VLDB 2026 Research / reviewers in the wild / expert
Tiago Heinrich
dblp:288/7661
· DBLP profile ↗
13ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0002-8017-1293ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 2 first-author · 7 since 2021Security and privacy · 5 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lessons from an (Unsuccessful?) IPv6 Amplification Honeypot DeploymentabstractWhile DRDoS attacks are well-understood in IPv4, it is not known to what extend attackers also make use of services on the IPv6 Internet to perform DRDoS attacks.In this work, we adapted an IPv4-only DRDoS honeypot to observe DRDoS attacks in IPv6.To attract scanners, we publicized our honeypots' addresses on the TUM IPv6 Hitlist.After one year of data collection, however, we observed little to no attackers exploiting IPv6 UDP services for DRDoS attacks.This paper presents our setup, findings, and the lessons learned from trying attract scanners to our DRDoS honeypot: we analyze the interactions we observed over time as well as the source addresses of scanners, and discuss how our choice of the IPv6 Hitlist as an address exposure method possibly impacted our findings.Although we managed to attract several scanners also observed by previous work, our results show that there are currently no attackers performing DRDoS attacks in IPv6, at least among these that rely on the IPv6 Hitlist to discover vulnerable hots. Tiago Heinrich, Sebastian Kappes, Rafael R. Obelheiro |
SIGCOMM | 1 |
| 2025 | Poster: Investigating the Survivability of the Experimental TCP OptionabstractIn this work, we extend Yarrpbox to assess the survivability of the TCP experimental option across paths toward the Tranco Top-100k domains. Our findings highlight middlebox interference and motivate broader Internet-wide studies. This study represents an initial step toward understanding the feasibility of extending TCP in today's Internet, while highlighting potential pitfalls that must be considered by future protocol designers. Zahra Yazdani, Fahad Hilal, Cecilia Testart, Alberto Dainotti, Kevin Vermeulen, Tiago Heinrich, Taha Albakour |
IMC | 6 |
| 2025 | How Risky Is It? A Closer Look at Game Anti-Cheat SoftwareabstractAnti-cheat software is a system designed to detect cheats (or hacks) in a video game. This paper investigates operations executed by anti-cheat software and their impact on user privacy. We collected data and analyzed three popular anticheat solutions: BattlEye, FACEIT, and Vanguard. Our analysis reveals that these programs interact with system files, memory, and users’ directories. In addition, the privileged access of these anti-cheat solutions to the operating system and the lack of clarity on what data is collected directly affect user privacy. This conduct risks not complying with current regulations. Amanda B. Viescinski, Tiago Heinrich, Vinicius Fulber-Garcia, Carlos Maziero |
ISCC | 2 |
| 2025 | Measuring Increasing Heterogeneity in BGPabstractAutonomous Systems (ASes) on the Internet use the Border Gateway Protocol (BGP) to distribute routing information. The BGP-a policy-based protocol-defines a best path decision process that chooses one path per prefix. Some researchers assume ASes use the same path for the same prefix, i.e., that ASes are homogeneous networks. However, this is not the case. Previous work has shown the existence of heterogeneous ASes, i.e., ASes that use different best paths for the same prefix. Nevertheless, this work is outdated due to the Internet's fast pace of evolution. Our work thus aims to quantize the number of heterogeneous ASes by improving upon previous limitations. We introduce a novel method to find heterogeneous ASes that works by finding detours in AS paths from different vantage points. Our analysis covers samples from the last 10 years to show the historical growth and ongoing adoption of heterogeneity on the Internet. We found that the number of heterogeneous ASes steadily increased over the last decade. For example, there has been an increase of up to 173% since 2014. Further, especially Content Delivery Networks have become more heterogeneous (an increase of 360%), followed by Internet Service Providers (196%), and Network Service Providers (173%). Lastly, we found that smaller ASes with fewer customers are becoming more prone to being heterogeneous. Pascal Hennen, Tiago Heinrich, Johannes Zirngibl |
NOMS | 2 |
| 2024 | Anywhere on Earth: A Look at Regional Characteristics of DRDoS Attacks
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 1 |
| 2024 | A Categorical Data Approach for Anomaly Detection in WebAssembly Applications
Tiago Heinrich, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ICISSP | 1 |
| 2024 | Poster: An Investigation into Internet-facing Router ServicesabstractRouters are the core building block of the Internet infrastructure. Maintaining a secure router deployment is critical for protecting networks and providing uninterrupted, smooth operation. In this work, we take a first step toward analyzing routers' security on the Internet. We focus on the potential attack surface for routers, i.e., publicly exposed services. Specifically, we investigate what services are commonly running on known router IPv4 addresses. While exposed services may not pose an immediate risk, they do highlight failure to follow best practices, e.g., strict access control lists. We found that more than 40% of known router IPv4 addresses have at least one public-facing service. We also highlight the lack of consistency in applying network-wide security policies. Sina Rostami, Tiago Heinrich, Taha Albakour |
IMC | 2 |
| 2024 | I See Syscalls by the Seashore: An Anomaly-based IDS for Containers Leveraging Sysdig DataabstractIntrusion detection in virtualized environments is vital due to the widespread adoption of virtualization technology. A common strategy for achieving this task involves collecting data from the virtual environment and providing it to intrusion detection solutions. However, these solutions can be affected by other elements present in the virtual environment. An approach that has gained prominence is applying machine learning (ML) models to perform anomaly-based intrusion detection based on system call traces. In Linux-based environments, many tools can be used for collecting the system calls issued by processes and containers; two of the most popular are strace and sysdig. This paper introduces a dataset of system call traces collected with sysdig with a focus on anomaly-based intrusion detection for containerized applications and uses this dataset to compare the effectiveness of strace and sysdig data and evaluate the performance of five different ML models for anomaly detection. The results reveal that sysdig is an attractive option, enabling the collection of system call traces with lower overhead than strace while achieving good detection performance with several ML models. Anderson Aparecido do Carmo Frasão, Tiago Heinrich, Vinicius Fulber-Garcia, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
ISCC | 2 |
| 2024 | The Use of the DWARF Debugging Format for the Identification of Potentially Unwanted Applications (PUAs) in WebAssembly Binaries
Calebe Helpa, Tiago Heinrich, Marcus Botacin, Newton Carlos Will, Rafael R. Obelheiro, Carlos Maziero |
SECRYPT | 2 |
| 2022 | How DRDoS attacks vary across the globe?abstractIn this study we characterize Distributed Reflection Denial of Service (DRDoS) attack traffic taking into consideration the geographical distribution of victims. This type of characterization is not widely explored in the literature and could help to better understand this type of attack. We aim to explore this gap in the literature using data collected by four honeypots over three and a half years. Our findings highlight attack similarities and differences across continents. Tiago Heinrich, Carlos Maziero, Newton Carlos Will, Rafael R. Obelheiro |
IMC | 1 |
| 2022 | Behavior Modeling of a Distributed Application for Anomaly Detection
Amanda B. Viescinski, Tiago Heinrich, Newton Carlos Will, Carlos Maziero |
SECRYPT | 2 |
| 2021 | Taking a Peek: An Evaluation of Anomaly Detection Using System calls for ContainersabstractThe growth in the use of virtualization in the last ten years has contributed to the improvement of this technology. The practice of implementing and managing this type of isolated environment raises doubts about the security of such systems. Considering the host's proximity to a container, approaches that use anomaly detection systems attempt to monitor and detect unexpected behavior. Our work aims to use system calls to identify threats within a container environment, using machine learning based strategies to distinguish between expected and unexpected behaviors (possible threats). Gabriel R. Castanhel, Tiago Heinrich, Fabricio Ceschin, Carlos Maziero |
ISCC | 2 |
| 2021 | New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks
Tiago Heinrich, Rafael R. Obelheiro, Carlos Maziero |
PAM | 1 |