VLDB 2026 Research / reviewers in the wild / expert
Gerry Wan
dblp:248/0261
· DBLP profile ↗
6ranked-venue papers
4as first author
4since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 3 first-author · 4 since 2021Security and privacy · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Iris: Expressive Traffic Analysis for the Modern Internet
Thea Rossman, Diana Qing, Gerry Wan, Zakir Durumeric |
NSDI | 3 |
| 2025 | Efficient Multi-WAN Transport for 5G with OTTER
Mary Hogan, Gerry Wan, Yiming Qiu 0001, Sharad Agarwal, Ryan Beckett, Rachee Singh, Paramvir Bahl |
NSDI | 2 |
| 2025 | CATO: End-to-End Optimization of ML-Based Traffic Analysis Pipelines
Gerry Wan, Shinan Liu, Francesco Bronzino, Nick Feamster, Zakir Durumeric |
NSDI | 1 |
| 2022 | Retina: analyzing 100GbE traffic on commodity hardwareabstractAs network speeds have increased to over 100 Gbps, operators and researchers have lost the ability to easily ask complex questions of reassembled and parsed network traffic. In this paper, we introduce Retina, a software framework that lets users analyze over 100 Gbps of real-world traffic on a single server with no specialized hardware. Retina supports running arbitrary user-defined analysis functions on a wide variety of extensible data representations ranging from raw packets to parsed application-layer handshakes. We introduce a novel filtering mechanism and subscription interface to safely and efficiently process high-speed traffic. Under the hood, Retina implements an efficient data pipeline that strategically discards unneeded traffic and defers expensive processing operations to preserve computation for complex analyses. We present the framework architecture, evaluate its performance on production traffic, and explore several applications. Our experiments show that Retina is capable of running sophisticated analyses at over 100 Gbps on a single commodity server and can support 5--100× higher traffic rates than existing solutions, dramatically reducing the effort to complete investigations on real-world networks. Gerry Wan, Fengchen Gong, Tom Barbette, Zakir Durumeric |
SIGCOMM | 1 |
| 2020 | On the Origin of Scanning: The Impact of Location on Internet-Wide ScansabstractFast IPv4 scanning has enabled researchers to answer a wealth of security and networking questions. Yet, despite widespread use, there has been little validation of the methodology's accuracy, including whether a single scan provides sufficient coverage. In this paper, we analyze how scan origin affects the results of Internet-wide scans by completing three HTTP, HTTPS, and SSH scans from seven geographically and topologically diverse networks. We find that individual origins miss an average 1.6-8.4% of HTTP, 1.5-4.6% of HTTPS, and 8.3-18.2% of SSH hosts. We analyze why origins see different hosts, and show how permanent and temporary blocking, packet loss, geographic biases, and transient outages affect scan results. We discuss the implications for scanning and provide recommendations for future studies. Gerry Wan, Liz Izhikevich, David Adrian, Katsunari Yoshioka, Ralph Holz, Christian Rossow, Zakir Durumeric |
Internet Measurement Conference | 1 |
| 2019 | Guard Placement Attacks on Path Selection Algorithms for TorabstractAbstract The popularity of Tor has made it an attractive target for a variety of deanonymization and fingerprinting attacks. Location-based path selection algorithms have been proposed as a countermeasure to defend against such attacks. However, adversaries can exploit the location-awareness of these algorithms by strategically placing relays in locations that increase their chances of being selected as a client’s guard. Being chosen as a guard facilitates website fingerprinting and traffic correlation attacks over extended time periods. In this work, we rigorously define and analyze the guard placement attack. We present novel guard placement attacks and show that three state-of-the-art path selection algorithms—Counter-RAPTOR, DeNASA, and LASTor—are vulnerable to these attacks, overcoming defenses considered by all three systems. For instance, in one attack, we show that an adversary contributing only 0.216% of Tor’s total bandwidth can attain an average selection probability of 18.22%, 84× higher than what it would be under Tor currently. Our findings indicate that existing location-based path selection algorithms allow guards to achieve disproportionately high selection probabilities relative to the cost required to run the guard. Finally, we propose and evaluate a generic defense mechanism that provably defends any path selection algorithm against guard placement attacks. We run our defense mechanism on each of the three path selection algorithms, and find that our mechanism significantly enhances the security of these algorithms against guard placement attacks with only minimal impact to the goals or performance of the original algorithms. Gerry Wan, Aaron Johnson 0001, Ryan Wails, Sameer Wagh, Prateek Mittal |
Proc. Priv. Enhancing Technol. | 1 |