Jeroen van der Ham

dblp:30/4433 · also Jeroen van der Ham-de Vos · DBLP profile ↗
← Back
20ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-5685-8714ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 3 first-authorComputer networks · 4 · 1 first-authorSecurity and privacy · 4 · 4 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 SoK: Understanding the state of IoT-specific vulnerabilities via CVE characterization with LLIoT
abstract
Following the expansion of IoT systems, spanning from devices to cloud backends, reported IoT CVE vulnerabilities have increased at an alarming pace. Since most IoT attacks exploit known vulnerabilities, understanding known vulnerabilities is vital for defense and security research. In this work, we systematize the prior research on studying IoT vulnerabilities, revealing the absence of consistent IoT definitions, reliable and scalable classification methodologies, and high-quality IoT CVE datasets. To overcome these limitations, we design LLIoT, a novel and LLM-assisted approach that systematically and automatically distinguishes IoT-specific CVEs at large scale, enabling in-depth under-standing of IoT vulnerabilities. First, leveraging the systematization knowledge from the literature, we derive a four-layer IoT ecosystem taxonomy and define classification criteria for distinguishing IoT CVEs. Then, using an expert-validated ground-truth dataset, we demonstrate that LLMs can reliably distinguish IoT from non-IoT CVEs with a high accuracy of 95%, outperforming humans by avoiding cognitive errors and gaps in domain knowledge. Applying LLIoT to CVEs from 2013-2024, we build a dataset of 15,116 IoT-specific vulnerabilities, of which 8,368 are newly classified with respect to previous datasets. Using this dataset, which we share with the research community for further research and reproducibility, we characterize how IoT vulnerabilities differ from traditional IT vulnerabilities. Upon our observation, we provide actionable recommendations for responsible stakeholders.
Tina Rezaei, Suzan Bayhan, Andrea Continella, Jeroen van der Ham, Roland van Rijswijk-Deij
EuroS&P4
2025 90th Minute: A First Look to Collateral Damages and Efficacy of the Italian Piracy Shield
abstract
In the fight against illegal football streaming, Italy introduced Piracy Shield, a platform through which copyright holders can notify the national regulator (AGCOM), which in turn orders ISPs to block infringing resources -- such as IP addresses and Fully Qualified Domain Names (FQDNs) -- within 30 minutes. In this paper, we present the first investigation into the platform's real-world impact by reconstructing and analyzing its blocking activity. Our analysis shows that the platform causes significant collateral damage. Indiscriminate IP-level blocking has disrupted and continues to disrupt hundreds of legitimate, non-streaming websites. At the same time, the platform's effectiveness may have been undermined by streamers who evaded enforcement by migrating to new infrastructure and unfiltered IP address space. Based on these findings, we call on Italian authorities and policymakers to critically reconsider the platform's core blocking principles. The evidence suggests that its broad impact on legitimate services and the potential national security risks outweigh its intended benefits.
Raffaele Sommese, Anna Sperotto, Antonio Prado, Jeroen van der Ham, Antonia Affinito
CNSM4
2024 A First Look at User-Installed Residential Proxies From a Network Operator's Perspective
abstract
Residential proxies (RESIP) enable the tunneling of traffic through non-data center Internet connections. Previous research has focused on malicious software on end-user devices that made them part of RESIP networks. This study investigates RESIP networks that users voluntarily join in exchange for monetary rewards, aiming to understand the activities facilitated through these services. We developed a testbed environment to operate and monitor eight different residential proxy applications over 7.5 months, enabling us to collect and analyze 368 GB of proxied network traffic, the majority of which is encrypted.In this work, we highlight three distinct case studies that suggest these proxies are used in practices not advertised by the RESIP providers and in one case, shed light on the scale of the proxied campaigns. Firstly, we discuss the use of RESIPs on two dating apps, Tinder and happn, highlighting their likely role in facilitating fraudulent activities. Secondly, an analysis of metadata suggests that RESIPs may play a crucial part in phishing campaigns. Thirdly, a collaboration with a leading technology company in the travel industry allows us to analyze the behavior of web scrapers.Our results underscore the need for enhanced detection mechanisms to mitigate fraud and protect users.
Etienne Khan, Elisa Chiapponi, Martijn Verkleij, Anna Sperotto, Roland van Rijswijk-Deij, Jeroen van der Ham
CNSM6
2023 Stranger VPNs: Investigating the Geo-Unblocking Capabilities of Commercial VPN Providers
Etienne Khan, Anna Sperotto, Jeroen van der Ham, Roland van Rijswijk-Deij
PAM3
2023 No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability Information
abstract
The number of published software vulnerabilities is increasing every year. How do organizations stay in control of their attack surface despite their limited staff resources? Prior work has analyzed the overall software vulnerability ecosystem as well as patching processes within organizations, but not how these two are connected.We investigate this missing link through semi-structured interviews with 22 organizations in critical infrastructure and government services. We analyze where in these organizations the responsibility is allocated to collect and triage information about software vulnerabilities, and find that none of our respondents is acquiring such information comprehensively, not even in a reduced and aggregated form like the National Vulnerability Database (NVD). This means that information on known vulnerabilities will be missed, even in critical infrastructure organizations. We observe that organizations apply implicit and explicit coping mechanisms to reduce their intake of vulnerability information, and identify three trade-offs in these strategies: independence, pro-activeness and formalization.Although our respondents’ behavior is in conflict with the widely accepted security advice to collect comprehensive vulnerability information about active systems, no respondents recall having experienced a security incident that was associated with missing information on a known software vulnerability. This suggests that, given scarce resources, reducing the intake of vulnerability information by up to 95% can be considered a rational strategy. Our findings raise questions about the allocation of responsibility and accountability for finding vulnerable systems, as well as suggest changing expectations around collecting vulnerability information.
Stephanie de Smale, Rik van Dijk, Xander Bouwman, Jeroen van der Ham, Michel van Eeten
SP4
2022 Assessing e-Government DNS Resilience
abstract
Electronic government (e-gov) enables citizens and residents to digitally interact with their government via the Internet. Underpinning these services is the Internet Domain Name Systems (DNS), which maps e-gov domain names to Internet addresses. Structuring DNS with multiple levels of redundancy that can withstand stress events such as denial-of-service (DoS) attacks is a challenging task. While the operator community has established best practices to this end, adopting them all involves expert knowledge and resources. In this work, we obtain and study a list of e-gov domain names used by four countries (The Netherlands, Sweden, Switzerland, and the United States) and measure the DNS structuring of these domains. We show the adoption of best practices, inter-country differences such as the use of anycast, and provide recommendations to improve DNS service robustness.
Raffaele Sommese, Mattijs Jonker, Jeroen van der Ham, Giovane Cesar Moreira Moura
CNSM3
2022 Mirrors in the Sky: On the Potential of Clouds in DNS Reflection-based Denial-of-Service Attacks
abstract
Clouds are likely to be well-provisioned in terms of network capacity by design. The rapid growth of cloud-based services means an increased availability of network infrastructure for all types of customers. However, it could also provide attackers opportunity to misuse cloud infrastructure to bring about attacks, or to target the cloud infrastructure itself.
Ramin Yazdani, Alden Hilton, Jeroen van der Ham, Roland van Rijswijk-Deij, Casey T. Deccio, Anna Sperotto, Mattijs Jonker
RAID3
2017 Model-driven software engineering in practice: privacy-enhanced filtering of network traffic
abstract
Network traffic data contains a wealth of information for use in security analysis and application development. Unfortunately, it also usually contains confidential or otherwise sensitive information, prohibiting sharing and analysis. Existing automated anonymization solutions are hard to maintain and tend to be outdated.
Roel van Dijk, Christophe Creeten, Jeroen van der Ham, Jeroen van den Bos
ESEC/SIGSOFT FSE3
2015 Technology-aware multi-domain multi-layer routing
Farabi Muhammad Iqbal, Jeroen van der Ham, Fernando A. Kuipers
Comput. Commun.2
2015 The NOVI information models
Jeroen van der Ham, József Stéger, Sándor Laki, Yiannos Kryftis, Basil S. Maglaris, Cees T. A. M. de Laat
Future Gener. Comput. Syst.1
2015 Resource discovery and allocation for federated virtualized infrastructures
Chariklis Pittaras, Chrysa Papagianni, Aris Leivadeas, Paola Grosso, Jeroen van der Ham, Symeon Papavassiliou
Future Gener. Comput. Syst.5
2013 Open Cloud eXchange (OCX): Architecture and Functional Components
abstract
This paper presents the concept of Open Cloud eXchange (OCX) that has been proposed to bridge the gap between two major components of the cloud services provisioning infrastructure: Cloud Service Provider (CSP) infrastructure, and cloud services delivery infrastructure which in many cases requires dedicated local infrastructure and quality of services that cannot be delivered by the public Internet infrastructure. In both cases there is a need for interconnecting the CSP infrastructure and local access network infrastructure, in particular, to solve the "last mile" problem in delivering cloud services to customer locations and individual (end-)users. The OCX remains neutral to actual cloud services provisioning and limit its services to Layer 0 through Layer 2 to remain transparent to current cloud services model. The proposed document identifies the initial set of requirements to OCX, that can be run by NRENs, as a part of the G&201;ANT network, or jointly, and provides suggestions about OCX implementation. The proposed OCX concept will leverage the existing Internet eXchange (IX) and GLIF Open Light path Exchange (GOLE) solutions and practices, adding specific functionality that will simplify inter-CSP and customer infrastructure integration when supporting basic cloud services provisioning models, in particular Trusted Third Party (TTP) services to allow federated infrastructure and access control, commonly used by NRENs. The paper also describes trusted/secured topology exchange protocol and dynamic trust establishment protocol as a part of the OCX services.
Yuri Demchenko, Jeroen van der Ham, Canh Ngo, Taras Matselyukh, Sonja Filiposka, Cees T. A. M. de Laat, Eduard Escalona
CloudCom (2)2
2012 Towards an Infrastructure Description Language for Modeling Computing Infrastructures
abstract
This paper describes the Infrastructure and Network Description Language (INDL). The aim of INDL is to provide technology independent descriptions of computing infrastructures. These descriptions include the physical resources and the network infrastructure that connects these resources. The description language also provides the necessary vocabulary to describe virtualization of resources and the services offered by these resources. Furthermore, the language can be easily extended to describe federation of different existing computing infrastructures, specific types of (optical) equipment and also behavioral aspects of resources, for example, their energy consumption. Before we introduce INDL we first discuss a number of modeling efforts that have lead to the development of INDL, namely the Network Description Language, the Network Markup Language and the CineGrid Description Language. We also show current applications of INDL in two EU-FP7 projects: NOVI and GEYSERS. We demonstrate the flexibility and extensibility of INDL to cater the specific needs of these two projects.
Mattijs Ghijsen, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
ISPA2
2011 Managing federations of virtualized infrastructures: A semantic-aware policy based approach
abstract
This paper presents our work toward organizing and managing various forms of federations of virtualized infrastructures. We adopt the Ponder2 policy framework and the SMC architecture as a powerful engineering approach, which we apply to semantic-aware management of federations of Future Internet (FI) virtualized infrastructures. To cater for context-awareness, we plan for a common information model, based on the Network Description Language (NDL), capturing a common set of abstractions of virtualized resources and services, nodes, routers and switches, custom network topologies with specific bandwidth demands, etc. To handle management of generic complex federated environments, we employ structural patterns to model federations as graphs, whose vertices represent SMCs and edges denote the type of relationship between them. We give an illustration of such structures corresponding to existing FI experimental platforms in the US and Europe and we provide examples containing inter-domain management responsibilities as missions. Finally, we propose to augment the Ponder2 framework with single & multi-domain resource provisioning capabilities, enabling efficient sharing of virtualized networked facilities among federation users.
Leonidas Lymberopoulos, Paola Grosso, Chrysa Papagianni, Dimitrios Kalogeras, Georgios Androulidakis, Jeroen van der Ham, Cees T. A. M. de Laat, Basil S. Maglaris
Integrated Network Management6
2009 A path finding implementation for multi-layer networks
Freek Dijkstra, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
Future Gener. Comput. Syst.2
2008 A multi-layer network model based on ITU-T G.805
Freek Dijkstra, Bert Andree, Karst Koymans, Jeroen van der Ham, Paola Grosso, Cees T. A. M. de Laat
Comput. Networks4
2007 Using the Network Description Language in Optical Networks
abstract
Current research networks allow end users to build their own application-specific connections (lightpaths) and optical private networks (OPNs). This requires a clear communication between the requesting application and the network. The network description language (NDL) is a vocabulary designed to describe optical networks based on the resource description framework (RDF). These descriptions aid applications in querying the capabilities of the network and allow them to clearly express requests to the network. This article introduces NDL and shows its current applications in optical research networks.
Jeroen van der Ham, Paola Grosso, Ronald van der Pol, Andree Toonk, Cees T. A. M. de Laat
Integrated Network Management1
2006 Poster reception - Semantics for hybrid networks using the network description language
abstract
Several research networks around the world are implementing hybrid networks, that provide end-users with traditional routed IP together with lightpaths. These paths are dynamically configured at user request and network provisioning systems must have topology information, both intra- and inter-domain.We developed the Network Description Language (NDL), based on RDF, a semantic web technique. This language can be used to describe hybrid networks, so that different administrative domains can share and correlate topology information. It supports the end-user to express a lightpath reservation request, and helps the service provider to validate the feasibility of requests. It facilitates generation and exchange of network maps by allowing automatic correlation of information across domains.Our first application ground is GLIF, a collaboration promoting co-operation for Lambda Networking. Several tools for automatic provisioning are in development. However, these tools lack a common network description, which NDL can provide.
Jeroen van der Ham, Paola Grosso, Freek Dijkstra, Cees T. A. M. de Laat
SC1
2006 Using zero configuration technology for IP addressing in optical networks
Freek Dijkstra, Jeroen van der Ham, Cees T. A. M. de Laat
Future Gener. Comput. Syst.2
2006 Using RDF to describe networks
Jeroen van der Ham, Freek Dijkstra, Franco Travostino, Hubertus M. A. Andree, Cees T. A. M. de Laat
Future Gener. Comput. Syst.1