VLDB 2026 Research / reviewers in the wild / expert
Ralph Holz
dblp:42/1058 · also Ralph-Günther Holz
· DBLP profile ↗
26ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0001-9614-2377ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 4 since 2021Computer networks · 7 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Through a Smaller Lens: Revisiting Opportunistic Analysis Using Network Telescopes
Bernhard Degen, Nils Kempen, K. C. Claffy, Ricky K. P. Mok, Ralph Holz, Roland van Rijswijk-Deij, Raffaele Sommese, Mattijs Jonker |
PAM | 5 |
| 2026 | Detecting and Characterizing DDoS Scrubbing from Global BGP Routing: Insights from Five Leading Scrubbers
Shyam Krishna Khadka, Suzan Bayhan, Ralph Holz, Cristian Hesselman |
PAM | 3 |
| 2025 | Characterizing Hosting and Security Practices for Public-Facing LDAP ServersabstractThe Lightweight Directory Access Protocol (LDAP) is widely used to make structured data available for standardized lookup, which may sometimes include personal information or authentication credentials. Previous work, including ours, found security issues such as public LDAP servers leaking sensitive information without prior authentication and server configurations with poor communication security. However, prior work did not investigate whether, or to what extent, the identified problems are linked to hosting and management setups. In this paper, we address this gap and explore the organizations hosting publicfacing LDAP servers. We identify the network segments more likely to host LDAP instances, the products and operating systems used, and examine the management practices related to Public Key Infrastructure (PKI) setups for LDAP. In contrast to studies on Web and email, which have revealed strong centralization tendencies in deployment, we show that the LDAP ecosystem is diverse, with a wide range of different hosting networks. In this study, we identify 69.1 k LDAP instances- $6.5 \times$ more than prior work-and map these to the respective LDAP products. We find that 5.8% of the servers use a product that is end-of-life or runs on a deprecated OS. We identify servers using problematic X. 509 certificates, e.g., those associated with publicly known private keys. From our observations, we give recommendations for network operators to improve their security posture. Gustavo Luvizotto Cesar, Gurur Öndarö, Jonas Kaspereit, Fabian Ising, Sebastian Schinzel, Mattijs Jonker, Ralph Holz |
CNSM | 7 |
| 2025 | A First Look at the Adoption of BGP-based DDoS Scrubbing Services: A 5-year Longitudinal AnalysisabstractBesides being the de facto routing protocol of the Internet, the Border Gateway Protocol (BGP) has also been used for mitigating Distributed Denial of Service (DDoS) attacks for many years. In such situations, victims of DDoS attacks use BGP to redirect attack traffic to a “scrubber” outside their network, which separates clean traffic from DDoS traffic and forwards the former to the victim’s network. While there exist many BGP-based DDoS scrubbing providers, their adoption on the global Internet remains unstudied. This paper aims to fill this gap by identifying and characterizing Autonomous Systems (ASes) and prefixes protected by five of the leading scrubbing providers, using AS path patterns in public BGP routing data. Our study focuses on scrubbers that allow their protected ASes to originate their prefixes themselves. We find that the percentage of ASes using this kind of protection has increased almost three times (from 0.7% to 2% and from 464 ASes to 1,730 ASes) between 2020 and 2024. Similarly, the percentage of protected prefixes has also increased three times in the same period, from 0.3% to 0.9% and from 3,154 to 12,362 prefixes, across both IPv4 and IPv6. Globally, we observe a higher adoption rate among financial institutions, while adoption remains low among educational institutions. We believe our insights will be useful for individual AS operators to find the transit providers or peers that are DDoS-protected. It might also be useful for (national) policy-makers to incentivize the adoption of DDoS protection services and for researchers studying the phenomenon of DDoS scrubbing. Shyam Krishna Khadka, Suzan Bayhan, Ralph Holz, Saeedeh Shokoohi, Marinho P. Barcellos, Cristian Hesselman |
CNSM | 3 |
| 2025 | Double-Edged Sword: An Empirical Study on the Contribution of Cloud Providers in Malicious InfrastructureabstractCloud computing offers flexibility and costeffectiveness, but can also be abused for malicious activities. In this study, we conduct an empirical analysis of the cloud infrastructure of malicious (blocklisted) domains, with a focus on three core infrastructural components — web hosting, DNS, and email — and we compare them against a baseline of general domains. Our goal is to assess the rate of abuse targeting these components as they represent fundamental pillars of Internet communication. Leveraging DNS data from OpenINTEL, cloud classification from IP2Location, and a curated ground-truth list of cloud providers, we evaluate the role of major providers in hosting malicious infrastructure. Our results show that malicious domains are increasingly shifting toward partial cloud infrastructure outsourcing, with a strong preference for cloud-based web hosting while avoiding full-stack cloud adoption. We also observe a high degree of diversity of malicious infrastructure deployment across all three components. Finally, our country analysis highlights a growing concentration of malicious hosting activity in the Asia-Pacific region. Sousan Tarahomi, Raffaele Sommese, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 4 |
| 2025 | Investigating Middlebox Deployment and Characteristics in Dutch Autonomous SystemsabstractMiddleboxes shape modern network behavior by enforcing security policies and optimizing traffic, but their opaque operations reduce network transparency and complicate digital sovereignty efforts. In this study, we analyze middlebox deployment and behavior across Dutch Autonomous Systems (ASes), motivated by the strategic position of the Netherlands in European network infrastructure. We classify ASes into sectorsgovernmental, private, educational, and digital infrastructureand using active probing and third-party datasets, we examined 989 ASes and 5.1 million IPs, identified 310 middleboxes, with high confidence, registered to and located within Dutch ASes. Our results reveal several sector-specific interference patterns. ISPs and hosting providers show diverse modifications, governmental ASes exhibit consistent policy enforcement at the edge, and private ASes adopt hybrid strategies, combining TCP option stripping with deeper manipulation of TCP state. Exposed management interfaces and outdated software further increase operational risks, whether tied to the middleboxes themselves or co-located devices. Our findings highlight the value of AS-level investigation for understanding middlebox behavior and underscore the need for proactive auditing and secure configuration to support resilient and sovereign network infrastructure. Bulut Ulukapi, Anna Sperotto, Ralph Holz |
CNSM | 3 |
| 2025 | ACCESS-FL: Agile Communication and Computation for Efficient Secure Aggregation in Stable Networks for FLaaSabstractFederated Learning (FL) enables privacy-preserving machine learning by allowing clients to collaboratively train models without sharing raw data. Federated Learning as a Service (FLaaS) extends this approach to cloud infrastructures. However, conventional secure aggregation protocols, such as Google's SecAgg and SecAgg+, introduce high computation and communication overheads, particularly in large-scale FLaaS deployments where client dropout rates are limited. To address these challenges, we propose ACCESS-FL, a lightweight, secure aggregation method designed for honest-but-curious FLaaS scenarios with stable network conditions. ACCESS-FL eliminates double masking, Shamir's Secret Sharing, and excessive encryption/decryption by creating shared secrets only between two peers per client, which reduces computation and communication complexity to constant$O(1)$and makes the algorithm independent of network size and comparable to standard FL. ACCESS-FL preserves privacy against inversion attacks and maintains model accuracy equivalent to the FL, SecAgg, and SecAgg+ protocols, proving that reducing overhead does not compromise learning performance and achieves communication and computation costs comparable to standard FL. Experimental evaluations on benchmark datasets (MNIST, FMNIST, and CIFAR-10) demonstrate lower overhead, making ACCESS-FL practical for service-based stable FLaaS applications such as healthcare analytics. Niousha Nazemi, Omid Tavallaie, Shuaijun Chen, Anna Maria Mandalari, Kanchana Thilakarathna, Ralph Holz, Hamed Haddadi 0001, Albert Y. Zomaya |
ICWS | 6 |
| 2025 | Web Crawl Refusals: Insights From Common Crawl
Mostafa Ansar, Anna Sperotto, Ralph Holz |
PAM | 3 |
| 2024 | Is a Name Enough? A First Look into Detecting Clouds Using DNS Pointer RecordsabstractThe flexibility and scalability of cloud services have led to their adoption across various industries. While it is easy to identify deployments of very large cloud providers (hypergiants) as they often publish the allocation of their network resources, this is much less commonly the case for smaller providers. Despite efforts by commercial IP intelligence providers to bridge this gap, it is not clear how complete and reliable their data is, which is compounded by the lack of transparency surrounding their identification methods. In this early study, we utilize reverse DNS, a public data source provided and used by network operators, to identify the IP cloud space. We develop a Markov chain-based classifier to identify patterns and structures in the reverse DNS naming schemes of cloud providers. Our results indicate that cloud infrastructure naming often differs significantly from that of residential IP space, although there are some overlaps that require further investigation. We believe that our model can be used by network operators to identify cloud deployments with varying levels of confidence. Sousan Tarahomi, Raffaele Sommese, Pieter-Tjerk de Boer, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 5 |
| 2024 | LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scale
Jonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers, Fabian Ising, Christoph Saatjohann, Mattijs Jonker, Ralph Holz, Sebastian Schinzel |
USENIX Security Symposium | 8 |
| 2023 | Quantifying Security Risks in Cloud Infrastructures: A Data-driven ApproachabstractBusinesses increasingly outsource their ICT services to cloud environments, mostly driven by considerations about costs, processes and security. However concerns around cloud exposure against cyber-security attacks are also growing. This bring about the question if the cloud really makes us more secure, or if it merely changes the type of threats we are exposed to. This PhD project aims at addressing this question by focusing on cloud infrastructure security. Using Internet measurements, we will take a data-driven approach to identify vulnerabilities and single points of failure in cloud infrastructure. Based on our analysis, we will propose solutions to mitigate these vulnerabilities and enhance the overall security of cloud environments. Sousan Tarahomi, Ralph Holz, Anna Sperotto |
NetSoft | 2 |
| 2022 | On the Asymmetry of Internet eXchange Points -Why Should IXPs and CDNs Care?abstractInternet eXchange Points (IXPs) provide an infrastructure where content providers and consumers can freely exchange network traffic. The main incentive for connecting to an IXP is to decrease costs and improve the user experience by having content closer to consumers. Despite these benefits, several small Content Delivery Networks (CDNs) avoid exchanging traffic on IXPs due to the poor routing quality via IXP paths. In this paper, we investigate how traffic asymmetry affects the quality of paths. IXP asymmetry occurs when traffic is sent (or received) via a direct IXP peering but received (or sent) on an alternative path outside the IXP. We employ a new method to quantify a symmetry rate for an IXP, which we evaluate on five IXPs. Our method covers three times more ASes than alternatives, such as using RIPE ATLAS. Our results show that IXPs have 15% asymmetric paths at a distance of one AS hop, i.e., when sending traffic to a given peer on the IXP, 15% of this traffic will be responded via a transit AS that does not use the IXP path. We also identify deaf neighbors, i.e., ASes that never return traffic to the IXP. We identify egress-only paths as a major cause of asymmetries and show that this occurs only for a small number of ASes. We also quantify the impact of traffic asymmetry at IXPs in terms of latency and show that traditional traffic engineering on IXP prefixes can actually make route quality worse. Leandro Marcio Bertholdo, Sandro L. A. Ferreira, João M. Ceron, Lisandro Z. Granville, Ralph Holz, Roland van Rijswijk-Deij |
CNSM | 5 |
| 2020 | On the Origin of Scanning: The Impact of Location on Internet-Wide ScansabstractFast IPv4 scanning has enabled researchers to answer a wealth of security and networking questions. Yet, despite widespread use, there has been little validation of the methodology's accuracy, including whether a single scan provides sufficient coverage. In this paper, we analyze how scan origin affects the results of Internet-wide scans by completing three HTTP, HTTPS, and SSH scans from seven geographically and topologically diverse networks. We find that individual origins miss an average 1.6-8.4% of HTTP, 1.5-4.6% of HTTPS, and 8.3-18.2% of SSH hosts. We analyze why origins see different hosts, and show how permanent and temporary blocking, packet loss, geographic biases, and transient outages affect scan results. We discuss the implications for scanning and provide recommendations for future studies. Gerry Wan, Liz Izhikevich, David Adrian, Katsunari Yoshioka, Ralph Holz, Christian Rossow, Zakir Durumeric |
Internet Measurement Conference | 5 |
| 2020 | Triplet Mining-based Phishing Webpage DetectionabstractPhishing web pages impersonate legitimate websites to trick users into entering sensitive information such as their credentials. In many high profile data breaches, the initial entry points have been traced back to phishing attacks. Attackers are using increasingly sophisticated methods such as code obfuscation to bypass existing phishing detection systems. Since phishing websites show very high visual similarity to the respective target pages, recent advances in Convolutional Neural Networks (CNN) can be leveraged to build better phishing detection systems. In this work, we propose a novel CNN architecture consisting of two paths to capture the content similarity and structural similarity between web pages. Leveraging the fact that web pages of the same web site are visually similar, we use triplet learning to train our model without any labelled phishing examples. Kalana Abeywardena, Lexi Brent, Suranga Seneviratne, Ralph Holz |
LCN | 5 |
| 2018 | The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch |
Internet Measurement Conference | 7 |
| 2018 | In Log We Trust: Revealing Poor Security Practices with Certificate Transparency Logs and Internet Measurements
Oliver Gasser, Benjamin Hof, Max Helm, Maciej Korczynski, Ralph Holz, Georg Carle |
PAM | 5 |
| 2017 | Automated Analysis of Secure Internet of Things ProtocolsabstractFormal security analysis has proven to be a useful tool for tracking modifications in communication protocols in an automated manner, where full security analysis of revisions requires minimum efforts. In this paper, we formally analysed prominent IoT protocols and uncovered many critical challenges in practical IoT settings. We address these challenges by using formal symbolic modelling of such protocols under various adversaries and security goals. Furthermore, this paper extends formal analysis to cryptographic Denial-of-Service (DoS) attacks and demonstrates that a vast majority of IoT protocols are vulnerable to such resource exhaustion attacks. We present a cryptographic DoS attack countermeasure that can be generally used in many IoT protocols. Our study of prominent IoT protocols such as CoAP and MQTT shows the benefits of our approach. Jun Young Kim, Ralph Holz, Wen Hu 0001, Sanjay K. Jha |
ACSAC | 2 |
| 2017 | Mission accomplished?: HTTPS security after diginotarabstractDriven by CA compromises and the risk of man-in-the-middle attacks, new security features have been added to TLS, HTTPS, and the web PKI over the past five years. These include Certificate Transparency (CT), for making the CA system auditable; HSTS and HPKP headers, to harden the HTTPS posture of a domain; the DNS-based extensions CAA and TLSA, for control over certificate issuance and pinning; and SCSV, for protocol downgrade protection. Johanna Amann, Oliver Gasser, Quirin Scheitle, Lexi Brent, Georg Carle, Ralph Holz |
Internet Measurement Conference | 6 |
| 2017 | On Availability for Blockchain-Based SystemsabstractBlockchain has recently gained momentum. Startups, enterprises, banks, and government agencies around the world are exploring the use of blockchain for broad applications including public registries, supply chains, health records, and voting. Dependability properties, like availability, are critical for many of these applications, but the guarantees offered by the blockchain technology remain unclear, especially from an application perspective. In this paper, we identify the availability limitations of two mainstream blockchains, Ethereum and Bitcoin. We demonstrate that while read availability of blockchains is typically high, write availability - for transaction management - is actually low. For Ethereum, we collected 6 million transactions over a period of 97 days. First, we measured the time for transactions to commit as required by the applications. Second, we observed that some transactions never commit, due to the inherent blockchain design. Third and perhaps even more dramatically, we identify the consequences of the lack of built-in options for explicit abort or retry that can maintain the application in an uncertain state, where transactions remain pending (neither aborted nor committed) for an unknown duration. Finally we propose techniques to mitigate the availability limitations of existing blockchains, and experimentally test the efficacy of these techniques. Ingo Weber, Vincent Gramoli, Alexander Ponomarev, Mark Staples, Ralph Holz, An Binh Tran, Paul Rimba |
SRDS | 5 |
| 2016 | Endpoint-Transparent Multipath Transport with Software-Defined NetworksabstractMultipath forwarding consists of using multiple paths simultaneously to transport data over the network. While most such techniques require endpoint modifications, we investigate how multipath forwarding can be done inside the network, transparently to endpoint hosts. With such a network-centric approach, packet reordering becomes a critical issue as it may cause critical performance degradation. We present a Software Defined Network architecture which automatically sets up multipath forwarding, including solutions for reordering and performance improvement, both at the sending side through multipath scheduling algorithms, and the receiver side, by resequencing out-of-order packets in a dedicated in-network buffer. We implemented a prototype with commonly available technology and evaluated it in both emulated and real networks. Our results show consistent throughput improvements, thanks to the use of aggregated path capacity. We give comparisons to Multipath TCP, where we show our approach can achieve a similar performance while offering the advantage of endpoint transparency. Dario Banfi, Olivier Mehani, Guillaume Jourjon, Lukas Schwaighofer, Ralph Holz |
LCN | 5 |
| 2016 | TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic Communication
Ralph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar, Matthias Wachs |
NDSS | 1 |
| 2016 | HEAP: Reliable Assessment of BGP Hijacking AttacksabstractThe detection of BGP prefix hijacking attacks has been the focus of research for more than a decade. However, the state-of-the-art techniques fall short of detecting more elaborate types of attack. To study such attacks, we devise a novel formalization of Internet routing, and apply this model to routing anomalies in order to establish a comprehensive attacker model. We use this model to precisely classify attacks and to evaluate their impact and detectability. We analyze the eligibility of attack tactics that suit an attacker's goals and demonstrate that related work mostly focuses on less impactful kinds of attacks. We further propose, implement, and test the Hijacking Event Analysis Program (HEAP), a new approach to investigate hijacking alarms. Our approach is designed to seamlessly integrate with the previous work in order to reduce the high rates of false alarms inherent to these techniques. We leverage several unique data sources that can reliably disprove malicious intent. First, we make use of an Internet routing registry to derive business or organizational relationships between the parties involved in an event. Second, we use a topology-based reasoning algorithm to rule out events caused by legitimate operational practice. Finally, we use Internet-wide network scans to identify SSL/TLS-enabled hosts, which helps to identify non-malicious events by comparing public keys prior to and during an event. In our evaluation, we prove the effectiveness of our approach, and show that day-to-day routing anomalies are harmless for the most part. More importantly, we use HEAP to assess the validity of publicly reported alarms. We invite researchers to interface with HEAP in order to crosscheck and narrow down their hijacking alerts. Johann Schlamp, Ralph Holz, Quentin Jacquemart, Georg Carle, Ernst W. Biersack |
IEEE J. Sel. Areas Commun. | 2 |
| 2014 | A deeper understanding of SSH: Results from Internet-wide scansabstractUntil recently, relatively little was known about the characteristics of the SSH protocol on the Internet, until two larger studies analysed the cryptographic properties of SSH host keys and identified weaknesses in a number of SSH devices. However, there is no succinct comprehensive image yet how the SSH landscape looks like from the point of view of deployment practices, especially with respect to key management. In this paper, we present the results of Internet-wide SSH scans that we carried out over a period of 7 months, which resulted in the largest data set to date. We enriched our data set with large-scale mappings obtained from DNS scans, AS and WHOIS lookups, and a geo-IP database. We analysed the distribution of server and protocol versions, and found that while SSH 2 has displaced SSH 1, the rate of software updates seems to be slow. We analysed the mentioned cryptographic weaknesses and found they have become fewer, but continue to persist one year after the disclosure. Finally, we investigated the reasons for duplicate yet cryptographically strong keys. We found these are used in very different setups at varying degrees of security. Some are indeed dangerous weaknesses, others are the result of a careful and centralised setup. By example of the ten most common keys, we show the circumstances in which they occur and assess the security of each deployment. Finally, we analysed the deployment of ciphers and associated key lengths and found good results in terms of security. As our scans are of a sensitive nature, we also document the ethical considerations that guided us. Oliver Gasser, Ralph Holz, Georg Carle |
NOMS | 2 |
| 2012 | X.509 Forensics: Detecting and Localising the SSL/TLS Men-in-the-Middle
Ralph Holz, Thomas Riedmaier, Nils Kammenhuber, Georg Carle |
ESORICS | 1 |
| 2011 | Investigating the OpenPGP Web of Trust
Alexander Ulrich, Ralph Holz, Peter Hauck, Georg Carle |
ESORICS | 2 |
| 2011 | The SSL landscape: a thorough analysis of the x.509 PKI using active and passive measurementsabstractThe SSL and TLS infrastructure used in important protocols like HTTPs and IMAPs is built on an X.509 public-key infrastructure (PKI). X.509 certificates are thus used to authenticate services like online banking, shopping, e-mail, etc. However, it always has been felt that the certification processes of this PKI may lack in stringency, resulting in a deployment where many certificates do not meet the requirements of a secure PKI. Ralph Holz, Lothar Braun, Nils Kammenhuber, Georg Carle |
Internet Measurement Conference | 1 |