VLDB 2026 Research / reviewers in the wild / expert
Michael D. Bailey
dblp:359/0958 · also Michael Donald Bailey
· DBLP profile ↗
58ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-0250-9164ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 36 · 2 first-author · 5 since 2021Computer networks · 17 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3Databases, data management, data science and information retrieval · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti, Michael D. Bailey, Fabian Monrose |
NDSS | 5 |
| 2025 | The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Michael D. Bailey, Fabian Monrose |
NDSS | 4 |
| 2023 | Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS KeysabstractCertificate authorities enable TLS server authentication by generating certificates that attest to the mapping between a domain name and a cryptographic keypair, for up to 398 days. This static, name-to-key caching mechanism belies a complex reality: a tangle of dynamic infrastructure involving domains, servers, cryptographic keys, etc. When any of these operations changes, the authentication information in a certificate becomes stale and no longer accurately reflects reality. In this work, we examine the broader phenomenon of certificate invalidation events and discover three classes of security-relevant events that enable a third-party to impersonate a domain outside of their control. Longitudinal measurement of these precarious scenarios reveals that they affect over 15K new domains per day, on average. Unfortunately, modern certificate revocation provides little recourse, so we examine the potential impact of reducing certificate lifetimes (cache duration): shortening the current 398-day limit to 90 days yields a 75% decrease in precarious access to valid TLS keys. Zane Ma, Aaron Faulkenberry, Thomas Papastergiou, Zakir Durumeric, Michael D. Bailey, Angelos D. Keromytis, Fabian Monrose, Manos Antonakakis |
IMC | 5 |
| 2022 | Equivocal URLs: Understanding the Fragmented Space of URL Parser Implementations
Joshua Reynolds, Adam Bates 0001, Michael D. Bailey |
ESORICS (3) | 3 |
| 2021 | Measuring DNS-over-HTTPS performance around the worldabstractIn recent years, DNS-over-HTTPS (DoH) has gained significant traction as a privacy-preserving alternative to unencrypted DNS. While several studies have measured DoH performance relative to traditional DNS and other encrypted DNS schemes, they are often incomplete, either conducting measurements from single countries or are unable to compare encrypted DNS to default client behavior. To expand on existing research, we use the BrightData proxy network to gather a dataset consisting of 22,052 unique clients across 224 countries and territories. Our data shows that the performance impact of a switch to DoH is mixed, with a median slowdown of 65ms per query across a 10-query connection, but with 28% of clients receiving a speedup over that same interval. We compare four public DoH providers, noting that Cloudflare excels in both DoH resolution time (265ms) and global points-of-presence (146). Furthermore, we analyze geographic differences between DoH and Do53 resolution times, and provide analysis on possible causes, finding that clients from countries with low Internet infrastructure investment are almost twice as likely to experience a slowdown when switching to DoH as those with high Internet infrastructure investment. We conclude with possible improvements to the DoH ecosystem. We hope that our findings can help to inform continuing DoH deployments. Rishabh Chhabra, Paul Murley, Deepak Kumar 0006, Michael D. Bailey, Gang Wang 0011 |
Internet Measurement Conference | 4 |
| 2021 | Tracing your roots: exploring the TLS trust anchor ecosystemabstractSecure TLS server authentication depends on reliable trust anchors. The fault intolerant design of today's system---where a single compromised trust anchor can impersonate nearly all web entities---necessitates the careful assessment of each trust anchor found in a root store. In this work, we present a first look at the root store ecosystem that underlies the accelerating deployment of TLS. Our broad collection of TLS user agents, libraries, and operating systems reveals a surprisingly condensed root store ecosystem, with nearly all user agents ultimately deriving their roots from one of three root programs: Apple, Microsoft, and NSS. This inverted pyramid structure further magnifies the importance of judicious root store management by these foundational root programs. Zane Ma, James Austgen, Joshua Mason, Zakir Durumeric, Michael D. Bailey |
Internet Measurement Conference | 5 |
| 2021 | SoK: Hate, Harassment, and the Changing Landscape of Online AbuseabstractWe argue that existing security, privacy, and antiabuse protections fail to address the growing threat of online hate and harassment. In order for our community to understand and address this gap, we propose a taxonomy for reasoning about online hate and harassment. Our taxonomy draws on over 150 interdisciplinary research papers that cover disparate threats ranging from intimate partner violence to coordinated mobs. In the process, we identify seven classes of attacks—such as toxic content and surveillance—that each stem from different attacker capabilities and intents. We also provide longitudinal evidence from a three-year survey that hate and harassment is a pervasive, growing experience for online users, particularly for at-risk communities like young adults and people who identify as LGBTQ+. Responding to each class of hate and harassment requires a unique strategy and we highlight five such potential research directions that ultimately empower individuals, communities, and platforms to do so. Kurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh, Elie Bursztein, Sunny Consolvo, Nicola Dell, Zakir Durumeric, Patrick Gage Kelley, Deepak Kumar 0006, Damon McCoy, Sarah Meiklejohn, Thomas Ristenpart, Gianluca Stringhini |
SP | 3 |
| 2021 | What's in a Name? Exploring CA Certificate Control
Zane Ma, Joshua Mason, Manos Antonakakis, Zakir Durumeric, Michael D. Bailey |
USENIX Security Symposium | 5 |
| 2021 | WebSocket Adoption and the Landscape of the Real-Time WebabstractDevelopers are increasingly deploying web applications which require real-time bidirectional updates, a use case which does not naturally align with the traditional client-server architecture of the web. Many solutions have arisen to address this need over the preceding decades, including HTTP polling, Server-Sent Events, and WebSockets. This paper investigates this ecosystem and reports on the prevalence, benefits, and drawbacks of these technologies, with a particular focus on the adoption of WebSockets. We crawl the Tranco Top 1 Million websites to build a dataset for studying real-time updates in the wild. We find that HTTP Polling remains significantly more common than WebSockets, and WebSocket adoption appears to have stagnated in the past two to three years. We investigate some of the possible reasons for this decrease in the rate of adoption, and we contrast the adoption process to that of other web technologies. Our findings further suggest that even when WebSockets are employed, the prescribed best practices for securing them are often disregarded. The dataset is made available in the hopes that it may help inform the development of future real-time solutions for the web. Paul Murley, Zane Ma, Joshua Mason, Michael D. Bailey, Amin Kharraz |
WWW | 4 |
| 2020 | Measuring Identity Confusion with Uniform Resource LocatorsabstractUniform Resource Locators (URLs) unambiguously specify host identity on the web. URLs are syntactically complex, and although software can accurately parse identity from URLs, users are frequently exposed to URLs and expected to do the same. Unfortunately, incorrect assessment of identity from a URL can expose users to attacks, such as typosquatting and phishing. Our work studies how well users can correctly determine the host identity of real URLs from common services and obfuscated "look-alike" URLs. We observe that participants employ a wide range of URL parsing strategies, and can identify real URLs 93% of time. However, only 40% of obfuscated URLs were identified correctly. These mistakes highlighted several ways in which URLs were confusing to users and why their existing URL parsing strategies fall short. We conclude with future research directions for reliably conveying website identity to users. Joshua Reynolds, Deepak Kumar 0006, Zane Ma, Rohan Subramanian, Meishan Wu, Martin Shelton, Joshua Mason, Emily Stark 0001, Michael D. Bailey |
CHI | 9 |
| 2020 | Empirical Measurement of Systemic 2FA Usability
Joshua Reynolds, Nikita Samarin, Joseph D. Barnes, Taylor Judd, Joshua Mason, Michael D. Bailey, Serge Egelman |
USENIX Security Symposium | 6 |
| 2019 | Outguard: Detecting In-Browser Covert Cryptocurrency Mining in the WildabstractIn-browser cryptojacking is a form of resource abuse that leverages end-users' machines to mine cryptocurrency without obtaining the users' consent. In this paper, we design, implement, and evaluate Outguard, an automated cryptojacking detection system. We construct a large ground-truth dataset, extract several features using an instrumented web browser, and ultimately select seven distinctive features that are used to build an SVM classification model. Outguardachieves a 97.9% TPR and 1.1% FPR and is reasonably tolerant to adversarial evasions. We utilized Outguardin the wild by deploying it across the Alexa Top 1M websites and found 6,302 cryptojacking sites, of which 3,600 are new detections that were absent from the training data. These cryptojacking sites paint a broad picture of the cryptojacking ecosystem, with particular emphasis on the prevalence of cryptojacking websites and the shared infrastructure that provides clues to the operators behind the cryptojacking phenomenon. Amin Kharraz, Zane Ma, Paul Murley, Charles Lever, Joshua Mason, Andrew Miller 0001, Nikita Borisov, Manos Antonakakis, Michael D. Bailey |
WWW | 9 |
| 2018 | Measuring Ethereum Network Peers
Seoung Kyun Kim, Zane Ma, Siddharth Murali, Joshua Mason, Andrew Miller 0001, Michael D. Bailey |
Internet Measurement Conference | 6 |
| 2018 | Tracking Certificate Misissuance in the WildabstractCertificate Authorities (CAs) regularly make mechanical errors when issuing certificates. To quantify these errors, we introduce ZLint, a certificate linter that codifies the policies set forth by the CA/Browser Forum Baseline Requirements and RFC 5280 that can be tested in isolation. We run ZLint on browser-trusted certificates in Censys and systematically analyze how well CAs construct certificates. We find that the number errors has drastically reduced since 2012. In 2017, only 0.02% of certificates have errors. However, this is largely due to a handful of large authorities that consistently issue correct certificates. There remains a long tail of small authorities that regularly issue non-conformant certificates. We further find that issuing certificates with errors is correlated with other types of mismanagement and for large authorities, browser action. Drawing on our analysis, we conclude with a discussion on how the community can best use lint data to identify authorities with worrisome organizational practices and ensure long-term health of the Web PKI. Deepak Kumar 0006, Zhengping Wang, Matthew Hyder, Joseph Dickinson, Gabrielle Beck, David Adrian, Joshua Mason, Zakir Durumeric, J. Alex Halderman, Michael D. Bailey |
IEEE Symposium on Security and Privacy | 10 |
| 2018 | SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CabstractUSB-based attacks have increased in complexity in recent years. Modern attacks now incorporate a wide range of attack vectors, from social engineering to signal injection. To address these challenges, the security community has responded with a growing set of fragmented defenses. In this work, we survey and categorize USB attacks and defenses, unifying observations from both peer-reviewed research and industry. Our systematization extracts offensive and defensive primitives that operate across layers of communication within the USB ecosystem. Based on our taxonomy, we discover that USB attacks often abuse the trust-by-default nature of the ecosystem, and transcend different layers within a software stack; none of the existing defenses provide a complete solution, and solutions expanding multiple layers are most effective. We then develop the first formal verification of the recently released USB Type-C Authentication specification, and uncover fundamental flaws in the specification's design. Based on the findings from our systematization, we observe that while the spec has successfully pinpointed an urgent need to solve the USB security problem, its flaws render these goals unattainable. We conclude by outlining future research directions to ensure a safer computing experience with USB. Jing (Dave) Tian, Nolen Scaife, Deepak Kumar 0006, Michael D. Bailey, Adam Bates 0001, Kevin R. B. Butler |
IEEE Symposium on Security and Privacy | 4 |
| 2018 | Skill Squatting Attacks on Amazon Alexa
Deepak Kumar 0006, Riccardo Paccagnella, Paul Murley, Eric Hennenfent, Joshua Mason, Adam Bates 0001, Michael D. Bailey |
USENIX Security Symposium | 7 |
| 2018 | Erays: Reverse Engineering Ethereum's Opaque Smart Contracts
Deepak Kumar 0006, Surya Bakshi, Joshua Mason, Andrew Miller 0001, Michael D. Bailey |
USENIX Security Symposium | 6 |
| 2018 | Practical Proactive DDoS-Attack Mitigation via Endpoint-Driven In-Network Traffic Control
Zhuotao Liu, Yih-Chun Hu, Michael D. Bailey |
IEEE/ACM Trans. Netw. | 4 |
| 2017 | The Security Impact of HTTPS Interception
Zakir Durumeric, Zane Ma, Drew Springall, Richard Barnes 0001, Nick Sullivan, Elie Bursztein, Michael D. Bailey, J. Alex Halderman, Vern Paxson |
NDSS | 7 |
| 2017 | Understanding the Mirai Botnet
Manos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michael G. Kallitsis, Deepak Kumar 0006, Charles Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas |
USENIX Security Symposium | 3 |
| 2017 | Security Challenges in an Increasingly Tangled WebabstractOver the past 20 years, websites have grown increasingly complex and interconnected. In 2016, only a negligible number of sites are dependency free, and over 90% of sites rely on external content. In this paper, we investigate the current state of web dependencies and explore two security challenges associated with the increasing reliance on external services: (1) the expanded attack surface associated with serving unknown, implicitly trusted third-party content, and (2) how the increased set of external dependencies impacts HTTPS adoption. We hope that by shedding light on these issues, we can encourage developers to consider the security risks associated with serving third-party content and prompt service providers to more widely deploy HTTPS. Deepak Kumar 0006, Zane Ma, Zakir Durumeric, Ariana Mirian, Joshua Mason, J. Alex Halderman, Michael D. Bailey |
WWW | 7 |
| 2016 | MiddlePolice: Toward Enforcing Destination-Defined Policies in the Middle of the InternetabstractVolumetric attacks, which overwhelm the bandwidth of a destination, are amongst the most common DDoS attacks today. One practical approach to addressing these attacks is to redirect all destination traffic (e.g., via DNS or BGP) to a third-party, DDoS-protection-as-a-service provider (e.g., CloudFlare) that is well provisioned and equipped with filtering mechanisms to remove attack traffic before passing the remaining benign traffic to the destination. An alternative approach is based on the concept of network capabilities, whereby source sending rates are determined by receiver consent, in the form of capabilities enforced by the network. While both third-party scrubbing services and network capabilities can be effective at reducing unwanted traffic at an overwhelmed destination, DDoS-protection-as-a-service solutions outsource all of the scheduling decisions (e.g., fairness, priority and attack identification) to the provider, while capability-based solutions require extensive modifications to existing infrastructure to operate. In this paper we introduce MiddlePolice, which seeks to marry the deployability of DDoS-protection-as-a-service solutions with the destination-based control of network capability systems. We show that by allowing feedback from the destination to the provider, MiddlePolice can effectively enforce destination-chosen policies, while requiring no deployment from unrelated parties. Zhuotao Liu, Yih-Chun Hu, Michael D. Bailey |
CCS | 4 |
| 2016 | Towards a Complete View of the Certificate Ecosystem
Benjamin VanderSloot, Johanna Amann, Matthew Bernhard, Zakir Durumeric, Michael D. Bailey, J. Alex Halderman |
Internet Measurement Conference | 5 |
| 2016 | Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security Policy
Jakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. Bailey |
NDSS | 4 |
| 2016 | An Internet-wide view of ICS devicesabstractIndustrial control systems have become ubiquitous, enabling the remote, electronic control of physical equipment and sensors. Originally designed to operate on closed networks, the protocols used by these devices have no built-in security. However, despite this, an alarming number of systems are connected to the public Internet and an attacker who finds a device often can cause catastrophic damage to physical infrastructure. We consider two aspects of ICS security in this work: (1) what devices have been inadvertently exposed on the public Internet, and (2) who is searching for vulnerable systems. First, we implement five common SCADA protocols in ZMap and conduct a survey of the public IPv4 address space finding more than 60K publicly accessible systems. Second, we use a large network telescope and high-interaction honeypots to find and profile actors searching for devices. We hope that our findings can both motivate and inform future work on securing industrial control systems. Ariana Mirian, Zane Ma, David Adrian, Matthew Tischer, Thasphon Chuenchujit, Timothy M. Yardley, Robin Berthier, Joshua Mason, Zakir Durumeric, J. Alex Halderman, Michael D. Bailey |
PST | 11 |
| 2016 | The Abuse Sharing Economy: Understanding the Limits of Threat Exchanges
Kurt Thomas, Rony Amira, Adi Ben-Yoash, Ori Folger, Amir Hardon, Ari Berger, Elie Bursztein, Michael D. Bailey |
RAID | 8 |
| 2016 | Users Really Do Plug in USB Drives They FindabstractWe investigate the anecdotal belief that end users will pick up and plug in USB flash drives they find by completing a controlled experiment in which we drop 297 flash drives on a large university campus. We find that the attack is effective with an estimated success rate of 45 -- 98% and expeditious with the first drive connected in less than six minutes. We analyze the types of drives users connected and survey those users to understand their motivation and security profile. We find that a drive's appearance does not increase attack success. Instead, users connect the drive with the altruistic intention of finding the owner. These individuals are not technically incompetent, but are rather typical community members who appear to take more recreational risks then their peers. We conclude with lessons learned and discussion on how social engineering attacks -- while less technical -- continue to be an effective attack vector that our community has yet to successfully address. Matthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan, Alec Mori, Elie Bursztein, Michael D. Bailey |
IEEE Symposium on Security and Privacy | 7 |
| 2016 | You've Got Vulnerability: Exploring Effective Vulnerability Notifications
Frank Li 0001, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael D. Bailey, Damon McCoy, Stefan Savage, Vern Paxson |
USENIX Security Symposium | 5 |
| 2015 | A Search Engine Backed by Internet-Wide ScanningabstractFast Internet-wide scanning has opened new avenues for security research, ranging from uncovering widespread vulnerabilities in random number generators to tracking the evolving impact of Heartbleed. However, this technique still requires significant effort: even simple questions, such as, "What models of embedded devices prefer CBC ciphers?", require developing an application scanner, manually identifying and tagging devices, negotiating with network administrators, and responding to abuse complaints. In this paper, we introduce Censys, a public search engine and data processing facility backed by data collected from ongoing Internet-wide scans. Designed to help researchers answer security-related questions, Censys supports full-text searches on protocol banners and querying a wide range of derived fields (e.g., 443.https.cipher). It can identify specific vulnerable devices and networks and generate statistical reports on broad usage patterns and trends. Censys returns these results in sub-second time, dramatically reducing the effort of understanding the hosts that comprise the Internet. We present the search engine architecture and experimentally evaluate its performance. We also explore Censys's applications and show how questions asked in recent studies become simple to answer. Zakir Durumeric, David Adrian, Ariana Mirian, Michael D. Bailey, J. Alex Halderman |
CCS | 4 |
| 2015 | Neither Snow Nor Rain Nor MITM...: An Empirical Analysis of Email Delivery SecurityabstractThe SMTP protocol is responsible for carrying some of users' most intimate communication, but like other Internet protocols, authentication and confidentiality were added only as an afterthought. In this work, we present the first report on global adoption rates of SMTP security extensions, including: STARTTLS, SPF, DKIM, and DMARC. We present data from two perspectives: SMTP server configurations for the Alexa Top Million domains, and over a year of SMTP connections to and from Gmail. We find that the top mail providers (e.g., Gmail, Yahoo, and Outlook) all proactively encrypt and authenticate messages. However, these best practices have yet to reach widespread adoption in a long tail of over 700,000 SMTP servers, of which only 35% successfully configure encryption, and 1.1% specify a DMARC authentication policy. This security patchwork---paired with SMTP policies that favor failing open to allow gradual deployment---exposes users to attackers who downgrade TLS connections in favor of cleartext and who falsify MX records to reroute messages. We present evidence of such attacks in the wild, highlighting seven countries where more than 20% of inbound Gmail messages arrive in cleartext due to network attackers. Zakir Durumeric, David Adrian, Ariana Mirian, James Kasten, Elie Bursztein, Nicolas Lidzborski, Kurt Thomas, Vijay Eranti, Michael D. Bailey, J. Alex Halderman |
Internet Measurement Conference | 9 |
| 2015 | On the Power and Limitations of Detecting Network Filtering via Passive Observation
Matthew Sargent, Jakub Czyz, Mark Allman, Michael D. Bailey |
PAM | 4 |
| 2015 | Bohatei: Flexible and Elastic DDoS Defense
Seyed Kaveh Fayaz, Yoshiaki Tobioka, Vyas Sekar, Michael D. Bailey |
USENIX Security Symposium | 4 |
| 2015 | Cloudy with a Chance of Breach: Forecasting Cyber Security Incidents
Yang Liu 0018, Armin Sarabi, Jing Zhang 0027, Parinaz Naghizadeh Ardabili, Manish Karir, Michael D. Bailey, Mingyan Liu |
USENIX Security Symposium | 6 |
| 2014 | Taming the 800 Pound Gorilla: The Rise and Decline of NTP DDoS AttacksabstractDistributed Denial of Service (DDoS) attacks based on Network Time Protocol (NTP) amplification, which became prominent in December 2013, have received significant global attention. We chronicle how this attack rapidly rose from obscurity to become the dominant large DDoS vector. Via the lens of five distinct datasets, we characterize the advent and evolution of these attacks. Through a dataset that measures a large fraction of global Internet traffic, we show a three order of magnitude rise in NTP. Using a large darknet, we observe a similar rise in global scanning activity, both malicious and research. We then dissect an active probing dataset, which reveals that the pool of amplifiers totaled 2.2M unique IPs and includes a small number of "mega amplifiers," servers that replied to a single tiny probe packet with gigabytes of data. This dataset also allows us, for the first time, to analyze global DDoS attack victims (including ports attacked) and incidents, where we show 437K unique IPs targeted with at least 3 trillion packets, totaling more than a petabyte. Finally, ISP datasets shed light on the local impact of these attacks. In aggregate, we show the magnitude of this major Internet threat, the community's response, and the effect of that response. Jakub Czyz, Michael G. Kallitsis, Manaf Gharaibeh, Christos Papadopoulos, Michael D. Bailey, Manish Karir |
Internet Measurement Conference | 5 |
| 2014 | The Matter of HeartbleedabstractThe Heartbleed vulnerability took the Internet by surprise in April 2014. The vulnerability, one of the most consequential since the advent of the commercial Internet, allowed attackers to remotely read protected memory from an estimated 24--55% of popular HTTPS sites. In this work, we perform a comprehensive, measurement-based analysis of the vulnerability's impact, including (1) tracking the vulnerable population, (2) monitoring patching behavior over time, (3) assessing the impact on the HTTPS certificate ecosystem, and (4) exposing real attacks that attempted to exploit the bug. Furthermore, we conduct a large-scale vulnerability notification experiment involving 150,000 hosts and observe a nearly 50% increase in patching by notified hosts. Drawing upon these analyses, we discuss what went well and what went poorly, in an effort to understand how the technical community can respond more effectively to such events in the future. Zakir Durumeric, James Kasten, David Adrian, J. Alex Halderman, Michael D. Bailey, Frank Li 0001, Nicholas Weaver, Johanna Amann, Jethro G. Beekman, Mathias Payer, Vern Paxson |
Internet Measurement Conference | 5 |
| 2014 | On the Mismanagement and Maliciousness of Networks
Jing Zhang 0027, Zakir Durumeric, Michael D. Bailey, Mingyan Liu, Manish Karir |
NDSS | 3 |
| 2014 | Measuring IPv6 adoptionabstractAfter several IPv4 address exhaustion milestones in the last three years, it is becoming apparent that the world is running out of IPv4 addresses, and the adoption of the next generation Internet protocol, IPv6, though nascent, is accelerating. In order to better understand this unique and disruptive transition, we explore twelve metrics using ten global-scale datasets to create the longest and broadest measurement of IPv6 adoption to date. Using this perspective, we find that adoption, relative to IPv4, varies by two orders of magnitude depending on the measure examined and that care must be taken when evaluating adoption metrics in isolation. Further, we find that regional adoption is not uniform. Finally, and perhaps most surprisingly, we find that over the last three years, the nature of IPv6 utilization-in terms of traffic, content, reliance on transition technology, and performance-has shifted dramatically from prior findings, indicating a maturing of the protocol into production mode. We believe IPv6's recent growth and this changing utilization signal a true quantum leap. Jakub Czyz, Mark Allman, Jing Zhang 0027, Scott Iekel-Johnson, Eric Osterweil, Michael D. Bailey |
SIGCOMM | 6 |
| 2014 | An Internet-Wide View of Internet-Wide Scanning
Zakir Durumeric, Michael D. Bailey, J. Alex Halderman |
USENIX Security Symposium | 2 |
| 2013 | Small is better: avoiding latency traps in virtualized data centersabstractPublic clouds have become a popular platform for building Internet-scale applications. Using virtualization, public cloud services grant customers full control of guest operating systems and applications, while service providers still retain the management of their host infrastructure. Because applications built with public clouds are often highly sensitive to response time, infrastructure builders strive to reduce the latency of their data center's internal network. However, most existing solutions require modification to the software stack controlled by guests. We introduce a new host-centric solution for improving latency in virtualized cloud environments. In this approach, we extend a classic scheduling principle---Shortest Remaining Time First---from the virtualization layer, through the host network stack, to the network switches. Experimental and simulation results show that our solution can reduce median latency of small flows by 40%, with improvements in the tail of almost 90%, while reducing throughput of large flows by less than 3%. Yunjing Xu, Michael D. Bailey, Brian D. Noble, Farnam Jahanian |
SoCC | 2 |
| 2013 | Understanding IPv6 internet background radiationabstractWe report the results of a study to collect and analyze IPv6 Internet background radiation. This study, the largest of its kind, collects unclaimed traffic on the IPv6 Internet by announcing five large covering prefixes; these cover the majority of allocated IPv6 space on today's Internet. Our analysis characterizes the nature of this traffic across regions, over time, and by the allocation and routing status of the intended destinations, which we show help to identify the causes of this traffic. We compare results to unclaimed traffic in IPv4, and highlight case studies that explain a large fraction of the data or highlight notable properties. We describe how announced covering prefixes differ from traditional network telescopes, and show how this technique can help both network operators and the research community identify additional potential issues and misconfigurations in this critical Internet transition period. Jakub Czyz, Kyle Lady, Sam G. Miller, Michael D. Bailey, Michael G. Kallitsis, Manish Karir |
Internet Measurement Conference | 4 |
| 2013 | Analysis of the HTTPS certificate ecosystemabstractWe report the results of a large-scale measurement study of the HTTPS certificate ecosystem---the public-key infrastructure that underlies nearly all secure web communications. Using data collected by performing 110 Internet-wide scans over 14 months, we gain detailed and temporally fine-grained visibility into this otherwise opaque area of security-critical infrastructure. We investigate the trust relationships among root authorities, intermediate authorities, and the leaf certificates used by web servers, ultimately identifying and classifying more than 1,800 entities that are able to issue certificates vouching for the identity of any website. We uncover practices that may put the security of the ecosystem at risk, and we identify frequent configuration problems that lead to user-facing errors and potential vulnerabilities. We conclude with lessons and recommendations to ensure the long-term health and security of the certificate ecosystem. Zakir Durumeric, James Kasten, Michael D. Bailey, J. Alex Halderman |
Internet Measurement Conference | 3 |
| 2013 | Clear and Present Data: Opaque Traffic and its Security Implications for the Future
Andrew M. White 0002, Srinivas Krishnan, Michael D. Bailey, Fabian Monrose, Phillip A. Porras |
NDSS | 3 |
| 2013 | Bobtail: Avoiding Long Tails in the Cloud
Yunjing Xu, Zachary Musgrave, Brian D. Noble, Michael D. Bailey |
NSDI | 4 |
| 2013 | Understanding IPv6 Populations in the Wild
Manish Karir, Geoff Huston, George Michaelson, Michael D. Bailey |
PAM | 4 |
| 2013 | Characterization of Blacklists and Tainted Network Traffic
Jing Zhang 0027, Ari Chivukula, Michael D. Bailey, Manish Karir, Mingyan Liu |
PAM | 3 |
| 2013 | Detecting Traditional Packers, Decisively
Denis Bueno, Kevin J. Compton, Karem A. Sakallah, Michael D. Bailey |
RAID | 4 |
| 2012 | Safeguarding academic accounts and resources with the University Credential Abuse Auditing SystemabstractWhether it happens through malware or through phishing, loss of one's online identity is a real and present danger. While many attackers seek credentials to realize financial gain, an analysis of the compromised accounts at our own institutions reveals that perpetrators often steal university credentials to gain free and unfettered access to information. This nontraditional motivation for credential theft puts a special burden on the academic institutions that provide these accounts. In this paper, we describe the design, implementation, and evaluation of a system for safeguarding academic accounts and resources called the University Credential Abuse Auditing System (UCAAS). We evaluate UCAAS at two major research universities with tens of thousands of user accounts and millions of login events during a two-week period. We show the UCAAS to be useful in reducing this burden, having helped the university security teams identify a total of 125 compromised accounts with zero false positives during the trail. Jing Zhang 0027, Robin Berthier, Will Rhee, Michael D. Bailey, Partha P. Pal, Farnam Jahanian, William H. Sanders |
DSN | 4 |
| 2011 | A comparative study of two network-based anomaly detection methodsabstractModern networks are complex and hence, network operators often rely on automation to assist in assuring the security, availability, and performance of these networks. At the core of many of these systems are general-purpose anomaly-detection algorithms that seek to identify normal behavior and detect deviations. While the number and variations of these algorithms are large, two broad categories have emerged as leading approaches to this problem: those based on spatial correlation and those based on temporal analysis. In this paper, we compare one promising approach from each of these categories, namely entropy-based PCA and HHH-based wavelets. Kaustubh Nyalkalkar, Sushant Sinha, Michael D. Bailey, Farnam Jahanian |
INFOCOM | 3 |
| 2011 | On Measuring the Similarity of Network Hosts: Pitfalls, New Metrics, and Empirical Analyses
Scott E. Coull, Fabian Monrose, Michael D. Bailey |
NDSS | 3 |
| 2010 | Internet background radiation revisitedabstractThe monitoring of packets destined for routeable, yet unused, Internet addresses has proved to be a useful technique for measuring a variety of specific Internet phenomenon (e.g., worms, DDoS). In 2004, Pang et al. stepped beyond these targeted uses and provided one of the first generic characterizations of this non-productive traffic, demonstrating both its significant size and diversity. However, the six years that followed this study have seen tremendous changes in both the types of malicious activity on the Internet and the quantity and quality of unused address space. In this paper, we revisit the state of Internet ”background radiation ” through the lens of two unique data-sets: a five-year collection from a single unused /8 network block, and week-long collections from three recently allocated /8 network blocks. Through Eric Wustrow, Manish Karir, Michael D. Bailey, Farnam Jahanian, Geoff Huston |
Internet Measurement Conference | 3 |
| 2010 | Improving Spam Blacklisting Through Dynamic Thresholding and Speculative Aggregation
Sushant Sinha, Michael D. Bailey, Farnam Jahanian |
NDSS | 2 |
| 2010 | CANVuS: Context-Aware Network Vulnerability Scanning
Yunjing Xu, Michael D. Bailey, Eric Vander Weele, Farnam Jahanian |
RAID | 2 |
| 2008 | Towards an understanding of anti-virtualization and anti-debugging behavior in modern malwareabstractMany threats that plague today’s networks (e.g., phishing, botnets, denial of service attacks) are enabled by a complex ecosystem of attack programs commonly called malware. To combat these threats, defenders of these networks have turned to the collection, analysis, and reverse engineering of malware as mechanisms to understand these programs, generate signatures, and facilitate cleanup of infected hosts. Recently however, new malware instances have emerged with the capability to check and often thwart these defensive activities — essentially leaving defenders blind to their activities. To combat this emerging threat, we have undertaken a robust analysis of current malware and developed a detailed taxonomy of malware defender fingerprinting methods. We demonstrate the utility of this taxonomy by using it to characterize the prevalence of these avoidance methods, to generate a novel fingerprinting method that can assist malware propagation, and to create an effective new technique to protect production systems. Xu Chen 0028, Jonathon Andersen, Z. Morley Mao, Michael D. Bailey, Jose Nazario |
DSN | 4 |
| 2007 | Shedding Light on the Configuration of Dark Addresses
Sushant Sinha, Michael D. Bailey, Farnam Jahanian |
NDSS | 2 |
| 2007 | Automated Classification and Analysis of Internet Malware
Michael D. Bailey, Jon Oberheide, Jon Andersen, Z. Morley Mao, Farnam Jahanian, Jose Nazario |
RAID | 1 |
| 2006 | The Dark Oracle: Perspective-Aware Unused and Unreachable Address Discovery
Evan Cooke, Michael D. Bailey, Farnam Jahanian, Richard Mortier |
NSDI | 2 |
| 2005 | Data Reduction for the Scalable Automated Analysis of Distributed Darknet Traffic
Michael D. Bailey, Evan Cooke, Farnam Jahanian, Niels Provos, Karl Rosaen, David Watson 0001 |
Internet Measurement Conference | 1 |
| 2005 | The Internet Motion Sensor - A Distributed Blackhole Monitoring System
Michael D. Bailey, Evan Cooke, Farnam Jahanian, Jose Nazario |
NDSS | 1 |