due to factors such as government-ordered shutdowns, infrastructure failures, and sophisticated traffic manipulation techniques. While existing detection platforms are effective at identifying complete disconnections, they fail to detect service degradations, such as those caused by throttling, intentional rerouting, or network attacks, which degrade performance without blocking connectivity. In this poster, we discuss our plan to improve Internet disruption investigation through additional metrics (loss, latency) and measurement techniques (traceroutes) to help identify such events and provide researchers with the network-level information necessary for investigation. Our method not only helps to identify service degradations missed by traditional connectivity checks but also provides data for generating insights into the underlying causes and impacts of Internet disruptions. Weili Wu 0004, Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
IMC | 3 |
| 2024 | Poster: Investigating Autonomous Systems Recurrently Causing Unexplained (Sub)MOAS EventsabstractThe Border Gateway Protocol (BGP) is the de facto routing protocol of the Internet. In BGP, networks (Autonomous Systems, ASes) advertise to neighboring ASes the IP address blocks (IP prefixes) they host and the ones hosted by other ASes towards which they have a path. Two ASes can announce themselves as the host (origin) of the same IP prefix (Multiple Origin AS prefix, MOAS). Alternatively, one AS can advertise itself as the host of an IP prefix, and another can advertise itself as the host of a subset of that same prefix (SubMOAS prefix). If MOAS and SubMOAS can be legitimate, they can also result in misdirected Internet traffic (BGP hijacking), whether the cause is intentional or not. Thus, network operators need a mechanism to differentiate between unauthorized and legitimate route announcements. The Global Routing Intelligence Platform (GRIP) is state-of-the-art regarding MOAS and SubMOAS detection. GRIP automatically detects SubMOAS and MOAS, then performs initial filtering to tag obvious benign events and reduce the number of cases to investigate. Between January 1, 2020, and January 1, 2023, GRIP detected 4.5M MOAS and SubMOAS, and classified 4.36M as benign, leaving 134k events without explanation. We call them unexplained events. Likely, there are still many benign cases in those 134K events, and only a few should generate an alert. This work aims to uncover AS behaviors that could cause benign MOAS or SubMOAS events but are not currently considered in BGP hijacking detection systems. Upon examining these GRIP events between January 1, 2020, and January 1, 2023, we find that they are primarily caused by a small number of ASes. Therefore, we manually investigate these ASes repeatedly causing MOAS and SubMOAS, leveraging the data collected by GRIP. For example, this data includes the BGP AS path attribute and RPKI status. In addition, we also use RIPE Stat API (routing history and ASN neighbor history), as well as WHOIS data (mainly aut-num/ASNumber and inet-num/NetRange objects). Olivier Bemba, Cecilia Testart, Alberto Dainotti |
IMC | 2 |
| 2024 | Sublet Your Subnet: Inferring IP Leasing in the WildabstractIPv4 addresses have become a commodity with monetary value since the exhaustion of unallocated IPv4 space. This led to the rise of a secondary market for buying, selling, and leasing IPv4 addresses. While prior work has studied the IPv4 transfer behavior, the IPv4 leasing ecosystem remains largely unexplored. In this paper, we analyze the IPv4 leasing ecosystem by designing a methodology to infer leased address space for all RIRs and study its impact on routing and hosting security. We infer that 4.1% of all advertised IPv4 prefixes (0.9% of routed v4 address space) were leased in April 2024. Our method achieves 98% precision when evaluated against our validated dataset. Finally, we show that leased address space is five times more likely to be abused compared to non-leased space. Ben Du, Romain Fontugne, Cecilia Testart, Alex C. Snoeren, K. C. Claffy |
IMC | 3 |
| 2024 | Poster: Diverging Branches - How different are RPKI Trees across RIRs?abstractResource Public Key Infrastructure (RPKI) is a critical component in securing the inter-domain routing infrastructure today. More than 50% of the routed IPv4 and IPv6 prefixes are covered by RPKI Route Origin Authorizations (ROAs). ROAs are cryptographically verifi- able records of the Autonomous System (AS) authorized to originate routes to a set of prefixes. Network operators are increasingly rely- ing on RPKI to validate routing information and reduce the spread of BGP hijacks and misconfigurations. RPKI infrastructure has five root authorities maintained by the five Regional Internet Registries (RIRs). Each root authority independently implements its RPKI in- frastructure, choosing how to manage certificate production from its self-signed root of trust certificate. In this poster, we study the different designs of RPKI infrastructure across the five roots and how these differences impact the characteristics of the RPKI Cer- tificate repository, such as scalability and compute requirements. We discover that some RPKI repositories are computationally more expensive than others due to their design. Deepak Gouda, Cecilia Testart |
IMC | 2 |
| 2024 | Poster: Investigating Network Security Post-Outage: Open Ports VulnerabilitiesabstractThe Internet has become an important part of our lives today, hence ensuring its security and reliability is critical. Internet outages happen frequently due to various factors, including human inter- ventions, natural disasters, and power outages. A key question is whether hosts become vulnerable when a network recovers from an outage impacting Internet infrastructure. This could happen if firewalls malfunction, even for a short while, allowing some ports to become unexpectedly open. This can potentially lead to expo- sure of previously restricted services to external users, making the network vulnerable to security threats. Previous work has shown that, in general, unnecessary open ports can increase vulnerabil- ities in systems. This study proposes a practical approach to examine network security post-outage by identifying newly open ports that can increase system vulnerability. The goal of this work is to show that such risks can indeed arise after an outage and that the proposed methodology detects these new ports. Zahra Yazdani, Paul Pearce, Alberto Dainotti, Cecilia Testart |
IMC | 4 |
| 2023 | IRRegularities in the Internet Routing RegistryabstractThe Internet Routing Registry (IRR) is a set of distributed databases used by networks to register routing policy information and to validate messages received in the Border Gateway Protocol (BGP). First deployed in the 1990s, the IRR remains the most widely used database for routing security purposes, despite the existence of more recent and more secure alternatives. Yet, the IRR lacks a strict validation standard and the limited coordination across different database providers can lead to inaccuracies. Moreover, it has been reported that attackers have begun to register false records in the IRR to bypass operators' defenses when launching attacks on the Internet routing system, such as BGP hijacks. In this paper, we provide a longitudinal analysis of the IRR over the span of 1.5 years. We develop a workflow to identify irregular IRR records that contain conflicting information compared to different routing data sources. We identify 34,199 irregular route objects out of 1,542,724 route objects from November 2021 to May 2023 in the largest IRR database and find 6,373 to be potentially suspicious. Ben Du, Katherine Izhikevich, Sumanth Rao, Gautam Akiwate, Cecilia Testart, Alex C. Snoeren, K. C. Claffy |
IMC | 5 |
| 2023 | Improving the Inference of Sibling Autonomous Systems
Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
PAM | 3 |
| 2023 | Poster: Taking the Low Road: How RPKI Invalids PropagateabstractThe Border Gateway Protocol (BGP) includes no mechanism to verify the correctness of routing information exchanged between networks. To defend against unauthorized use of address space, the IETF developed the Resource Public Key Infrastructure (RPKI), a cryptographically attested database system that facilitates validation of BGP messages. Networks can use RPKI to check whether the Autonomous System (AS) at the origin of the AS path in a BGP announcement is authorized to originate the IP prefixes being announced. Ben Du, Cecilia Testart, Romain Fontugne, Alex C. Snoeren, K. C. Claffy |
SIGCOMM | 2 |
| 2022 | Mind your MANRS: measuring the MANRS ecosystemabstractMutually Agreed Norms on Routing Security (MANRS) is an industry-led initiative to improve Internet routing security by encouraging participating networks to implement a series of mandatory or recommended actions. MANRS members must register their IP prefixes in a trusted routing database and use such information to prevent propagation of invalid routing information. MANRS membership has increased significantly in recent years, but the impact of the MANRS initiative on the overall Internet routing security remains unclear. In this paper, we provide the first independent look into the MANRS ecosystem by using publicly available data to analyze the routing behavior of participant networks. We quantify MANRS participants' level of conformance with the stated requirements, and compare the behavior of MANRS and non-MANRS networks. While not all MANRS members fully comply with all required actions, we find that they are more likely to implement routing security practices described in MANRS actions. We assess the relevance of the MANRS effort in securing the overall routing ecosystem. We found that as of May 2022, over 83% of MANRS networks were conformant to the route filtering requirement by dropping BGP messages with invalid information according to authoritative records, and over 95% were conformant to the routing information facilitation requirement, registering their resources in authoritative databases. Ben Du, Cecilia Testart, Romain Fontugne, Gautam Akiwate, Alex C. Snoeren, K. C. Claffy |
IMC | 2 |
| 2022 | IRR Hygiene in the RPKI Era
Ben Du, Gautam Akiwate, Thomas Krenc, Cecilia Testart, Alexander Marder, Bradley Huffaker, Alex C. Snoeren, K. C. Claffy |
PAM | 4 |
| 2021 | The parallel lives of autonomous systems: ASN allocations vs. BGPabstractAutonomous Systems (ASes) exist in two dimensions on the Internet: the administrative and the operational one. Regional Internet Registries (RIRs) rule the former, while BGP the latter. In this work, we reconstruct the lives of the ASes on both dimensions, performing a joint analysis that covers 17 years of data. For the administrative dimension, we leverage delegation files published by RIRs to report the daily status of Internet resources they allocate. For the operational dimension, we characterize the temporal activity of ASNs in the Internet control plane using BGP data collected by the RouteViews and RIPE RIS projects. We present a methodology to extract insights about AS life cycles, including dealing with pitfalls affecting authoritative public datasets. We then perform a joint analysis to establish the relationship (or lack of) between these two dimensions for all allocated ASNs and all ASNs visible in BGP. We characterize the usual behaviors, specific differences between RIRs and historical resources, as well as measure the discrepancies between the two "parallel" lives. We find discrepancies and misalignment that reveal useful insights, and we highlight through examples the potential of this new lens to help pinpoint malicious BGP activity and various types of misconfigurations. This study illuminates a largely unexplored aspect of the Internet global routing system and provides methods and data to support broader studies that relate to security, policy, and network management. Eugenio Nerio Nemmi, Francesco Sassi, Massimo La Morgia, Cecilia Testart, Alessandro Mei, Alberto Dainotti |
Internet Measurement Conference | 4 |
| 2020 | To Filter or Not to Filter: Measuring the Benefits of Registering in the RPKI Today
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
PAM | 1 |
| 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing TableabstractBGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems. Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
Internet Measurement Conference | 1 |