VLDB 2026 Research / reviewers in the wild / expert
Alan Mislove
dblp:31/3833
· DBLP profile ↗
78ranked-venue papers
8as first author
15since 2021 · last 2025
0000-0002-4824-9302ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 37 · 4 first-author · 5 since 2021Security and privacy · 16 · 5 since 2021Databases, data management, data science and information retrieval · 13 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 10 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 1 first-authorArtificial intelligence and machine learning · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Quantifying the Threat of Sandwiching MEV on Jito: A Measurement of Solana's Leading Validator ClientabstractSolana has emerged as a major blockchain platform providing high throughput and low fees. Like other blockchains, Solana can be attacked via so-called ''Sandwiching'' attacks, where an attacker observes a pending transaction, quickly buys the target cryptocurrency, lets the transaction go through, and then immediately sells it for a profit, skimming that profit from the user who submitted the transaction. While such attacks have been observed by users, they remain underexplored in academic literature due to technical difficulties studying Solana at scale. Nicole Gerzon, Ben Weintraub, Junbeom In, Alan Mislove, Cristina Nita-Rotaru |
IMC | 4 |
| 2024 | What I Learned at the White House, or, the Importance of Measurement Researchers Engaging with PolicyabstractComputing systems now impact almost every aspect of our daily lives. As these systems evolve and develop, they often raise new challenges to our security and privacy, as well as to our commitments to equity and justice. To identify and mitigate the risks that these new technologies present, it is crucial to have scientific and technological experts participate in the conversation. But fully addressing these issues in government-through legislation, regulation, policy development, and executive actions-requires that experts engage with policy and legislative processes, to be ''in the room where it happens.'' In this talk, I'll reflect on my 18 months serving at the White House Office of Science and Technology Policy (OSTP) as Deputy U.S. Chief Technology Officer for Privacy. I'll provide an overview of the Biden-Harris Administration's work on fast-moving technologies such as AI as well as long-standing challenges such as privacy. I'll describe OSTP's role within the Executive Office of the President, and how OSTP works with and across the government to coordinate federal science and technology policy. Finally, I'll discuss the importance of members of computing-and the IMC community in particular-engaging with government. And I'll highlight opportunities to do so, ranging from responding to requests for information, to collaborative research projects, to tours of service and even careers in government. Alan Mislove |
IMC | 1 |
| 2024 | On the Use of Proxies in Political Ad TargetingabstractDetailed targeting of advertisements has long been one of the core offerings of online platforms. Unfortunately, malicious advertisers have frequently abused such targeting features, with results that range from violating civil rights laws to driving division, polarization, and even social unrest. Platforms have often attempted to mitigate this behavior by removing targeting attributes deemed problematic, such as inferred political leaning, religion, or ethnicity. In this work, we examine the effectiveness of these mitigations by collecting data from political ads placed on Facebook in the lead up to the 2022 U.S. midterm elections. We show that major political advertisers circumvented these mitigations by targeting proxy attributes: seemingly innocuous targeting criteria that closely correspond to political and racial divides in American society. We introduce novel methods for directly measuring the skew of various targeting criteria to quantify their effectiveness as proxies, and then examine the scale at which those attributes are used. Our findings have crucial implications for the ongoing discussion on the regulation of political advertising and emphasize the urgency for increased transparency. Piotr Sapiezynski, Levi Kaplan, Alan Mislove, Aleksandra Korolova |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2023 | Problematic Advertising and its Disparate Exposure on Facebook
Muhammad Ali 0014, Angelica Goetzen, Alan Mislove, Elissa M. Redmiles, Piotr Sapiezynski |
USENIX Security Symposium | 3 |
| 2023 | Track You: A Deep Dive into Safety Alerts for Apple AirTagsabstractBluetooth-based item trackers have sparked apprehension over their potential misuse in harmful stalking and privacy violations. In response, manufacturers have implemented safety alerts to notify victims of extended tracking by unknown item trackers. In this study, we specifically investigate the anti-stalking mechanism of Apple's AirTag. We identify and analyze potential triggers of safety alerts that have not been examined in previous research, such as the local time, the victim's device model, AirTag's battery life, and the distance between the AirTag and the victim's device. Furthermore, we demonstrate a novel possibility of developing a stealthy cloned AirTag capable of tracking victims directly on the Find My app while circumventing safety alerts on the victim’s device. Our experiments demonstrate that, despite regular updates to the public key and MAC address, our cloned AirTag can provide real-time location updates even with a four months old key, thereby highlighting the challenges in designing a robust anti-stalking framework. Furthermore, we propose practical solutions to mitigate stalking risks from cloned AirTags and enhance the existing anti-stalking safeguards for AirTags. These suggestions seek to provide a foundation for similar Bluetooth-based item trackers to improve their anti-stalking protections while ensuring optimal tracking efficiency. We conducted rigorous experiments to validate our findings, ensuring their accuracy and reliability. Our evaluation highlights that safety alerts take over 8 hours to appear during the day and are more prompt during the night, particularly after 11 pm. Narmeen Shafqat, Nicole Gerzon, Maggie Van Nortwick, Victor Sun, Alan Mislove, Aanjhan Ranganathan |
Proc. Priv. Enhancing Technol. | 5 |
| 2022 | Algorithms that "Don't See Color": Measuring Biases in Lookalike and Special Ad AudiencesabstractResearchers and journalists have repeatedly shown that algorithms commonly used in domains such as credit, employment, healthcare, or criminal justice can have discriminatory effects. Some organizations have tried to mitigate these effects by simply removing sensitive features from an algorithm's inputs. In this paper, we explore the limits of this approach using a unique opportunity. In 2019, Facebook agreed to settle a lawsuit by removing certain sensitive features from inputs of an algorithm that identifies users similar to those provided by an advertiser for ad targeting, making both the modified and unmodified versions of the algorithm available to advertisers. We develop methodologies to measure biases along the lines of gender, age, and race in the audiences created by this modified algorithm, relative to the unmodified one. Our results provide experimental proof that merely removing demographic features from a real-world algorithmic system's inputs can fail to prevent biased outputs. As a result, organizations using algorithms to help mediate access to important life opportunities should consider other approaches to mitigating discriminatory effects. Piotr Sapiezynski, Avijit Ghosh, Levi Kaplan, Aaron Rieke, Alan Mislove |
AIES | 5 |
| 2022 | Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation PoliciesabstractThis paper proposes using a logic programming language to disentangle X.509 certificate validation policy from mechanism. Expressing validation policies in a logic programming language provides multiple benefits. First, policy and mechanism can be more independently written, augmented, and analyzed compared to the current practice of interweaving them within a C or C++ implementation. Once written, these policies can be easily shared and modified for use in different TLS clients. Further, logic programming allows us to determine when clients differ in their policies and use the power of imputation to automatically generate interesting certificates, e.g., a certificate that will be accepted by one browser but not by another. James Larisch, Waqar Aqeel, Michael Lum, Yaelle Goldschlag, Leah Kannan, Kasra Torshizi, Taejoong Chung, Dave Levin, Bruce M. Maggs, Alan Mislove, Bryan Parno, Christo Wilson |
CCS | 11 |
| 2022 | Measurement and analysis of implied identity in ad delivery optimizationabstractOnline services such as Facebook and Google serve as a popular way by which users today are exposed to products, services, viewpoints, and opportunities. These services implement advertising platforms that enable precise targeting of platform users, and they optimize the delivery of ads to the subset of the targeted users predicted to be most receptive. Unfortunately, recent work has shown that such delivery can---often without the advertisers' knowledge---show ads to biased sets of users based only on the content of the ad. Such concerns are particularly acute for ads that contain pictures of people (e.g., job ads showing workers), as advertisers often select images to carefully convey their goals and values (e.g., to promote diversity in hiring). However, it remains unknown how ad delivery algorithms react to---and make delivery decisions based on---demographic features of people represented in such ad images. Here, we examine how one major advertising platform (Facebook) delivers ads that include pictures of people of varying ages, genders, and races. We develop techniques to isolate the effect of these demographic variables, using a combination of both stock photos and realistic synthetically-generated images of people. We find dramatic skews in who ultimately sees ads solely based on the demographics of the person in the ad. Ads are often delivered disproportionately to users similar to those pictured: images of Black people are shown more to Black users, and the age of the person pictured correlates positively with the age of the users to whom it is shown. But, this is not universal, and more complex effects emerge: older women see more images of children, while images of younger women are shown disproportionately to men aged 55 and older. These findings bring up novel technical, legal, and policy questions and underscore the need to better understand how platforms deliver ads today. Levi Kaplan, Nicole Gerzon, Alan Mislove, Piotr Sapiezynski |
IMC | 3 |
| 2022 | Broadening Participation in Computing via Ubiquitous Combined Majors (CS+X)abstractIn 2001, Khoury College of Computer Sciences at Northeastern University created their first combined majors with Cognitive Psychology, Mathematics and Physics. This type of degree has often been referred to as "CS+X" in the literature and is increasingly relevant as the need for interdisciplinary computer scientists grows. As of 2021, students at Northeastern can choose among three computing majors (Computer Science, Data Science or Cybersecurity) and 42 combined majors, which combine one of the three computing degrees with one of 29 distinct majors in other fields. Prior to 2014, combined majors were with the sciences, business and design. Over the last seven years, we created 29 new combined majors, explicitly creating combinations with fields where there has traditionally been greater gender diversity. The resulting increase in student interest and gender diversity over the last seven years is compelling. As of Fall 2020, 44.6% of the 2,800+ computing majors at Northeastern are pursuing combined majors, 39% of whom are women. This is substantially higher than the 21.5% reported in IPEDS for 2019 women computing graduates in the U.S. We did not observe any significant differences in racial and ethnic diversity between combined and computing only degrees. In this experience paper, we describe how we create and manage combined majors, and we present results on enrollments, admissions, graduation, internship placements, and how students discover combined majors. Carla E. Brodley, Benjamin Hescott, Jessica Biron, Ali Ressing, Melissa Peiken, Sarah Maravetz, Alan Mislove |
SIGCSE (1) | 7 |
| 2021 | Selfish & opaque transaction ordering in the Bitcoin blockchain: the case for chain neutralityabstractMost public blockchain protocols, including the popular Bitcoin and Ethereum blockchains, do not formally specify the order in which miners should select transactions from the pool of pending (or uncommitted) transactions for inclusion in the blockchain. Over the years, informal conventions or "norms" for transaction ordering have, however, emerged via the use of shared software by miners, e.g., the GetBlockTemplate (GBT) mining protocol in Bitcoin Core. Today, a widely held view is that Bitcoin miners prioritize transactions based on their offered "transaction fee-per-byte." Bitcoin users are, consequently, encouraged to increase the fees to accelerate the commitment of their transactions, particularly during periods of congestion. In this paper, we audit the Bitcoin blockchain and present statistically significant evidence of mining pools deviating from the norms to accelerate the commitment of transactions for which they have (i) a selfish or vested interest, or (ii) received dark-fee payments via opaque (non-public) side-channels. As blockchains are increasingly being used as a record-keeping substrate for a variety of decentralized (financial technology) systems, our findings call for an urgent discussion on defining neutrality norms that miners must adhere to when ordering transactions in the chains. Finally, we make our data sets and scripts publicly available. Johnnatan Messias, Mohamed Alzayat, Balakrishnan Chandrasekaran 0002, Krishna P. Gummadi, Patrick Loiseau, Alan Mislove |
Internet Measurement Conference | 6 |
| 2021 | Measurement and Analysis of Automated Certificate Reissuance
Olamide Omolola, Md. Ishtiaq Ashiq, Taejoong Chung, Dave Levin, Alan Mislove |
PAM | 6 |
| 2021 | The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scaleabstractThe couplings between IP addresses, names of content or services, and socket interfaces, are too tight. This impedes system manageability, growth, and overall provisioning. In turn, large-scale content providers are forced to use staggering numbers of addresses, ultimately leading to address exhaustion (IPv4) and inefficiency (IPv6). Marwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola, Marek Majkowski, Pavel Odintsov, Jakub Sitnicki, Taejoong Chung, Dave Levin, Alan Mislove, Christopher A. Wood, Nick Sullivan |
SIGCOMM | 10 |
| 2021 | Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile Apps
Zhichuang Sun, Ruimin Sun, Long Lu, Alan Mislove |
USENIX Security Symposium | 4 |
| 2021 | Ad Delivery Algorithms: The Hidden Arbiters of Political MessagingabstractPolitical campaigns are increasingly turning to targeted advertising platforms to inform and mobilize potential voters. The appeal of these platforms stems from their promise to empower advertisers to select (or "target") users who see their messages with great precision, including through inferences about those users' interests and political affiliations. However, prior work has shown that the targeting may not work as intended, as platforms' ad delivery algorithms play a crucial role in selecting which subgroups of the targeted users see the ads. In particular, the platforms can selectively deliver ads to subgroups within the target audiences selected by advertisers in ways that can lead to demographic skews along race and gender lines, and do so without the advertiser's knowledge. In this work we demonstrate that ad delivery algorithms used by Facebook, the most advanced targeted advertising platform, shape the political ad delivery in ways that may not be beneficial to the political campaigns and to societal discourse. In particular, the ad delivery algorithms lead to political messages on Facebook being shown predominantly to people who Facebook thinks already agree with the ad campaign's message even if the political advertiser targets an ideologically diverse audience. Furthermore, an advertiser determined to reach ideologically non-aligned users is non-transparently charged a high premium compared to their more aligned competitor, a difference from traditional broadcast media. Our results demonstrate that Facebook exercises control over who sees which political messages beyond the control of those who pay for them or those who are exposed to them. Taken together, our findings suggest that the political discourse's increased reliance on profit-optimized, non-transparent algorithmic systems comes at a cost of diversity of political views that voters are exposed to. Thus, the work raises important questions of fairness and accountability desiderata for ad delivery algorithms applied to political ads. Muhammad Ali 0014, Piotr Sapiezynski, Aleksandra Korolova, Alan Mislove, Aaron Rieke |
WSDM | 4 |
| 2021 | Utilizing Web Trackers for Sybil DefenseabstractUser tracking has become ubiquitous practice on the Web, allowing services to recommend behaviorally targeted content to users. In this article, we design Alibi, a system that utilizes such readily available personalized content, generated by recommendation engines in real time, as a means to tame Sybil attacks. In particular, by using ads and other tracker-generated recommendations as implicit user “certificates,” Alibi is capable of creating meta-profiles that allow for rapid and inexpensive validation of users’ uniqueness, thereby enabling an Internet-wide Sybil defense service. We demonstrate the feasibility of such a system, exploring the aggregate behavior of recommendation engines on the Web and demonstrating the richness of the meta-profile space defined by such inputs. We further explore the fundamental properties of such meta-profiles, i.e., their construction, uniqueness, persistence, and resilience to attacks. By conducting a user study, we show that the user meta-profiles are robust and show important scaling effects. We demonstrate that utilizing even a moderate number of popular Web sites empowers Alibi to tame large-scale Sybil attacks. Marcel Flores, Andrew Kahn, Marc Anthony Warrior, Alan Mislove, Aleksandar Kuzmanovic |
ACM Trans. Web | 4 |
| 2020 | On the Potential for Discrimination via CompositionabstractThe success of platforms such as Facebook and Google has been due in no small part to features that allow advertisers to target ads in a fine-grained manner. However, these features open up the potential for discriminatory advertising when advertisers include or exclude users of protected classes---either directly or indirectly---in a discriminatory fashion. Despite the fact that advertisers are able to compose various targeting features together, the existing mitigations to discriminatory targeting have focused only on individual features; there are concerns that such composition could result in targeting that is more discriminatory than the features individually. Giridhari Venkatadri, Alan Mislove |
Internet Measurement Conference | 2 |
| 2019 | You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS CertificatesabstractThe public key infrastructure (PKI) provides the fundamental property of authentication: the means by which users can know with whom they are communicating online. The PKI ensures end-to-end authenticity insofar as it verifies a chain of certificates, but the true final step in end-to-end authentication comes when the user verifies that the website is what they expect. To this end, users are expected to evaluate domain names, but various "domain impersonation" attacks threaten their ability to do so. Indeed, if a user could be easily tricked into believing that amazon.com-offers.com is actually amazon.com, then, coupled with security indicators like a lock icon, users could believe that they have a secure connection to Amazon. Yaelle Goldschlag, Rachel Walter, Taejoong Chung, Alan Mislove, Dave Levin |
CCS | 5 |
| 2019 | RPKI is Coming of Age: A Longitudinal Study of RPKI Deployment and Invalid Route OriginsabstractDespite its critical role in Internet connectivity, the Border Gateway Protocol (BGP) remains highly vulnerable to attacks such as prefix hijacking, where an Autonomous System (AS) announces routes for IP space it does not control. To address this issue, the Resource Public Key Infrastructure (RPKI) was developed starting in 2008, with deployment beginning in 2011. This paper performs the first comprehensive, longitudinal study of the deployment, coverage, and quality of RPKI. We use a unique dataset containing all RPKI Route Origin Authorizations (ROAs) from the moment RPKI was first deployed, more than 8 years ago. We combine this dataset with BGP announcements from more than 3,300 BGP collectors worldwide. Our analysis shows the after a gradual start, RPKI has seen a rapid increase in adoption over the past two years. We also show that although misconfigurations were rampant when RPKI was first deployed (causing many announcements to appear as invalid) they are quite rare today. We develop a taxonomy of invalid RPKI announcements, then quantify their prevalence. We further identify suspicious announcements indicative of prefix hijacking and present case studies of likely hijacks. Overall, we conclude that while misconfigurations still do occur, RPKI is "ready for the big screen," and routing security can be increased by dropping invalid announcements. To foster reproducibility and further studies, we release all RPKI data and the tools we used to analyze it into the public domain. Taejoong Chung, Emile Aben, Tim Bruijnzeels, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Roland van Rijswijk-Deij, John P. Rula, Nick Sullivan |
Internet Measurement Conference | 8 |
| 2019 | Measuring the Facebook Advertising Ecosystem
Athanasios Andreou, Márcio Silva, Fabrício Benevenuto, Oana Goga, Patrick Loiseau, Alan Mislove |
NDSS | 6 |
| 2019 | A large-scale analysis of deployed traffic differentiation practicesabstractNet neutrality has been the subject of considerable public debate over the past decade. Despite the potential impact on content providers and users, there is currently a lack of tools or data for stakeholders to independently audit the net neutrality policies of network providers. In this work, we address this issue by conducting a one-year study of content-based traffic differentiation policies deployed in operational networks, using results from 1,045,413 crowdsourced measurements conducted by 126,249 users across 2,735 ISPs in 183 countries/regions. We develop and evaluate a methodology that combines individual per-device measurements to form high-confidence, statistically significant inferences of differentiation practices, including fixed-rate bandwidth limits (i.e., throttling) and delayed throttling practices. Using this approach, we identify differentiation in both cellular and WiFi networks, comprising 30 ISPs in 7 countries. We also investigate the impact of throttling practices on video streaming resolution for several popular video streaming providers. Fangfan Li, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove |
SIGCOMM | 5 |
| 2019 | Auditing Offline Data Brokers via Facebook's Advertising PlatformabstractData brokers such as Acxiom and Experian are in the business of collecting and selling data on people; the data they sell is commonly used to feed marketing as well as political campaigns. Despite the ongoing privacy debate, there is still very limited visibility into data collection by data brokers. Recently, however, online advertising services such as Facebook have begun to partner with data brokers-to add additional targeting features to their platform- providing avenues to gain insight into data broker information. Giridhari Venkatadri, Piotr Sapiezynski, Elissa M. Redmiles, Alan Mislove, Oana Goga, Michelle L. Mazurek, Krishna P. Gummadi |
WWW | 4 |
| 2019 | Discrimination through Optimization: How Facebook's Ad Delivery Can Lead to Biased OutcomesabstractThe enormous financial success of online advertising platforms is partially due to the precise targeting features they offer. Although researchers and journalists have found many ways that advertisers can target---or exclude---particular groups of users seeing their ads, comparatively little attention has been paid to the implications of the platform's ad delivery process, comprised of the platform's choices about which users see which ads. It has been hypothesized that this process can "skew" ad delivery in ways that the advertisers do not intend, making some users less likely than others to see particular ads based on their demographic characteristics. In this paper, we demonstrate that such skewed delivery occurs on Facebook, due to market and financial optimization effects as well as the platform's own predictions about the "relevance" of ads to different groups of users. We find that both the advertiser's budget and the content of the ad each significantly contribute to the skew of Facebook's ad delivery. Critically, we observe significant skew in delivery along gender and racial lines for "real" ads for employment and housing opportunities despite neutral targeting parameters. Our results demonstrate previously unknown mechanisms that can lead to potentially discriminatory ad delivery, even when advertisers set their targeting parameters to be highly inclusive. This underscores the need for policymakers and platforms to carefully consider the role of the ad delivery optimization run by ad platforms themselves---and not just the targeting choices of advertisers---in preventing discrimination in digital advertising. Muhammad Ali 0014, Piotr Sapiezynski, Miranda Bogen, Aleksandra Korolova, Alan Mislove, Aaron Rieke |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2019 | Investigating sources of PII used in Facebook's targeted advertising
Giridhari Venkatadri, Eli Lucherini, Piotr Sapiezynski, Alan Mislove |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | Rolling With Confidence: Managing the Complexity of DNSSEC OperationsabstractThe domain name system (DNS) is the naming system on the Internet. With the DNS security extensions (DNSSECs) operators can protect the authenticity of their domain using public key cryptography. DNSSEC, however, can be difficult to configure and maintain: operators need to replace keys to upgrade their algorithm, react to security breaches or follow key management policies. These tasks are not trivial. If operators do not time changes to their keys right, caching resolvers may not have access to the correct keys, potentially rendering DNS zones unavailable for minutes or hours. While best current practices give abstract guidelines on how to introduce and withdraw keys, information on how to monitor and control actual rollovers in a live environment is lacking. More specifically, it is challenging for operators to know when to introduce or withdraw keys based on the state of the network. Our main contribution is to help operators answer this question and to address this barrier for deploying DNSSEC. We develop a method with which operators can monitor the replacement of DNSSEC keys, called a rollover. Thereby, they can make confident decisions during the rollover and make sure their zone stays available at all times. We validate the method with an algorithm rollover of the Swedish TLD .se and provide an open source tool with which operators can monitor their rollover themselves. Taejoong Chung, Alan Mislove, Roland van Rijswijk-Deij |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | Treads: Transparency-Enhancing AdsabstractOnline advertising platforms such as those of Facebook and Google collect detailed data about users, which they leverage to allow advertisers to target ads to users based on various pieces of user information. While most advertising platforms have transparency mechanisms in place to reveal this collected information to users, these often present an incomplete view of the information being collected and of how it is used for targeting ads, thus necessitating further transparency. Giridhari Venkatadri, Alan Mislove, Krishna P. Gummadi |
HotNets | 2 |
| 2018 | Is the Web Ready for OCSP Must-Staple?
Taejoong Chung, Jay Lok, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, John P. Rula, Nick Sullivan, Christo Wilson |
Internet Measurement Conference | 7 |
| 2018 | Analyzing Ethereum's Contract Topology
Lucianna Kiffer, Dave Levin, Alan Mislove |
Internet Measurement Conference | 3 |
| 2018 | Investigating Ad Transparency Mechanisms in Social Media: A Case Study of Facebooks Explanations
Athanasios Andreou, Giridhari Venkatadri, Oana Goga, Krishna P. Gummadi, Patrick Loiseau, Alan Mislove |
NDSS | 6 |
| 2018 | Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach
Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove, Cristina Nita-Rotaru |
NDSS | 4 |
| 2018 | Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising InterfaceabstractSites like Facebook and Google now serve as de facto data brokers, aggregating data on users for the purpose of implementing powerful advertising platforms. Historically, these services allowed advertisers to select which users see their ads via targeting attributes. Recently, most advertising platforms have begun allowing advertisers to target users directly by uploading the personal information of the users who they wish to advertise to (e.g., their names, email addresses, phone numbers, etc.); these services are often known as custom audiences. Custom audiences effectively represent powerful linking mechanisms, allowing advertisers to leverage any PII (e.g., from customer data, public records, etc.) to target users. In this paper, we focus on Facebook's custom audience implementation and demonstrate attacks that allow an adversary to exploit the interface to infer users' PII as well as to infer their activity. Specifically, we show how the adversary can infer users' full phone numbers knowing just their email address, determine whether a particular user visited a website, and de-anonymize all the visitors to a website by inferring their phone numbers en masse. These attacks can be conducted without any interaction with the victim(s), cannot be detected by the victim(s), and do not require the adversary to spend money or actually place an ad. We propose a simple and effective fix to the attacks based on reworking the way Facebook de-duplicates uploaded information. Facebook's security team acknowledged the vulnerability and has put into place a fix that is a variant of the fix we propose. Overall, our results indicate that advertising platforms need to carefully consider the privacy implications of their interfaces. Giridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove, Krishna P. Gummadi, Patrick Loiseau, Oana Goga |
IEEE Symposium on Security and Privacy | 4 |
| 2018 | On Ridesharing Competition and Accessibility: Evidence from Uber, Lyft, and TaxiabstractRidesharing services such as Uber and Lyft have become an important part of the Vehicle For Hire (VFH) market, which used to be dominated by taxis. Unfortunately, ridesharing services are not required to share data like taxi services, which has made it challenging to compare the competitive dynamics of these services, or assess their impact on cities. In this paper, we comprehensively compare Uber, Lyft, and taxis with respect to key market features (supply, demand, price, and wait time) in San Francisco and New York City. Based on point pattern statistics, we develop novel statistical techniques to validate our measurement methods. Using spatial lag models, we investigate the accessibility of VFH services, and find that transportation infrastructure and socio-economic features have substantial effects on VFH market features. Shan Jiang 0008, Alan Mislove, Christo Wilson |
WWW | 3 |
| 2017 | Bias in Online Freelance Marketplaces: Evidence from TaskRabbit and FiverrabstractOnline freelancing marketplaces have grown quickly in recent years. In theory, these sites offer workers the ability to earn money without the obligations and potential social biases associated with traditional employment frameworks. In this paper, we study whether two prominent online freelance marketplaces - TaskRabbit and Fiverr - are impacted by racial and gender bias. From these two platforms, we collect 13,500 worker profiles and gather information about workers' gender, race, customer reviews, ratings, and positions in search rankings. In both marketplaces, we find evidence of bias: we find that gender and race are significantly correlated with worker evaluations, which could harm the employment opportunities afforded to the workers. We hope that our study fuels more research on the presence and implications of discrimination in online environments. Aniko Hannak, Claudia Wagner 0001, David García 0001, Alan Mislove, Markus Strohmaier, Christo Wilson |
CSCW | 4 |
| 2017 | Using millions of emoji occurrences to learn any-domain representations for detecting sentiment, emotion and sarcasmabstractNLP tasks are often limited by scarcity of manually annotated data. In social media sentiment analysis and related tasks, researchers have therefore used binarized emoticons and specific hashtags as forms of distant supervision. Our paper shows that by extending the distant supervision to a more diverse set of noisy labels, the models can learn richer representations. Through emoji prediction on a dataset of 1246 million tweets containing one of 64 common emojis we obtain state-of-the-art performance on 8 benchmark datasets within sentiment, emotion and sarcasm detection using a single pretrained model. Our analyses confirm that the diversity of our emotional labels yield a performance improvement over previous distant supervision approaches. Bjarke Felbo, Alan Mislove, Anders Søgaard, Iyad Rahwan, Sune Lehmann |
EMNLP | 2 |
| 2017 | Stick a fork in it: Analyzing the Ethereum network partitionabstractAs blockchain technologies and cryptocurrencies increase in popularity, their decentralization poses unique challenges in network partitions. In traditional distributed systems, network partitions are generally a result of bugs or connectivity failures; the typical goal of the system designer is to automatically recover from such issues as seamlessly as possible. Blockchain-based systems, however, rely on purposeful "forks" to roll out protocol changes in a decentralized manner. Not all users may agree with proposed changes, and thus forks can persist, leading to permanent network partitions. In this paper, we closely study the large-scale fork that occurred in Ethereum, a new blockchain technology that allows for both currency transactions and smart contracts. Ethereum is currently the second-most-valuable cryptocurrency, with a market capitalization of over $28B. We explore the consequences of this fork, showing the impact on the two networks and their mining pools, and how the fork lead to unintentional incentives and security vulnerabilities. Lucianna Kiffer, Dave Levin, Alan Mislove |
HotNets | 3 |
| 2017 | Understanding the role of registrars in DNSSEC deploymentabstractThe Domain Name System (DNS) provides a scalable, flexible name resolution service. Unfortunately, its unauthenticated architecture has become the basis for many security attacks. To address this, DNS Security Extensions (DNSSEC) were introduced in 1997. DNSSEC's deployment requires support from the top-level domain (TLD) registries and registrars, as well as participation by the organization that serves as the DNS operator. Unfortunately, DNSSEC has seen poor deployment thus far: despite being proposed nearly two decades ago, only 1% of .com, .net, and .org domains are properly signed. Taejoong Chung, Roland van Rijswijk-Deij, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson |
Internet Measurement Conference | 6 |
| 2017 | Taking a long look at QUIC: an approach for rigorous evaluation of rapidly evolving transport protocolsabstractGoogle's QUIC protocol, which implements TCP-like properties at the application layer atop a UDP transport, is now used by the vast majority of Chrome clients accessing Google properties but has no formal state machine specification, limited analysis, and ad-hoc evaluations based on snapshots of the protocol implementation in a small number of environments. Further frustrating attempts to evaluate QUIC is the fact that the protocol is under rapid development, with extensive rewriting of the protocol occurring over the scale of months, making individual studies of the protocol obsolete before publication. Arash Molavi Kakhki, Samuel Jero, David R. Choffnes, Cristina Nita-Rotaru, Alan Mislove |
Internet Measurement Conference | 5 |
| 2017 | lib•erate, (n): a library for exposing (traffic-classification) rules and avoiding them efficientlyabstractMiddleboxes implement a variety of network management policies (e.g., prioritizing or blocking traffic) in their networks. While such policies can be beneficial (e.g., blocking malware) they also raise issues of network neutrality and freedom of speech when used for application-specific differentiation and censorship. There is a poor understanding of how such policies are implemented in practice, and how they can be evaded efficiently. As a result, most circumvention solutions are brittle, point solutions based on manual analysis. Fangfan Li, Abbas Razaghpanah, Arash Molavi Kakhki, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove |
Internet Measurement Conference | 7 |
| 2017 | CRLite: A Scalable System for Pushing All TLS Revocations to All BrowsersabstractCurrently, no major browser fully checks for TLS/SSL certificate revocations. This is largely due to the fact that the deployed mechanisms for disseminating revocations (CRLs, OCSP, OCSP Stapling, CRLSet, and OneCRL) are each either incomplete, insecure, inefficient, slow to update, not private, or some combination thereof. In this paper, we present CRLite, an efficient and easily-deployable system for proactively pushing all TLS certificate revocations to browsers. CRLite servers aggregate revocation information for all known, valid TLS certificates on the web, and store them in a space-efficient filter cascade data structure. Browsers periodically download and use this data to check for revocations of observed certificates in real-time. CRLite does not require any additional trust beyond the existing PKI, and it allows clients to adopt a fail-closed security posture even in the face of network errors or attacks that make revocation information temporarily unavailable. We present a prototype of name that processes TLS certificates gathered by Rapid7, the University of Michigan, and Google's Certificate Transparency on the server-side, with a Firefox extension on the client-side. Comparing CRLite to an idealized browser that performs correct CRL/OCSP checking, we show that CRLite reduces latency and eliminates privacy concerns. Moreover, CRLite has low bandwidth costs: it can represent all certificates with an initial download of 10 MB (less than 1 byte per revocation) followed by daily updates of 580 KB on average. Taken together, our results demonstrate that complete TLS/SSL revocation checking is within reach for all clients. James Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson |
IEEE Symposium on Security and Privacy | 5 |
| 2017 | A Longitudinal, End-to-End View of the DNSSEC Ecosystem
Taejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson |
USENIX Security Symposium | 7 |
| 2016 | Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemabstractThe semantics of online authentication in the web are rather straightforward: if Alice has a certificate binding Bob's name to a public key, and if a remote entity can prove knowledge of Bob's private key, then (barring key compromise) that remote entity must be Bob. However, in reality, many websites' and the majority of the most popular ones-are hosted at least in part by third parties such as Content Delivery Networks (CDNs) or web hosting providers. Put simply: administrators of websites who deal with (extremely) sensitive user data are giving their private keys to third parties. Importantly, this sharing of keys is undetectable by most users, and widely unknown even among researchers. In this paper, we perform a large-scale measurement study of key sharing in today's web. We analyze the prevalence with which websites trust third-party hosting providers with their secret keys, as well as the impact that this trust has on responsible key management practices, such as revocation. Our results reveal that key sharing is extremely common, with a small handful of hosting providers having keys from the majority of the most popular websites. We also find that hosting providers often manage their customers' keys, and that they tend to react more slowly yet more thoroughly to compromised or potentially compromised keys. Frank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson |
CCS | 6 |
| 2016 | Picocenter: supporting long-lived, mostly-idle applications in cloud environmentsabstractCloud computing has evolved to meet user demands, from arbitrary VMs offered by IaaS to the narrow application interfaces of PaaS. Unfortunately, there exists an intermediate point that is not well met by today's offerings: users who wish to run arbitrary, already available binaries (as opposed to rewriting their own application for a PaaS) yet expect their applications to be long-lived but mostly idle (as opposed to the always-on VM of IaaS). For example, end users who wish to run their own email or DNS server. Liang Zhang 0022, James Litton, Frank Cangialosi, Theophilus Benson, Dave Levin, Alan Mislove |
EuroSys | 6 |
| 2016 | Tunneling for Transparency: A Large-Scale Analysis of End-to-End Violations in the Internet
Taejoong Chung, David R. Choffnes, Alan Mislove |
Internet Measurement Conference | 3 |
| 2016 | Measuring and Applying Invalid SSL Certificates: The Silent Majority
Taejoong Chung, Yabing Liu, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson |
Internet Measurement Conference | 6 |
| 2016 | Classifiers Unclassified: An Efficient Approach to Revealing IP Traffic Classification Rules
Fangfan Li, Arash Molavi Kakhki, David R. Choffnes, Phillipa Gill, Alan Mislove |
Internet Measurement Conference | 5 |
| 2016 | An Empirical Analysis of Algorithmic Pricing on Amazon MarketplaceabstractThe rise of e-commerce has unlocked practical applications for algorithmic pricing (also called dynamic pricing algorithms), where sellers set prices using computer algorithms. Travel websites and large, well known e-retailers have already adopted algorithmic pricing strategies, but the tools and techniques are now available to small-scale sellers as well. Alan Mislove, Christo Wilson |
WWW | 2 |
| 2015 | Peeking Beneath the Hood of UberabstractRecently, Uber has emerged as a leader in the "sharing economy". Uber is a "ride sharing" service that matches willing drivers with customers looking for rides. However, unlike other open marketplaces (e.g., AirBnB), Uber is a black-box: they do not provide data about supply or demand, and prices are set dynamically by an opaque "surge pricing" algorithm. The lack of transparency has led to concerns about whether Uber artificially manipulate prices, and whether dynamic prices are fair to customers and drivers. In order to understand the impact of surge pricing on passengers and drivers, we present the first in-depth investigation of Uber. We gathered four weeks of data from Uber by emulating 43 copies of the Uber smartphone app and distributing them throughout downtown San Francisco (SF) and midtown Manhattan. Using our dataset, we are able to characterize the dynamics of Uber in SF and Manhattan, as well as identify key implementation details of Uber's surge price algorithm. Our observations about Uber's surge price algorithm raise important questions about the fairness and transparency of this system. Alan Mislove, Christo Wilson |
Internet Measurement Conference | 2 |
| 2015 | Identifying Traffic Differentiation in Mobile NetworksabstractTraffic differentiation---giving better (or worse) performance to certain classes of Internet traffic---is a well-known but poorly understood traffic management policy. There is active discussion on whether and how ISPs should be allowed to differentiate Internet traffic, but little data about current practices to inform this discussion. Previous work attempted to address this problem for fixed line networks; however, there is currently no solution that works in the more challenging mobile environment. Arash Molavi Kakhki, Abbas Razaghpanah, Anke Li, Hyungjoon Koo, Rajesh Golani, David R. Choffnes, Phillipa Gill, Alan Mislove |
Internet Measurement Conference | 8 |
| 2015 | Location, Location, Location: The Impact of Geolocation on Web Search PersonalizationabstractTo cope with the immense amount of content on the web, search engines often use complex algorithms to personalize search results for individual users. However, personalization of search results has led to worries about the Filter Bubble Effect, where the personalization algorithm decides that some useful information is irrelevant to the user, and thus prevents them from locating it. In this paper, we propose a novel methodology to explore the impact of location-based personalization on Google Search results. Assessing the relationship between location and personalization is crucial, since users' geolocation can be used as a proxy for other demographic traits, like race, income, educational attainment, and political affiliation. In other words, does location-based personalization trap users in geolocal Filter Bubbles? Chloe Kliman-Silver, Aniko Hannak, David Lazer, Christo Wilson, Alan Mislove |
Internet Measurement Conference | 5 |
| 2015 | An End-to-End Measurement of Certificate Revocation in the Web's PKIabstractCritical to the security of any public key infrastructure (PKI) is the ability to revoke previously issued certificates. While the overall SSL ecosystem is well-studied, the frequency with which certificates are revoked and the circumstances under which clients (e.g., browsers) check whether certificates are revoked are still not well-understood. Yabing Liu, Will Tome, Liang Zhang 0022, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Aaron Schulman, Christo Wilson |
Internet Measurement Conference | 7 |
| 2015 | Opportunities and Challenges in Crowdsourced WardrivingabstractKnowing the physical location of a mobile device is crucial for a number of context-aware applications. This information is usually obtained using the Global Positioning System (GPS), or by calculating the position based on proximity of WiFi access points with known location (where the position of the access points is stored in a database at a central server). To date, most of the research regarding the creation of such a database has investigated datasets collected both artificially and over short periods of time (e.g., during a one-day drive around a city). In contrast, most in-use databases are collected by mobile devices automatically, and are maintained by large mobile OS providers. Piotr Sapiezynski, Radu Gatej, Alan Mislove, Sune Lehmann |
Internet Measurement Conference | 3 |
| 2014 | The Tweets They Are a-Changin: Evolution of Twitter Users and Behavior
Yabing Liu, Chloe Kliman-Silver, Alan Mislove |
ICWSM | 3 |
| 2014 | Of Pins and Tweets: Investigating How Users Behave Across Image- and Text-Based Social Networks
Raphael Ottoni, Diego B. Las Casas, João Paulo Pesce, Wagner Meira Jr., Christo Wilson, Alan Mislove, Virgílio A. F. Almeida |
ICWSM | 6 |
| 2014 | Measuring Price Discrimination and Steering on E-commerce Web SitesabstractToday, many e-commerce websites personalize their content, including Netflix (movie recommendations), Amazon (product suggestions), and Yelp (business reviews). In many cases, personalization provides advantages for users: for example, when a user searches for an ambiguous query such as ``router,'' Amazon may be able to suggest the woodworking tool instead of the networking device. However, personalization on e-commerce sites may also be used to the user's disadvantage by manipulating the products shown (price steering) or by customizing the prices of products (price discrimination). Unfortunately, today, we lack the tools and techniques necessary to be able to detect such behavior. Aniko Hannak, Gary Soeller, David Lazer, Alan Mislove, Christo Wilson |
Internet Measurement Conference | 4 |
| 2014 | Analysis of SSL certificate reissues and revocations in the wake of heartbleedabstractCentral to the secure operation of a public key infrastructure (PKI) is the ability to revoke certificates. While much of users' security rests on this process taking place quickly, in practice, revocation typically requires a human to decide to reissue a new certificate and revoke the old one. Thus, having a proper understanding of how often systems administrators reissue and revoke certificates is crucial to understanding the integrity of a PKI. Unfortunately, this is typically difficult to measure: while it is relatively easy to determine when a certificate is revoked, it is difficult to determine whether and when an administrator should have revoked. Liang Zhang 0022, David R. Choffnes, Dave Levin, Tudor Dumitras, Alan Mislove, Aaron Schulman, Christo Wilson |
Internet Measurement Conference | 5 |
| 2014 | Identifying traffic differentiation on cellular data networksabstractThe goal of this research is to detect traffic differentiation in cellular data networks. We define service differentiation as any attempt to change the performance of network traffic traversing an ISP's boundaries. ISPs may implement differentiation policies for a number of reasons, including load balancing, bandwidth management, or business reasons. Specifically, we focus on detecting whether certain types of network traffic receive better (or worse) performance. As an example, a wireless provider might limit the performance of third-party VoIP or video calling services (or any other competing services) by introducing delays or reducing transfer rates to encourage users to use services provided by the wireless provider. Previous work explored this problem in limited environments. Glasnost focused on BitTorrent in the desktop/laptop environment, and lacked the ability to conduct controlled experiments to provide strong evidence of differentiation. NetDiff covered a wide range of passively gathered traffic from a large ISP but likewise did not support targeted, controlled experiments. We address these limitations with Mobile Replay. Arash Molavi Kakhki, Abbas Razaghpanah, Rajesh Golani, David R. Choffnes, Phillipa Gill, Alan Mislove |
SIGCOMM | 6 |
| 2014 | Understanding and Specifying Social Access Control Lists
Mainack Mondal, Yabing Liu, Bimal Viswanath, Krishna P. Gummadi, Alan Mislove |
SOUPS | 5 |
| 2014 | Towards Detecting Anomalous User Behavior in Online Social Networks
Bimal Viswanath, Muhammad Ahmad Bashir, Mark Crovella, Saikat Guha 0002, Krishna P. Gummadi, Balachander Krishnamurthy, Alan Mislove |
USENIX Security Symposium | 7 |
| 2013 | Maygh: building a CDN from client web browsersabstractOver the past two decades, the web has provided dramatic improvements in the ease of sharing content. Unfortunately, the costs of distributing this content are largely incurred by web site operators; popular web sites are required to make substantial monetary investments in serving infrastructure or cloud computing resources---or must pay other organizations (e.g., content distribution networks)---to help serve content. Previous approaches to offloading some of the distribution costs onto end users have relied on client-side software or web browser plug-ins, providing poor user incentives and dramatically limiting their scope in practice. Liang Zhang 0022, Fangfei Zhou, Alan Mislove, Ravi Sundaram |
EuroSys | 3 |
| 2013 | Measuring personalization of web searchabstractWeb search is an integral part of our daily lives. Recently, there has been a trend of personalization in Web search, where different users receive different results for the same search query. The increasing personalization is leading to concerns about Filter Bubble effects, where certain users are simply unable to access information that the search engines' algorithm decides is irrelevant. Despite these concerns, there has been little quantification of the extent of personalization in Web search today, or the user attributes that cause it. Aniko Hannak, Piotr Sapiezynski, Arash Molavi Kakhki, Balachander Krishnamurthy, David Lazer, Alan Mislove, Christo Wilson |
WWW | 6 |
| 2013 | Iolaus: securing online content rating systemsabstractOnline content ratings services allow users to find and share content ranging from news articles (Digg) to videos (YouTube) to businesses (Yelp). Generally, these sites allow users to create accounts, declare friendships, upload and rate content, and locate new content by leveraging the aggregated ratings of others. These services are becoming increasingly popular; Yelp alone has over 33 million reviews. Unfortunately, this popularity is leading to increasing levels of malicious activity, including multiple identity (Sybil) attacks and the "buying" of ratings from users. Arash Molavi Kakhki, Chloe Kliman-Silver, Alan Mislove |
WWW | 3 |
| 2012 | Defending against large-scale crawls in online social networksabstractThwarting large-scale crawls of user profiles in online social networks (OSNs) like Facebook and Renren is in the interest of both the users and the operators of these sites. OSN users wish to maintain control over their personal information, and OSN operators wish to protect their business assets and reputation. Existing rate-limiting techniques are ineffective against crawlers with many accounts, be they fake accounts (also known as Sybils) or compromised accounts of real users obtained on the black market. Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post |
CoNEXT | 6 |
| 2012 | Canal: scaling social network-based Sybil tolerance schemesabstractThere has been a flurry of research on leveraging social networks to defend against multiple identity, or Sybil, attacks. A series of recent works does not try to explicitly identify Sybil identities and, instead, bounds the impact that Sybil identities can have. We call these approaches Sybil tolerance; they have shown to be effective in applications including reputation systems, spam protection, online auctions, and content rating systems. All of these approaches use a social network as a credit network, rendering multiple identities ineffective to an attacker without a commensurate increase in social links to honest users (which are assumed to be hard to obtain). Unfortunately, a hurdle to practical adoption is that Sybil tolerance relies on computationally expensive network analysis, thereby limiting widespread deployment. Bimal Viswanath, Mainack Mondal, Krishna P. Gummadi, Alan Mislove, Ansley Post |
EuroSys | 4 |
| 2012 | Tweetin' in the Rain: Exploring Societal-Scale Effects of Weather on Mood
Aniko Hannak, Eric Anderson 0001, Lisa Feldman Barrett, Sune Lehmann, Alan Mislove, Mirek Riedewald |
ICWSM | 5 |
| 2012 | WebCloud: Recruiting Social Network Users to Assist in Content DistributionabstractToday, the data exchanged over online social networks (OSNs) represents a significant fraction of Internet traffic. However, OSN content is different from more traditional web content, as it is more likely to be generated at the edge of the network, to be exchanged within a local geographic region, and to possess a more even popularity distribution with fewer popular objects. Unfortunately, most OSNs still use largely centralized approaches to distribute content (e.g., CDNs and web caches), resulting in lower performance due to the different workload. In this paper, we take a first step towards addressing this situation by proposing Web Cloud, a content distribution system for OSNs that works by repurposing client web browsers to help serve content to others. When a user browses content, Web Cloud tries to serve the request from one of that user's friends' browsers, instead of from the OSN directly. Unlike other systems, Web Cloud works with existing browsers and does not require any plug-ins, and therefore can be directly applied to today's OSNs. We demonstrate the practicality of Web Cloud with micro benchmarks, simulations of a Facebook deployment, a real-world deployment, and evaluations of a proof-of-concept iOS app. Fangfei Zhou, Liang Zhang 0022, Eric Franco, Alan Mislove, Richard Revis, Ravi Sundaram |
NCA | 4 |
| 2011 | Understanding the Demographics of Twitter Users
Alan Mislove, Sune Lehmann, Yong-Yeol Ahn, Jukka-Pekka Onnela, J. Niels Rosenquist |
ICWSM | 1 |
| 2011 | Analyzing facebook privacy settings: user expectations vs. realityabstractThe sharing of personal data has emerged as a popular activity over online social networking sites like Facebook. As a result, the issue of online social network privacy has received significant attention in both the research literature and the mainstream media. Our overarching goal is to improve defaults and provide better tools for managing privacy, but we are limited by the fact that the full extent of the privacy problem remains unknown; there is little quantification of the incidence of incorrect privacy settings or the difficulty users face when managing their privacy. Yabing Liu, Krishna P. Gummadi, Balachander Krishnamurthy, Alan Mislove |
Internet Measurement Conference | 4 |
| 2011 | Bazaar: Strengthening User Reputations in Online Marketplaces
Ansley Post, Vijit Shah, Alan Mislove |
NSDI | 3 |
| 2011 | Limiting large-scale crawls of social networking sitesabstractOnline social networking sites (OSNs) like Facebook and Orkut contain personal data of millions of users. Many OSNs view this data as a valuable asset that is at the core of their business model. Both OSN users and OSNs have strong incentives to restrict large scale crawls of this data. OSN users want to protect their privacy and OSNs their business interest. Traditional defenses against crawlers involve rate- limiting browsing activity per user account. These defense schemes, however, are vulnerable to Sybil attacks, where a crawler creates a large number of fake user accounts. In this paper, we propose Genie, a system that can be deployed by OSN operators to defend against Sybil crawlers. Genie is based on a simple yet powerful insight: the social network itself can be leveraged to defend against Sybil crawlers. We first present Genie's design and then discuss how Genie can limit crawlers while allowing browsing of user profiles by normal users. Mainack Mondal, Bimal Viswanath, Allen Clement, Peter Druschel, Krishna P. Gummadi, Alan Mislove, Ansley Post |
SIGCOMM | 6 |
| 2010 | An analysis of social network-based Sybil defensesabstractRecently, there has been much excitement in the research community over using social networks to mitigate multiple identity, or Sybil, attacks. A number of schemes have been proposed, but they differ greatly in the algorithms they use and in the networks upon which they are evaluated. As a result, the research community lacks a clear understanding of how these schemes compare against each other, how well they would work on real-world social networks with different structural properties, or whether there exist other (potentially better) ways of Sybil defense. Bimal Viswanath, Ansley Post, Krishna P. Gummadi, Alan Mislove |
SIGCOMM | 4 |
| 2010 | You are who you know: inferring user profiles in online social networksabstractOnline social networks are now a popular way for users to connect, express themselves, and share content. Users in today's online social networks often post a profile, consisting of attributes like geographic location, interests, and schools attended. Such profile information is used on the sites as a basis for grouping users, for sharing content, and for suggesting users who may benefit from interaction. However, in practice, not all users provide these attributes. Alan Mislove, Bimal Viswanath, Krishna P. Gummadi, Peter Druschel |
WSDM | 1 |
| 2009 | A measurement-driven analysis of information propagation in the flickr social networkabstractOnline social networking sites like MySpace, Facebook, and Flickr have become a popular way to share and disseminate content. Their massive popularity has led to viral marketing techniques that attempt to spread content, products, and ideas on these sites. However, there is little data publicly available on viral propagation in the real world and few studies have characterized how information spreads over current online social networks. Meeyoung Cha, Alan Mislove, Krishna P. Gummadi |
WWW | 2 |
| 2008 | Detecting bittorrent blockingabstractRecently, it has been reported that certain access ISPs are surreptitiously blocking their customers from uploading data using the popular BitTorrent file-sharing protocol. The reports have sparked an intense and wide-ranging policy debate on network neutrality and ISP traffic management practices. However, to date, end users lack access to measurement tools that can detect whether their access ISPs are blocking their BitTorrent traffic. And since ISPs do not voluntarily disclose their traffic management policies, no one knows how widely BitTorrent traffic blocking is deployed in the current Internet. In this paper, we address this problem by designing an easy-to-use tool to detect BitTorrent blocking and by presenting results from a widely used public deployment of the tool. Marcel Dischinger, Alan Mislove, Andreas Haeberlen, Krishna P. Gummadi |
Internet Measurement Conference | 2 |
| 2008 | Ostra: Leveraging Trust to Thwart Unwanted Communication
Alan Mislove, Ansley Post, Peter Druschel, Krishna P. Gummadi |
NSDI | 1 |
| 2007 | Measurement and analysis of online social networksabstractOnline social networking sites like Orkut, YouTube, and Flickr are among the most popular sites on the Internet. Users of these sites form a social network, which provides a powerful means of sharing, organizing, and finding content and contacts. The popularity of these sites provides an opportunity to study the characteristics of online social network graphs at large scale. Understanding these graphs is important, both to improve current systems and to design new applications of online social networks. Alan Mislove, Massimiliano Marcon, Krishna P. Gummadi, Peter Druschel, Bobby Bhattacharjee |
Internet Measurement Conference | 1 |
| 2006 | Experiences in building and operating ePOST, a reliable peer-to-peer applicationabstractPeer-to-peer (p2p) technology can potentially be used to build highly reliable applications without a single point of failure. However, most of the existing applications, such as file sharing or web caching, have only moderate reliability demands. Without a challenging proving ground, it remains unclear whether the full potential of p2p systems can be realized.To provide such a proving ground, we have designed, deployed and operated a p2p-based email system. We chose email because users depend on it for their daily work and therefore place high demands on the availability and reliability of the service, as well as the durability, integrity, authenticity and privacy of their email. Our system, ePOST, has been actively used by a small group of participants for over two years.In this paper, we report the problems and pitfalls we encountered in this process. We were able to address some of them by applying known principles of system design, while others turned out to be novel and fundamental, requiring us to devise new solutions. Our findings can be used to guide the design of future reliable p2p systems and provide interesting new directions for future research. Alan Mislove, Ansley Post, Andreas Haeberlen, Peter Druschel |
EuroSys | 1 |
| 2006 | Exploiting Social Networks for Internet Search
Alan Mislove, Krishna P. Gummadi, Peter Druschel |
HotNets | 1 |
| 2005 | Glacier: Highly Durable, Decentralized Storage Despite Massive Correlated Failures
Andreas Haeberlen, Alan Mislove, Peter Druschel |
NSDI | 2 |
| 2003 | POST: A Secure, Resilient, Cooperative Messaging System
Alan Mislove, Ansley Post, Charles Reis, Paul Willmann, Peter Druschel, Dan S. Wallach, Xavier Bonnaire, Pierre Sens 0001, Jean-Michel Busca, Luciana Arantes |
HotOS | 1 |