Taha Albakour

dblp:303/0974 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0009-5924-6471ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 5 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Unpacking Internet Ossification: A Large-Scale Study of Path-Impairing Middleboxes Across IPv4 and IPv6
Fahad Hilal, Taha Albakour, Oliver Gasser, Kevin Vermeulen
PAM2
2025 Poster: Investigating the Survivability of the Experimental TCP Option
abstract
In this work, we extend Yarrpbox to assess the survivability of the TCP experimental option across paths toward the Tranco Top-100k domains. Our findings highlight middlebox interference and motivate broader Internet-wide studies. This study represents an initial step toward understanding the feasibility of extending TCP in today's Internet, while highlighting potential pitfalls that must be considered by future protocol designers.
Zahra Yazdani, Fahad Hilal, Cecilia Testart, Alberto Dainotti, Kevin Vermeulen, Tiago Heinrich, Taha Albakour
IMC7
2024 Poster: An Investigation into Internet-facing Router Services
abstract
Routers are the core building block of the Internet infrastructure. Maintaining a secure router deployment is critical for protecting networks and providing uninterrupted, smooth operation. In this work, we take a first step toward analyzing routers' security on the Internet. We focus on the potential attack surface for routers, i.e., publicly exposed services. Specifically, we investigate what services are commonly running on known router IPv4 addresses. While exposed services may not pose an immediate risk, they do highlight failure to follow best practices, e.g., strict access control lists. We found that more than 40% of known router IPv4 addresses have at least one public-facing service. We also highlight the lack of consistency in applying network-wide security policies.
Sina Rostami, Tiago Heinrich, Taha Albakour
IMC3
2023 Illuminating Router Vendor Diversity Within Providers and Along Network Paths
abstract
The Internet architecture has facilitated a multi-party, distributed, and heterogeneous physical infrastructure where routers from different vendors connect and inter-operate via IP. Such vendor heterogeneity can have important security and policy implications. For example, a security vulnerability may be specific to a particular vendor and implementation, and thus will have a disproportionate impact on particular networks and paths if exploited. From a policy perspective, governments are now explicitly banning particular vendors-or have threatened to do so.
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
IMC1
2023 Pushing Alias Resolution to the Limit
abstract
In this paper, we show that utilizing multiple protocols offers a unique opportunity to improve IP alias resolution and dual-stack inference substantially. Our key observation is that prevalent protocols, e.g., SSH and BGP, reply to unsolicited requests with a set of values that can be combined to form a unique device identifier. More importantly, this is possible by just completing the TCP hand-shake. Our empirical study shows that utilizing readily available scans and our active measurements can double the discovered IPv4 alias sets and more than 30× the dual-stack sets compared to the state-of-the-art techniques. We provide insights into our method's accuracy and performance compared to popular techniques.
Taha Albakour, Oliver Gasser, Georgios Smaragdakis
IMC1
2021 Third time's not a charm: exploiting SNMPv3 for router fingerprinting
abstract
In this paper, we show that adoption of the SNMPv3 network management protocol standard offers a unique---but likely unintended---opportunity for remotely fingerprinting network infrastructure in the wild. Specifically, by sending unsolicited and unauthenticated SNMPv3 requests, we obtain detailed information about the configuration and status of network devices including vendor, uptime, and the number of restarts. More importantly, the reply contains a persistent and strong identifier that allows for lightweight Internet-scale alias resolution and dual-stack association. By launching active Internet-wide SNMPv3 scan campaigns, we show that our technique can fingerprint more than 4.6 million devices of which around 350k are network routers. Not only is our technique lightweight and accurate, it is complementary to existing alias resolution, dual-stack inference, and device fingerprinting approaches. Our analysis not only provides fresh insights into the router deployment strategies of network operators worldwide, but also highlights potential vulnerabilities of SNMPv3 as currently deployed.
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
Internet Measurement Conference1