VLDB 2026 Research / reviewers in the wild / expert
Md. Ishtiaq Ashiq
dblp:260/9262
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0001-8282-6225ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Unraveling the Complexities of MTA-STS Deployment and Management in Securing EmailabstractEmail has been a cornerstone of online communication for decades, but its lack of built-in confidentiality has left it vulnerable to various attacks. To address this issue, two key protocols are being used: MTA-STS (Mail Transfer Agent Strict Transport Security) and DANE (DNS-based Authentication of Named Entities). While DANE was introduced first, MTA-STS has been actively adopted by major email providers like Google and Microsoft, as it does not require the complex DNSSEC chain that poses a significant challenge in deploying and managing DANE. However, despite its significance, there has been limited research on how MTA-STS is deployed and managed in practice. In this study, we present a thorough, longitudinal investigation of the MTA-STS ecosystem. We base our analysis on a dataset capturing over 87 million domains from DNS scans collected across four TLDs over 31 months, along with 10 months of additional component scanning such as TLS certificates, thereby offering a broad perspective on MTA-STS adoption and its management. Our analysis uncovers a concerning trend of misconfigurations and inconsistencies in MTA-STS setups. In our most recent snapshot, out of ~68K domains with MTA-STS record, 29.6% of domains were incorrectly configured, while 3.2% of these should encounter email delivery failure from MTA-STS supporting senders. To gain insights into the challenges faced by email administrators, we surveyed 117 operators. While awareness of MTA-STS was high (94.7%), many cited operational complexity (48.8%) and a preference for DANE (45.4%) as reasons for not deploying the protocol. Our study not only highlights the growing importance of MTA-STS but also reveals the significant challenges in its deployment and management. Md. Ishtiaq Ashiq, Tobias Fiebig, Taejoong Chung |
IMC | 1 |
| 2025 | Decoding DNSSEC Errors at Scale: An Automated DNSSEC Error Resolution Framework using Insights from DNSViz LogsabstractLow adoption and high misconfiguration rates continue to blunt the security benefits of DNSSEC. Drawing on 1.1M historical diagnostic snapshots covering 319K second-level and their subdomains between 2020 and 2024 from the DNSViz service, this paper delivers the first longitudinal, data-driven taxonomy of real-world DNSSEC failures. The study shows that NSEC3 misconfigurations, delegation failures and missing/expired signatures account for more than 70% of all bogus states, and that 18% of such domains remain broken. Md. Ishtiaq Ashiq, Olivier Hureau, Casey T. Deccio, Taejoong Chung |
IMC | 1 |
| 2024 | SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical Recommendations
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung |
USENIX Security Symposium | 1 |
| 2023 | RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKIabstractThe Resource Public Key Infrastructure (RPKI) is a system to add security to the Internet routing. In recent years, the publication of Route Origin Authorization (ROA) objects, which bind IP prefixes to their legitimate origin ASN, has been rapidly increasing. However, ROAs are effective only if the routers use them to verify and filter invalid BGP announcements, a process called Route Origin Validation (ROV). Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, Taejoong Chung |
IMC | 3 |
| 2023 | TTL Violation of DNS Resolvers in the Wild
Protick Bhowmick, Md. Ishtiaq Ashiq, Casey T. Deccio, Taejoong Chung |
PAM | 2 |
| 2023 | You've Got Report: Measurement and Security Implications of DMARC Reporting
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung |
USENIX Security Symposium | 1 |
| 2022 | Under the Hood of DANE Mismanagement in SMTP
Hyeonmin Lee, Md. Ishtiaq Ashiq, Roland van Rijswijk-Deij, Ted Taekyoung Kwon, Taejoong Chung |
USENIX Security Symposium | 2 |
| 2021 | Measurement and Analysis of Automated Certificate Reissuance
Olamide Omolola, Md. Ishtiaq Ashiq, Taejoong Chung, Dave Levin, Alan Mislove |
PAM | 3 |