David R. Choffnes

dblp:48/6854 · DBLP profile ↗
← Back
87ranked-venue papers
5as first author
27since 2021 · last 2026
0000-0001-7825-7226ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 55 · 5 first-author · 12 since 2021Security and privacy · 24 · 11 since 2021Human-computer interaction and ubiquitous computing · 4 · 4 since 2021Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 HERMES: Repurposing User-Driven Speed Tests to Monitor the Internet
abstract
Diagnosing performance degradations and pinpointing their source is crucial for operators to make informed routing decisions and for policymakers and researchers to assess the Internet's stability, yet no publicly available observatories currently provide this capability. Existing solutions rely on coarse-grained signals that fail to capture end-user performance, while proprietary solutions are inaccessible and offer limited attribution for identifying the source of a problem. We introduce HERMES, the first open system to fill this gap. HERMES uses publicly available M-Lab speed tests—data that has existed for years but has not previously been used to automatically detect and explain end-user performance degradations at scale. To achieve these goals, HERMES combines statistical techniques to detect performance degradation with novel tomography methods and forward and reverse path measurements to localize the source of a problem. Despite relying only on public data, HERMES matches a reimplementation of a large cloud provider's monitoring system for 94.5% of events visible to both systems, agreeing on the degradation source in the path. HERMES also surfaces 11× more publicly discussed events than existing public observatories. We demonstrate its ability to track weather- and cable-cut disruptions, diagnose routing inefficiencies, and identify persistently congested links.
Loqman Salamatian, Kevin Vermeulen, David R. Choffnes, Ethan Katz-Bassett, Phillipa Gill
SIGCOMM3
2025 Promises, Promises: Understanding Claims Made in Social Robot Consumer Experiences
abstract
Social robots are a class of emerging smart consumer electronics devices that promise sophisticated experiences featuring emotive capabilities, artificial intelligence, conversational interaction, and more. With unique risk factors like emotional attachment, little is known on how social robots communicate these promises to consumers and whether they adequately deliver upon them within their overall product experiences prior to and during user interaction. Animated by a consumer protection lens, this paper systematically investigates manufacturer claims made for four commercially available social robots, evaluating these claims against the provided user experience and consumer reviews. We find that social robots vary widely in the manner and extent to which they communicate intelligent features and the supposed benefits of these features, while consumer perspectives similarly include a wide range of perceptions on robot and AI performance, capabilities, and product frustrations. We conclude by discussing social robots’ unique propensities for consumer risk, and consider implications for regulators, developers, and researchers of social robots.
Johanna Gunawan, Sarah Elizabeth Gillespie, David R. Choffnes, Woodrow Hartzog, Christo Wilson
CHI3
2025 Empirically Measuring Data Localization in the EU
abstract
EU data localization regulations limit data transfers to non-EU countries with the GDPR. However, BGP, DNS and other Internet protocols were not designed to enforce jurisdictional constraints, so implementing data localization is challenging. Despite initial research on the topic, little is known about if or how companies currently operate their server infrastructure to comply with the regulations. We close this knowledge gap by empirically measuring the extent to which servers and routers that process EU requests are located outside of the EU (and a handful of 'adequate' non-EU countries). The key challenge is that both browser measurements (to infer relevant endpoints) and data-plane measurements (to infer relevant IP addresses) are needed, but no large-scale public infrastructure allows both. We build a novel methodology that combines BrightData (browser) and RIPE Atlas (data-plane) probes, with joint measurements from over 1,000 networks in 20 EU countries. We find that, on average, 2.2% of servers serving users in each EU country are located in non-adequate destination countries (1.4% of known trackers). Our findings suggest that data localization policies are largely being followed by content providers, though there are exceptions.
Alexander Gamero-Garrido, Kicho Yu, Sumukh Vasisht Shankar, Sachin Kumar Singh, Sindhya Balasubramanian, Alexander Wilcox, David R. Choffnes
Proc. Priv. Enhancing Technol.7
2025 Echoes of Privacy: Uncovering the Profiling Practices of Voice Assistants
abstract
Many companies, including Google, Amazon, and Apple, offer voice assistants as a convenient solution for answering general voice queries and accessing their services. These voice assistants have gained popularity and can be easily accessed through various smart devices such as smartphones, smart speakers, smartwatches, and an increasing array of other devices. However, this convenience comes with potential privacy risks. For instance, while companies vaguely mention in their privacy policies that they may use voice interactions for user profiling, it remains unclear to what extent this profiling occurs and whether voice interactions pose greater privacy risks compared to other interaction modalities. In this paper, we conduct 1171 experiments involving 24530 queries with different personas and interaction modalities during 20 months to characterize how the three most popular voice assistants profile their users. We analyze factors such as labels assigned to users, their accuracy, the time taken to assign these labels, differences between voice and web interactions, and the effectiveness of profiling remediation tools offered by each voice assistant. Our findings reveal that profiling can happen without interaction, can be incorrect and inconsistent at times, may take several days or weeks to change, and is affected by the interaction modality.
Tina Khezresmaeilzadeh, Elaine Zhu, Kiersten Grieco, Daniel J. Dubois, Konstantinos Psounis, David R. Choffnes
Proc. Priv. Enhancing Technol.6
2025 Gig Work at What Cost? Exploring Privacy Risks of Gig Work Platform Participation in the U.S
abstract
In recent years, "gig work" platforms have gained popularity as a way for individuals to earn money; as of 2021, 16% of Americans have at some point earned money from such platforms. Despite their popularity and their history of unfair data collection practices and worker safety, little is known about the data collected from workers (and users) by gig platforms and about the privacy dark pattern designs present in their apps. This paper presents an empirical measurement of 16 gig work platforms' data practices in the U.S. We analyze what data is collected by these platforms, and how it is shared and used. Finally, we consider how these practices constitute privacy dark patterns. To that end, we develop a novel combination of methods to address gig-worker-specific challenges in experimentation and data collection, enabling the largest in-depth study of such platforms to date. We find extensive data collection and sharing with 60 third parties—including sharing reversible hashes of worker Social Security Numbers (SSNs)—along with dark patterns that subject workers to greater privacy risk and opportunistically use collected data to nag workers in off-platform messages. We conclude this paper with proposed interdisciplinary mitigations for improving gig worker privacy protections. After we disclosed our SSN-related findings to affected platforms, the platforms confirmed that the issue had been mitigated. This is consistent with our independent audit of the affected platforms. Analysis code and redacted datasets will be made available to those who wish to reproduce our findings.
Amogh Pradeep, Johanna Gunawan, Álvaro Feal, Woodrow Hartzog, David R. Choffnes
Proc. Priv. Enhancing Technol.5
2024 Poster: Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE)
abstract
To transform cybersecurity and privacy research into a highly integrated, community-wide effort, researchers need a common, rich, representative research infrastructure that meets the needs across all members of the research community, and facilitates reproducible science. USC Information Sciences Institute and Northeastern University are meeting researcher needs, and have been funded by the NSF mid-scale research infrastructure program to build Security and Privacy Heterogeneous Environment for Reproducible Experimentation (SPHERE). SPHERE research infrastructure will offer access to an unprecedented variety of user-configurable hardware, software, and network resources, it will offer six user portals geared toward different populations of users, and it will support reproducible research via a combination of infrastructure services and community engagement activities.
Jelena Mirkovic, David M. Balenson, Brian Kocoloski, Geoff Lawler, Chris Tran, Joseph Barnes, Yuri Pradkin, Terry V. Benzel, Srivatsan Ravi, Ganesh Sankaran, Alba Regalado, David R. Choffnes, Daniel J. Dubois, Luis Garcia 0001
CCS12
2024 Fair or Fare? Understanding Automated Transcription Error Bias in Social Media and Videoconferencing Platforms
abstract
As remote work and learning increases in popularity, individuals, especially those with hearing impairments or who speak English as a second language, may depend on automated transcriptions to participate in business, school, entertainment, or basic communication. In this work, we investigate the automated transcription accuracy of seven popular social media and videoconferencing platforms with respect to some personal characteristics of their users, including gender, age, race, first language, speech rate, F0 frequency, and speech readability. We performed this investigation on a new corpus of 194 hours of English monologues by 846 TED talk speakers. Our results show the presence of significant bias, with transcripts less accurate for speakers that are male or non-native English speakers. We also observe differences in accuracy among platforms for different types of speakers. These results indicate that, while platforms have improved their automatic captioning, much work remains to make captions accessible for a wider variety of speakers and listeners.
Daniel J. Dubois, Nicole R. Holliday, Kaveh Waddell, David R. Choffnes
ICWSM4
2024 IoT Bricks Over v6: Understanding IPv6 Usage in Smart Homes
abstract
Recent years have seen growing interest and support for IPv6 in residential networks. While nearly all modern networking devices and operating systems support IPv6, it remains unclear how this basic support translates into higher-layer functionality, privacy, and security in consumer IoT devices. In this paper, we present the first comprehensive study of IPv6 usage in smart homes in a testbed equipped with 93 distinct, popular consumer IoT devices. We investigate whether and how they support and use IPv6, focusing on factors such as IPv6 addressing, configuration, DNS and destinations, and privacy and security practices.
Tianrui Hu, Daniel J. Dubois, David R. Choffnes
IMC3
2024 SunBlock: Cloudless Protection for IoT Systems
Vadim Safronov, Anna Maria Mandalari, Daniel J. Dubois, David R. Choffnes, Hamed Haddadi 0001
PAM (2)4
2023 Understanding Dark Patterns in Home IoT Devices
abstract
Internet-of-Things (IoT) devices are ubiquitous, but little attention has been paid to how they may incorporate dark patterns despite consumer protections and privacy concerns arising from their unique access to intimate spaces and always-on capabilities. This paper conducts a systematic investigation of dark patterns in 57 popular, diverse smart home devices. We update manual interaction and annotation methods for the IoT context, then analyze dark pattern frequency across device types, manufacturers, and interaction modalities. We find that dark patterns are pervasive in IoT experiences, but manifest in diverse ways across device traits. Speakers, doorbells, and camera devices contain the most dark patterns, with manufacturers of such devices (Amazon and Google) having the most dark patterns compared to other vendors. We investigate how this distribution impacts the potential for consumer exposure to dark patterns, discuss broader implications for key stakeholders like designers and regulators, and identify opportunities for future dark patterns study.
Monica Kowalczyk, Johanna Gunawan, David R. Choffnes, Daniel J. Dubois, Woodrow Hartzog, Christo Wilson
CHI3
2023 Behind the Scenes: Uncovering TLS and Server Certificate Practice of IoT Device Vendors in the Wild
abstract
IoT devices are increasingly used in consumer homes. Despite recent works in characterizing IoT TLS usage for a limited number of in-lab devices, there exists a gap in quantitatively understanding TLS behaviors from devices in the wild and server-side certificate management.
Hongying Dong, Yizhe Zhang 0006, Muhammad Talha Paracha, David R. Choffnes, Santiago Torres-Arias, Danny Yuxing Huang, Yixin Sun 0004
IMC6
2023 In the Room Where It Happens: Characterizing Local Communication and Threats in Smart Homes
abstract
The network communication between Internet of Things (IoT) devices on the same local network has significant implications for platform and device interoperability, security, privacy, and correctness. Yet, the analysis of local home Wi-Fi network traffic and its associated security and privacy threats have been largely ignored by prior literature, which typically focuses on studying the communication between IoT devices and cloud end-points, or detecting vulnerable IoT devices exposed to the Internet. In this paper, we present a comprehensive and empirical measurement study to shed light on the local communication within a smart home deployment and its threats. We use a unique combination of passive network traffic captures, protocol honeypots, dynamic mobile app analysis, and crowdsourced IoT data from participants to identify and analyze a wide range of device activities on the local network. We then analyze these datasets to characterize local network protocols, security and privacy threats associated with them. Our analysis reveals vulnerable devices, insecure use of network protocols, and sensitive data exposure by IoT devices. We provide evidence of how this information is exfiltrated to remote servers by mobile apps and third-party SDKs, potentially for household fingerprinting, surveillance and cross-device tracking. We make our datasets and analysis publicly available to support further research in this area.
Aniketh Girish, Tianrui Hu, Daniel J. Dubois, Srdjan Matic, Danny Yuxing Huang, Serge Egelman, Joel Reardon, Juan Tapiador, David R. Choffnes, Narseo Vallina-Rodriguez
IMC10
2023 BehavIoT: Measuring Smart Home IoT Behavior Using Network-Inferred Behavior Models
abstract
Smart home IoT platforms are typically closed systems, meaning that there is poor visibility into device behavior. Understanding device behavior is important not only for determining whether devices are functioning as expected, but also can reveal implications for privacy (e.g., surreptitious audio/video recording), security (e.g., device compromise), and safety (e.g., denial of service on a baby monitor). While there has been some work on identifying devices and a handful of activities, an open question is what is the extent to which we can automatically model the entire behavior of an IoT deployment, and how it changes over time, without any privileged access to IoT devices or platform messages.
Tianrui Hu, Daniel J. Dubois, David R. Choffnes
IMC3
2023 Tracking, Profiling, and Ad Targeting in the Alexa Echo Smart Speaker Ecosystem
abstract
Smart speakers collect voice commands, which can be used to infer sensitive information about users. Given the potential for privacy harms, there is a need for greater transparency and control over the data collected, used, and shared by smart speaker platforms as well as third party skills supported on them. To bridge this gap, we build a framework to measure data collection, usage, and sharing by the smart speaker platforms. We apply our framework to the Amazon smart speaker ecosystem. Our results show that Amazon and third parties, including advertising and tracking services that are unique to the smart speaker ecosystem, collect smart speaker interaction data. We also find that Amazon processes smart speaker interaction data to infer user interests and uses those inferences to serve targeted ads to users. Smart speaker interaction also leads to ad targeting and as much as 30X higher bids in ad auctions, from third party advertisers. Finally, we find that Amazon's and third party skills' data practices are often not clearly disclosed in their policy documents.
Umar Iqbal 0002, Pouneh Nikkhah Bahrami, Rahmadi Trimananda, Hao Cui 0004, Alexander Gamero-Garrido, Daniel J. Dubois, David R. Choffnes, Athina Markopoulou, Franziska Roesner, Zubair Shafiq
IMC7
2023 Localizing Traffic Differentiation
abstract
Network neutrality is important for users, content providers, policymakers, and regulators interested in understanding how network providers differentiate performance. When determining whether a network differentiates against certain traffic, it is important to have strong evidence, especially given that traffic differentiation is illegal in certain countries. In prior work, WeHe detects differentiation via end-to-end throughput measurements between a client and server but does not isolate the network responsible for it. Differentiation can occur anywhere on the network path between endpoints; thus, further evidence is needed to attribute differentiation to a specific network. We present a system, WeHeY, built atop WeHe, that can localize traffic differentiation, i.e., obtain concrete evidence that the differentiation happened within the client's ISP. Our system builds on ideas from network performance tomography; the challenge we solve is that TCP congestion control creates an adversarial environment for performance tomography (because it can significantly reduce the performance correlation on which tomography fundamentally relies). We evaluate our system via measurements "in the wild,'' as well as in emulated scenarios with a wide-area testbed; we further explore its limits via simulations and show that it accurately localizes traffic differentiation across a wide range of network conditions. WeHeY's source code is publicly available athttps://nal-epfl.github.io/WeHeY.
Zeinab Shmeiss, Pavlos Nikolopoulos, Katerina J. Argyraki, David R. Choffnes, Phillipa Gill
IMC5
2023 Protected or Porous: A Comparative Analysis of Threat Detection Capability of IoT Safeguards
abstract
Consumer Internet of Things (IoT) devices are increasingly common, from smart speakers to security cameras, in homes. Along with their benefits come potential privacy and security threats. To limit these threats a number of commercial services have become available (IoT safeguards). The safeguards claim to provide protection against IoT privacy risks and security threats. However, the effectiveness and the associated privacy risks of these safeguards remains a key open question. In this paper, we investigate the threat detection capabilities of IoT safeguards for the first time. We develop and release an approach for automated safeguards experimentation to reveal their response to common security threats and privacy risks. We perform thousands of automated experiments using popular commercial IoT safeguards when deployed in a large IoT testbed. Our results indicate not only that these devices may be ineffective in preventing risks, but also their cloud interactions and data collection operations may introduce privacy risks for the households that adopt them.
Anna Maria Mandalari, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes
SP4
2023 Not Your Average App: A Large-scale Privacy Analysis of Android Browsers
abstract
The transparency and privacy behavior of mobile browsers has remained widely unexplored by the research community. In fact, as opposed to regular Android apps, mobile browsers may present contradicting privacy behaviors. On the one end, they can have access to (and can expose) a unique combination of sensitive user data, from users’ browsing history to permission-protected personally identifiable information (PII) such as unique identifiers and geolocation. However, on the other end, they also are in a unique position to protect users’ privacy by limiting data sharing with other parties by implementing ad-blocking features. In this paper, we perform a comparative and empirical analysis on how hundreds of Android web browsers protect or expose user data during browsing sessions. To this end, we collect the largest dataset of Android browsers to date, from the Google Play Store and four Chinese app stores. Then, we developed a novel analysis pipeline that combines static and dynamic analysis methods to find a wide range of privacy-enhancing (e.g., ad-blocking) and privacy-harming behaviors (e.g., sending browsing histories to third parties, not validating TLS certificates, and exposing PII---including non-resettable identifiers---to third parties) across browsers. We find that various popular apps on both Google Play and Chinese stores have these privacy-harming behaviors, including apps that claim to be privacy-enhancing in their descriptions. Overall, our study not only provides new insights into important yet overlooked considerations for browsers’ adoption and transparency, but also that automatic app analysis systems (e.g., sandboxes) need context-specific analysis to reveal such privacy behaviors.
Amogh Pradeep, Álvaro Feal, Julien Gamba, Ashwin Rao, Martina Lindorfer, Narseo Vallina-Rodriguez, David R. Choffnes
Proc. Priv. Enhancing Technol.7
2022 ZLeaks: Passive Inference Attacks on Zigbee Based Smart Homes
Narmeen Shafqat, Daniel J. Dubois, David R. Choffnes, Aaron Schulman, Dinesh Bharadia, Aanjhan Ranganathan
ACNS3
2022 Using reverse IP geolocation to identify institutional networks
Alexander Gamero-Garrido, Elizabeth M. Belding, David R. Choffnes
IMC3
2022 A comparative analysis of certificate pinning in Android & iOS
abstract
TLS certificate pinning is a security mechanism used by applications (apps) to protect their network traffic against malicious certificate authorities (CAs), in-path monitoring, and other methods of TLS tampering. Pinning can provide enhanced security to defend against malicious third-party access to sensitive data in transit (e.g., to protect sensitive banking and health care information), but can also hide an app's personal data collection from users and auditors. Prior studies found pinning was rarely used in the Android ecosystem, except in high-profile, security-sensitive apps; and, little is known about its usage on iOS and across mobile platforms.
Amogh Pradeep, Muhammad Talha Paracha, Protick Bhowmick, Ali Davanian, Abbas Razaghpanah, Taejoong Chung, Martina Lindorfer, Narseo Vallina-Rodriguez, Dave Levin, David R. Choffnes
IMC10
2022 Internet scale reverse traceroute
abstract
Knowledge of Internet paths allows operators and researchers to better understand the Internet and troubleshoot problems. Paths are often asymmetric, so measuring just the forward path only gives partial visibility. Despite the existence of Reverse Traceroute, a technique that captures reverse paths (the sequence of routers traversed by traffic from an arbitrary, uncontrolled destination to a given source), this technique did not fulfill the needs of operators and the research community, as it had limited coverage, low throughput, and inconsistent accuracy. In this paper we design, implement and evaluate revtr 2.0, an Internet-scale Reverse Traceroute system that combines novel measurement approaches and studies with a large-scale deployment to improve throughput, accuracy, and coverage, enabling the first exploration of reverse paths at Internet scale. revtr 2.0 can run 15M reverse traceroutes in one day. This scale allows us to open the system to external sources and users, and supports tasks such as traffic engineering and troubleshooting.
Kevin Vermeulen, Ege Gürmeriçliler, Ítalo S. Cunha, David R. Choffnes, Ethan Katz-Bassett
IMC4
2022 Moby: A Blackout-Resistant Anonymity Network for Mobile Devices
abstract
Internet blackouts are challenging environments for anonymity and censorship resistance. Existing popular anonymity networks (e.g., Freenet, I2P, Tor) rely on Internet connectivity to function, making them impracticable during such blackouts. In such a setting, mobile ad-hoc networks can provide connectivity, but prior communication protocols for ad-hoc networks are not designed for anonymity and attack resilience. We address this need by designing, implementing, and evaluating Moby, a blackout-resistant anonymity network for mobile devices. Moby provides end-to-end encryption, forward secrecy and sender-receiver anonymity. It features a bi-modal design of operation, using Internet connectivity when available and ad-hoc networks during blackouts. During periods of Internet connectivity, Moby functions as a regular messaging application and bootstraps information that is later used in the absence of Internet connectivity to achieve secure anonymous communications. Moby incorporates a model of trust based on users’ contact lists, and a trust establishment protocol that mitigates flooding attacks. We perform an empirically informed simulation-based study based on cellphone traces of 268,596 users over the span of a week for a large cellular provider to determine Moby’s feasibility and present our findings. Last, we implement and evaluate the Moby client as an Android app.
Amogh Pradeep, Hira Javaid, Antoine Rault, David R. Choffnes, Stevens Le Blond, Bryan Ford
Proc. Priv. Enhancing Technol.5
2021 SoK: Attacks on Industrial Control Logic and Formal Verification-Based Defenses
abstract
Programmable Logic Controllers (PLCs) play a critical role in the industrial control systems. Vulnerabilities in PLC programs might lead to attacks causing devastating consequences to the critical infrastructure, as shown in Stuxnet and similar attacks. In recent years, we have seen an exponential increase in vulnerabilities reported for PLC control logic. Looking back on past research, we found extensive studies explored control logic modification attacks, as well as formal verification-based security solutions. We performed systematization on these studies, and found attacks that can compromise a full chain of control and evade detection. However, the majority of the formal verification research investigated ad-hoc techniques targeting PLC programs. We discovered challenges in every aspect of formal verification, rising from (1) the ever-expanding attack surface from evolved system design, (2) the real-time constraint during the program execution, and (3) the barrier in security evaluation given proprietary and vendor-specific dependencies on different techniques. Based on the knowledge systematization, we provide a set of recommendations for future research directions, and we highlight the need of defending security issues besides safety issues.
Ruimin Sun, Alejandro Mera, Long Lu, David R. Choffnes
EuroS&P4
2021 IoTLS: understanding TLS usage in consumer IoT devices
abstract
Consumer IoT devices are becoming increasingly popular, with most leveraging TLS to provide connection security. In this work, we study a large number of TLS-enabled consumer IoT devices to shed light on how effectively they use TLS, in terms of establishing secure connections and correctly validating certificates, and how observed behavior changes over time. To this end, we gather more than two years of TLS network traffic from IoT devices, conduct active probing to test for vulnerabilities, and develop a novel blackbox technique for exploring the trusted root stores in IoT devices by exploiting a side-channel through TLS Alert Messages. We find a wide range of behaviors across devices, with some adopting best security practices but most being vulnerable in one or more of the following ways: use of old/insecure protocol versions and/or ciphersuites, lack of certificate validation, and poor maintenance of root stores. Specifically, we find that at least 8 IoT devices still include distrusted certificates in their root stores, 11/32 devices are vulnerable to TLS interception attacks, and that many devices fail to adopt modern protocol features over time. Our findings motivate the need for IoT manufacturers to audit, upgrade, and maintain their devices' TLS implementations in a consistent and uniform way that safeguards all of their network traffic.
Muhammad Talha Paracha, Daniel J. Dubois, Narseo Vallina-Rodriguez, David R. Choffnes
Internet Measurement Conference4
2021 AnyOpt: predicting and optimizing IP Anycast performance
abstract
The key to optimizing the performance of an anycast-based system (e.g., the root DNS or a CDN) is choosing the right set of sites to announce the anycast prefix. One challenge here is predicting catchments. A naïve approach is to advertise the prefix from all subsets of available sites and choose the best-performing subset, but this does not scale well. We demonstrate that by conducting pairwise experiments between sites peering with tier-1 networks, we can predict the catchments that would result if we announce to any subset of the sites. We prove that our method is effective in a simplified model of BGP, consistent with common BGP routing policies, and evaluate it in a real-world testbed. We then present AnyOpt, a system that predicts anycast catchments. Using AnyOpt, a network operator can find a subset of anycast sites that minimizes client latency without using the naïve approach. In an experiment using 15 sites, each peering with one of six transit providers, AnyOpt predicted site catchments of 15,300 clients with 94.7% accuracy and client RTTs with a mean error of 4.6%. AnyOpt identified a subset of 12 sites, announcing to which lowers the mean RTT to clients by 33ms compared to a greedy approach that enables the same number of sites with the lowest average unicast latency.
Tanmoy Sen, Tim April, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Bruce M. Maggs, Haiying Shen, Ramesh K. Sitaraman, Xiaowei Yang 0001
SIGCOMM6
2021 A Comparative Study of Dark Patterns Across Web and Mobile Modalities
abstract
Dark patterns are user interface elements that can influence a person's behavior against their intentions or best interests. Prior work identified these patterns in websites and mobile apps, but little is known about how the design of platforms might impact dark pattern manifestations and related human vulnerabilities. In this paper, we conduct a comparative study of mobile application, mobile browser, and web browser versions of 105 popular services to investigate variations in dark patterns across modalities. We perform manual tests, identify dark patterns in each service, and examine how they persist or differ by modality. Our findings show that while services can employ some dark patterns equally across modalities, many dark patterns vary between platforms, and that these differences saddle people with inconsistent experiences of autonomy, privacy, and control. We conclude by discussing broader implications for policymakers and practitioners, and provide suggestions for furthering dark patterns research.
Johanna Gunawan, Amogh Pradeep, David R. Choffnes, Woodrow Hartzog, Christo Wilson
Proc. ACM Hum. Comput. Interact.3
2021 Blocking Without Breaking: Identification and Mitigation of Non-Essential IoT Traffic
abstract
Abstract Despite the prevalence of Internet of Things (IoT) devices, there is little information about the purpose and risks of the Internet traffic these devices generate, and consumers have limited options for controlling those risks. A key open question is whether one can mitigate these risks by automatically blocking some of the Internet connections from IoT devices, without rendering the devices inoperable. In this paper, we address this question by developing a rigorous methodology that relies on automated IoT-device experimentation to reveal which network connections (and the information they expose) are essential, and which are not. We further develop strategies to automatically classify network traffic destinations as either required (i.e., their traffic is essential for devices to work properly) or not, hence allowing firewall rules to block traffic sent to non-required destinations without breaking the functionality of the device. We find that indeed 16 among the 31 devices we tested have at least one blockable non-required destination, with the maximum number of blockable destinations for a device being 11. We further analyze the destination of network traffic and find that all third parties observed in our experiments are blockable, while first and support parties are neither uniformly required or non-required. Finally, we demonstrate the limitations of existing blocklists on IoT traffic, propose a set of guidelines for automatically limiting non-essential IoT traffic, and we develop a prototype system that implements these guidelines.
Anna Maria Mandalari, Daniel J. Dubois, Roman Kolcun, Muhammad Talha Paracha, Hamed Haddadi 0001, David R. Choffnes
Proc. Priv. Enhancing Technol.6
2020 A Haystack Full of Needles: Scalable Detection of IoT Devices in the Wild
abstract
Consumer Internet of Things (IoT) devices are extremely popular, providing users with rich and diverse functionalities, from voice assistants to home appliances. These functionalities often come with significant privacy and security risks, with notable recent large-scale coordinated global attacks disrupting large service providers. Thus, an important first step to address these risks is to know what IoT devices are where in a network. While some limited solutions exist, a key question is whether device discovery can be done by Internet service providers that only see sampled flow statistics. In particular, it is challenging for an ISP to efficiently and effectively track and trace activity from IoT devices deployed by its millions of subscribers---all with sampled network data.
Said Jawad Saidi, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001, Daniel J. Dubois, David R. Choffnes, Georgios Smaragdakis, Anja Feldmann
Internet Measurement Conference6
2020 FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network Traffic
Thijs van Ede, Riccardo Bortolameotti, Andrea Continella, Daniel J. Dubois, Martina Lindorfer, David R. Choffnes, Maarten van Steen, Andreas Peter 0001
NDSS7
2020 aBBRate: Automating BBR Attack Exploration Using a Model-Based Approach
Anthony Peterson, Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Cristina Nita-Rotaru
RAID4
2020 When Speakers Are All Ears: Characterizing Misactivations of IoT Smart Speakers
abstract
Abstract Internet-connected voice-controlled speakers, also known as smart speakers, are increasingly popular due to their convenience for everyday tasks such as asking about the weather forecast or playing music. However, such convenience comes with privacy risks: smart speakers need to constantly listen in order to activate when the “wake word” is spoken, and are known to transmit audio from their environment and record it on cloud servers. In particular, this paper focuses on the privacy risk from smart speaker misactivations, i.e., when they activate, transmit, and/or record audio from their environment when the wake word is not spoken. To enable repeatable, scalable experiments for exposing smart speakers to conversations that do not contain wake words, we turn to playing audio from popular TV shows from diverse genres. After playing two rounds of 134 hours of content from 12 TV shows near popular smart speakers in both the US and in the UK, we observed cases of 0.95 misactivations per hour, or 1.43 times for every 10,000 words spoken, with some devices having 10% of their misactivation durations lasting at least 10 seconds. We characterize the sources of such misactivations and their implications for consumers, and discuss potential mitigations.
Daniel J. Dubois, Roman Kolcun, Anna Maria Mandalari, Muhammad Talha Paracha, David R. Choffnes, Hamed Haddadi 0001
Proc. Priv. Enhancing Technol.5
2019 RPKI is Coming of Age: A Longitudinal Study of RPKI Deployment and Invalid Route Origins
abstract
Despite its critical role in Internet connectivity, the Border Gateway Protocol (BGP) remains highly vulnerable to attacks such as prefix hijacking, where an Autonomous System (AS) announces routes for IP space it does not control. To address this issue, the Resource Public Key Infrastructure (RPKI) was developed starting in 2008, with deployment beginning in 2011. This paper performs the first comprehensive, longitudinal study of the deployment, coverage, and quality of RPKI. We use a unique dataset containing all RPKI Route Origin Authorizations (ROAs) from the moment RPKI was first deployed, more than 8 years ago. We combine this dataset with BGP announcements from more than 3,300 BGP collectors worldwide. Our analysis shows the after a gradual start, RPKI has seen a rapid increase in adoption over the past two years. We also show that although misconfigurations were rampant when RPKI was first deployed (causing many announcements to appear as invalid) they are quite rare today. We develop a taxonomy of invalid RPKI announcements, then quantify their prevalence. We further identify suspicious announcements indicative of prefix hijacking and present case studies of likely hijacks. Overall, we conclude that while misconfigurations still do occur, RPKI is "ready for the big screen," and routing security can be increased by dropping invalid announcements. To foster reproducibility and further studies, we release all RPKI data and the tools we used to analyze it into the public domain.
Taejoong Chung, Emile Aben, Tim Bruijnzeels, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Roland van Rijswijk-Deij, John P. Rula, Nick Sullivan
Internet Measurement Conference5
2019 Information Exposure From Consumer IoT Devices: A Multidimensional, Network-Informed Measurement Approach
abstract
Internet of Things (IoT) devices are increasingly found in everyday homes, providing useful functionality for devices such as TVs, smart speakers, and video doorbells. Along with their benefits come potential privacy risks, since these devices can communicate information about their users to other parties over the Internet. However, understanding these risks in depth and at scale is difficult due to heterogeneity in devices' user interfaces, protocols, and functionality.
Daniel J. Dubois, David R. Choffnes, Anna Maria Mandalari, Roman Kolcun, Hamed Haddadi 0001
Internet Measurement Conference3
2019 Internet-QoE 2019: 4th Internet-QoE Workshop on QoE-based Analysis and Management of Data Communication Networks
abstract
After three highly successful editions of the Internet-QoE workshop organized at ACM SIGCOMM 2016, ACM SIGCOMM 2017, and IEEE ICDCS 2018, the goal of the fourth edition of the Internet-QoE workshop is to scale the concepts of Quality of Experience (user satisfaction, user engagement, and behavioral analysis) out of the lab studies context and bring it to the analysis and operation of distributed systems and communication networks, giving a user-centric perspective to the research performed by the MOBICOM community. By fostering an explicit and deep integration of the end-user directly into the design, analysis and management of large-scale operational networks, we expect to reduce the gap between QoE research and its application to future network management paradigms, as well as to provide a more targeted end-user perspective to the research on distributed communication systems. The 4th edition of Internet-QoE also focuses on novel end-user services enabled by next generation technologies such as immersive media (3D, Virtual Reality and Augmented Reality), self-driving cars, intelligent manufacturing systems, Industry 4.0 and tactile Internet, 5G ultra-low-latency mobile networks, and real-time applications.
Pedro Casas, Florian Wamser, Fabián E. Bustamante, David R. Choffnes
MobiCom4
2019 A large-scale analysis of deployed traffic differentiation practices
abstract
Net neutrality has been the subject of considerable public debate over the past decade. Despite the potential impact on content providers and users, there is currently a lack of tools or data for stakeholders to independently audit the net neutrality policies of network providers. In this work, we address this issue by conducting a one-year study of content-based traffic differentiation policies deployed in operational networks, using results from 1,045,413 crowdsourced measurements conducted by 126,249 users across 2,735 ISPs in 183 countries/regions. We develop and evaluate a methodology that combines individual per-device measurements to form high-confidence, statistically significant inferences of differentiation practices, including fixed-rate bandwidth limits (i.e., throttling) and delayed throttling practices. Using this approach, we identify differentiation in both cellular and WiFi networks, comprising 30 ISPs in 7 countries. We also investigate the impact of throttling practices on video streaming resolution for several popular video streaming providers.
Fangfan Li, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove
SIGCOMM3
2019 Janus: A Multi-TCP Framework for Application-Aware Optimization in Mobile Networks
abstract
As the dominant protocol on the Internet, TCP has attracted significant attention and has been implemented in various ways, each of which optimizes for a single objective such as high throughput or low delay. However, in today's mobile networks that carry traffic from diverse types of flows, this approach may lead to misconfiguration of TCP congestion control algorithms and further degrade performance for many applications. In this paper, we propose Janus, a new transport-layer framework that automatically selects among existing congestion control variants to optimize traffic in accordance with application demands. Janus is easy to deploy because it reuses existing, well-tested congestion control implementations, and does not require any in-network or client-side changes. To explore the potential for this approach, we implement Janus in the Linux kernel and extensively evaluate its performance with both emulated and real Internet traffic. We show Janus outperforms alternative protocols by offering fast convergence times in response to changing network conditions, achieving 5-10X lower delay with comparable or higher throughput. Our approach also significantly improves user-perceived performance according to QoE metrics, with up to 5X fewer interruptions for video streaming applications and 2X faster page loading for web-browsing applications.
Fan Zhou 0008, David R. Choffnes, Kaushik R. Chowdhury
IEEE Trans. Mob. Comput.2
2018 Is the Web Ready for OCSP Must-Staple?
Taejoong Chung, Jay Lok, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, John P. Rula, Nick Sullivan, Christo Wilson
Internet Measurement Conference4
2018 Automated Attack Discovery in TCP Congestion Control Using a Model-guided Approach
Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove, Cristina Nita-Rotaru
NDSS3
2018 Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App Versions
Martina Lindorfer, Daniel J. Dubois, Ashwin Rao, David R. Choffnes, Narseo Vallina-Rodriguez
NDSS5
2018 Mile High WiFi: A First Look At In-Flight Internet Connectivity
abstract
In-Flight Communication (IFC), available on a growing number of commercial flights, is often received by consumers with both awe for its mere availability and harsh criticism for its poor performance. Indeed, IFC provides Internet connectivity in some of the most challenging conditions with aircraft traveling at speeds in excess of 500 mph at 30,000 feet above the ground. Yet, while existing services do provide basic Internet \em accessibility, anecdotal reports rank their quality of service as, at best, poor. In this paper, we present the first characterization of deployed IFC systems. Using over 45 flight-hours of measurements, we profile the performance of IFC across the two dominant access technologies -- direct air-to-ground communication (DA2GC) and mobile satellite service (MSS). We show that IFC QoS is in large part determined by the high latencies inherent to DA2GC and MSS, with RTTs averaging 200ms and 750ms, respectively, and that these high latencies directly impact the performance of common applications such as web browsing. While each IFC technology is based on well studied wireless communication technologies, our findings reveal that IFC links experience further degraded link performance than their technological antecedents. We find median loss rates of 7%, and nearly 40% loss at the 90th percentile for MSS, 6.8x larger than recent characterizations of residential satellite networks. We extend our IFC study exploring the potential of the newly released HTTP/2 and QUIC protocols in an emulated IFC environment, finding that QUIC is able to improve page load times by as much as 7.9 times. In addition, we find that HTTP/2»s use of multiplexing multiple requests onto a single TCP connection performs up to 4.8x \em worse than HTTP/1.1 when faced with large numbers of objects. We use network emulation to explore proposed technological improvements to existing IFC systems finding that high link losses, and not bandwidth, account for the largest factor of performance degradation with applications such as web browsing.
John P. Rula, James Newman, Fabián E. Bustamante, Arash Molavi Kakhki, David R. Choffnes
WWW5
2018 Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications
abstract
Abstract The high-fidelity sensors and ubiquitous internet connectivity offered by mobile devices have facilitated an explosion in mobile apps that rely on multimedia features. However, these sensors can also be used in ways that may violate user’s expectations and personal privacy. For example, apps have been caught taking pictures without the user’s knowledge and passively listened for inaudible, ultrasonic audio beacons. The developers of mobile device operating systems recognize that sensor data is sensitive, but unfortunately existing permission models only mitigate some of the privacy concerns surrounding multimedia data. In this work, we present the first large-scale empirical study of media permissions and leaks from Android apps, covering 17,260 apps from Google Play, AppChina, Mi.com, and Anzhi. We study the behavior of these apps using a combination of static and dynamic analysis techniques. Our study reveals several alarming privacy risks in the Android app ecosystem, including apps that over-provision their media permissions and apps that share image and video data with other parties in unexpected ways, without user knowledge or consent. We also identify a previously unreported privacy risk that arises from third-party libraries that record and upload screenshots and videos of the screen without informing the user and without requiring any permissions.
Elleen Pan, Martina Lindorfer, Christo Wilson, David R. Choffnes
Proc. Priv. Enhancing Technol.5
2017 Understanding the role of registrars in DNSSEC deployment
abstract
The Domain Name System (DNS) provides a scalable, flexible name resolution service. Unfortunately, its unauthenticated architecture has become the basis for many security attacks. To address this, DNS Security Extensions (DNSSEC) were introduced in 1997. DNSSEC's deployment requires support from the top-level domain (TLD) registries and registrars, as well as participation by the organization that serves as the DNS operator. Unfortunately, DNSSEC has seen poor deployment thus far: despite being proposed nearly two decades ago, only 1% of .com, .net, and .org domains are properly signed.
Taejoong Chung, Roland van Rijswijk-Deij, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
Internet Measurement Conference3
2017 The record route option is an option!
abstract
The IPv4 Record Route (RR) Option instructs routers to record their IP addresses in a packet. RR is subject to a nine hop limit and, traditionally, inconsistent support from routers. Recent changes in interdomain connectivity---the so-called "flattening Internet"---and new best practices for how routers should handle RR packets suggest that now is a good time to reassess the potential of the RR Option.
Brian J. Goodchild, Yi-Ching Chiu, Rob Hansen, Haonan Lu, Matt Calder, Matthew J. Luckie, Wyatt Lloyd, David R. Choffnes, Ethan Katz-Bassett
Internet Measurement Conference8
2017 Taking a long look at QUIC: an approach for rigorous evaluation of rapidly evolving transport protocols
abstract
Google's QUIC protocol, which implements TCP-like properties at the application layer atop a UDP transport, is now used by the vast majority of Chrome clients accessing Google properties but has no formal state machine specification, limited analysis, and ad-hoc evaluations based on snapshots of the protocol implementation in a small number of environments. Further frustrating attempts to evaluate QUIC is the fact that the protocol is under rapid development, with extensive rewriting of the protocol occurring over the scale of months, making individual studies of the protocol obsolete before publication.
Arash Molavi Kakhki, Samuel Jero, David R. Choffnes, Cristina Nita-Rotaru, Alan Mislove
Internet Measurement Conference3
2017 lib•erate, (n): a library for exposing (traffic-classification) rules and avoiding them efficiently
abstract
Middleboxes implement a variety of network management policies (e.g., prioritizing or blocking traffic) in their networks. While such policies can be beneficial (e.g., blocking malware) they also raise issues of network neutrality and freedom of speech when used for application-specific differentiation and censorship. There is a poor understanding of how such policies are implemented in practice, and how they can be evaded efficiently. As a result, most circumvention solutions are brittle, point solutions based on manual analysis.
Fangfan Li, Abbas Razaghpanah, Arash Molavi Kakhki, Arian Akhavan Niaki, David R. Choffnes, Phillipa Gill, Alan Mislove
Internet Measurement Conference5
2017 A Broad View of the Ecosystem of Socially Engineered Exploit Documents
Stevens Le Blond, Cédric Gilbert, Utkarsh Upadhyay, Manuel Gomez-Rodriguez, David R. Choffnes
NDSS5
2017 CRLite: A Scalable System for Pushing All TLS Revocations to All Browsers
abstract
Currently, no major browser fully checks for TLS/SSL certificate revocations. This is largely due to the fact that the deployed mechanisms for disseminating revocations (CRLs, OCSP, OCSP Stapling, CRLSet, and OneCRL) are each either incomplete, insecure, inefficient, slow to update, not private, or some combination thereof. In this paper, we present CRLite, an efficient and easily-deployable system for proactively pushing all TLS certificate revocations to browsers. CRLite servers aggregate revocation information for all known, valid TLS certificates on the web, and store them in a space-efficient filter cascade data structure. Browsers periodically download and use this data to check for revocations of observed certificates in real-time. CRLite does not require any additional trust beyond the existing PKI, and it allows clients to adopt a fail-closed security posture even in the face of network errors or attacks that make revocation information temporarily unavailable. We present a prototype of name that processes TLS certificates gathered by Rapid7, the University of Michigan, and Google's Certificate Transparency on the server-side, with a Firefox extension on the client-side. Comparing CRLite to an idealized browser that performs correct CRL/OCSP checking, we show that CRLite reduces latency and eliminates privacy concerns. Moreover, CRLite has low bandwidth costs: it can represent all certificates with an initial download of 10 MB (less than 1 byte per revocation) followed by daily updates of 580 KB on average. Taken together, our results demonstrate that complete TLS/SSL revocation checking is within reach for all clients.
James Larisch, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
IEEE Symposium on Security and Privacy2
2017 A Longitudinal, End-to-End View of the DNSSEC Ecosystem
Taejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
USENIX Security Symposium4
2016 Measurement and Analysis of Private Key Sharing in the HTTPS Ecosystem
abstract
The semantics of online authentication in the web are rather straightforward: if Alice has a certificate binding Bob's name to a public key, and if a remote entity can prove knowledge of Bob's private key, then (barring key compromise) that remote entity must be Bob. However, in reality, many websites' and the majority of the most popular ones-are hosted at least in part by third parties such as Content Delivery Networks (CDNs) or web hosting providers. Put simply: administrators of websites who deal with (extremely) sensitive user data are giving their private keys to third parties. Importantly, this sharing of keys is undetectable by most users, and widely unknown even among researchers. In this paper, we perform a large-scale measurement study of key sharing in today's web. We analyze the prevalence with which websites trust third-party hosting providers with their secret keys, as well as the impact that this trust has on responsible key management practices, such as revocation. Our results reveal that key sharing is extremely common, with a small handful of hosting providers having keys from the majority of the most popular websites. We also find that hosting providers often manage their customers' keys, and that they tend to react more slowly yet more thoroughly to compromised or potentially compromised keys.
Frank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
CCS3
2016 A Case for Personal Virtual Networks
abstract
Our mobile devices regularly encounter and connect to multiple networks to maintain seamless connectivity. While this enables a variety of services we increasingly rely on, these ubiquitous network connections raise a number of important concerns. Our devices regularly send traffic over networks they do not fully trust and that are not under user control, which leads to security vulnerabilities, policies that impact performance and service availability, and privacy violations.
David R. Choffnes
HotNets1
2016 Tunneling for Transparency: A Large-Scale Analysis of End-to-End Violations in the Internet
Taejoong Chung, David R. Choffnes, Alan Mislove
Internet Measurement Conference2
2016 Measuring and Applying Invalid SSL Certificates: The Silent Majority
Taejoong Chung, Yabing Liu, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson
Internet Measurement Conference3
2016 Should You Use the App for That?: Comparing the Privacy Implications of App- and Web-based Online Services
Christophe Leung, David R. Choffnes, Christo Wilson
Internet Measurement Conference3
2016 Classifiers Unclassified: An Efficient Approach to Revealing IP Traffic Classification Rules
Fangfan Li, Arash Molavi Kakhki, David R. Choffnes, Phillipa Gill, Alan Mislove
Internet Measurement Conference3
2016 On the Free Bridge Across the Digital Divide: Assessing the Quality of Facebook's Free Basics Service
Rijurekha Sen, Hasnain Ali Pirzada, Amreesh Phokeer, Zaid Ahmed Farooq, Satadal Sengupta, David R. Choffnes, Krishna P. Gummadi
Internet Measurement Conference6
2016 ReCon: Revealing and Controlling PII Leaks in Mobile Network Traffic
abstract
It is well known that apps running on mobile devices extensively track and leak users' personally identifiable information (PII); however, these users have little visibility into PII leaked through the network traffic generated by their devices, and have poor control over how, when and where that traffic is sent and handled by third parties. In this paper, we present the design, implementation, and evaluation of ReCon: a cross-platform system that reveals PII leaks and gives users control over them without requiring any special privileges or custom OSes. ReCon leverages machine learning to reveal potential PII leaks by inspecting network traffic, and provides a visualization tool to empower users with the ability to control these leaks via blocking or substitution of PII. We evaluate ReCon's effectiveness with measurements from controlled experiments using leaks from the 100 most popular iOS, Android, and Windows Phone apps, and via an IRB-approved user study with 92 participants. We show that ReCon is accurate, efficient, and identifies a wider range of PII than previous approaches.
Ashwin Rao, Martina Lindorfer, Arnaud Legout, David R. Choffnes
MobiSys5
2016 Machine learning, data mining and Big Data frameworks for network monitoring and troubleshooting
Alessandro D'Alconzo, Pere Barlet-Ros, Kensuke Fukuda, David R. Choffnes
Comput. Networks4
2015 Investigating Interdomain Routing Policies in the Wild
abstract
Models of Internet routing are critical for studies of Internet security, reliability and evolution, which often rely on simulations of the Internet's routing system. Accurate models are difficult to build and suffer from a dearth of ground truth data, as ISPs often treat their connectivity and routing policies as trade secrets. In this environment, researchers rely on a number of simplifying assumptions and models proposed over a decade ago, which are widely criticized for their inability to capture routing policies employed in practice.
Ruwaifa Anwar, Haseeb Niaz, David R. Choffnes, Ítalo S. Cunha, Phillipa Gill, Ethan Katz-Bassett
Internet Measurement Conference3
2015 Identifying Traffic Differentiation in Mobile Networks
abstract
Traffic differentiation---giving better (or worse) performance to certain classes of Internet traffic---is a well-known but poorly understood traffic management policy. There is active discussion on whether and how ISPs should be allowed to differentiate Internet traffic, but little data about current practices to inform this discussion. Previous work attempted to address this problem for fixed line networks; however, there is currently no solution that works in the more challenging mobile environment.
Arash Molavi Kakhki, Abbas Razaghpanah, Anke Li, Hyungjoon Koo, Rajesh Golani, David R. Choffnes, Phillipa Gill, Alan Mislove
Internet Measurement Conference6
2015 An End-to-End Measurement of Certificate Revocation in the Web's PKI
abstract
Critical to the security of any public key infrastructure (PKI) is the ability to revoke previously issued certificates. While the overall SSL ecosystem is well-studied, the frequency with which certificates are revoked and the circumstances under which clients (e.g., browsers) check whether certificates are revoked are still not well-understood.
Yabing Liu, Will Tome, Liang Zhang 0022, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Aaron Schulman, Christo Wilson
Internet Measurement Conference4
2015 Mobilyzer: An Open Platform for Controllable Mobile Network Measurements
abstract
Mobile Internet availability, performance and reliability have remained stubbornly opaque since the rise of cellular data access. Conducting network measurements can give us insight into user-perceived network conditions, but doing so requires careful consideration of device state and efficient use of scarce resources. Existing approaches address these concerns in ad-hoc ways.
Ashkan Nikravesh, Hongyi Yao, Shichang Xu, David R. Choffnes, Z. Morley Mao
MobiSys4
2015 Demo: Mobilyzer: Mobile Network Measurement Made Easy
abstract
No abstract available.
Shichang Xu, Ashkan Nikravesh, Hongyi Yao, David R. Choffnes, Z. Morley Mao
MobiSys4
2015 Poster: Context-Triggered Mobile Network Measurement
abstract
While the availability and accessibility of cellular network connectivity have improved in recent years, our ability to diagnose and debug network problems in this environment has not. One key challenge is that many of the network problems occur near the edge of the network where only mobile devices can perceive them, but network and battery resources to conduct measurements from these mobile devices are scarce. Traditional network measurement approaches that use continuous, periodic, or random measurements are either infeasible or ineffective in this environment.
Shichang Xu, Ashkan Nikravesh, Hongyi Yao, David R. Choffnes, Z. Morley Mao
MobiSys4
2015 Investigating Transparent Web Proxies in Cellular Networks
Yurong Jiang, Tobias Flach, Ethan Katz-Bassett, David R. Choffnes, Ramesh Govindan
PAM5
2015 Herd: A Scalable, Traffic Analysis Resistant Anonymity Network for VoIP Systems
abstract
Effectively anonymizing Voice-over-IP (VoIP) calls requires a scalable anonymity network that is resilient to traffic analysis and has sufficiently low delay for high-quality voice calls. The popular Tor anonymity network, for instance, is not designed for the former and cannot typically achieve the latter. In this paper, we present the design, implementation, and experimental evaluation of Herd, an anonymity network where a set of dedicated, fully interconnected cloud-based proxies yield suitably low-delay circuits, while untrusted superpeers add scalability. Herd provides caller/callee anonymity among the clients within a trust zone (e.g., jurisdiction) and under a strong adversarial model. Simulations based on a trace of 370 million mobile phone calls among 10.8 million users indicate that Herd achieves anonymity among millions of clients with low bandwidth requirements, and that superpeers decrease the bandwidth and CPU requirements of the trusted infrastructure by an order of magnitude. Finally, experiments using a prototype deployment on Amazon EC2 show that Herd has a delay low enough for high-quality calls in most cases.
Stevens Le Blond, David R. Choffnes, William Caldwell, Peter Druschel, Nicholas Merritt
SIGCOMM2
2015 A Measurement Experimentation Platform at the Internet's Edge
abstract
Poor visibility into the network hampers progress in a number of important research areas, from network troubleshooting to Internet topology and performance mapping. This persistent, well-known problem has served as motivation for numerous proposals to build or extend existing Internet measurement platforms by recruiting larger, more diverse vantage points. Capturing the edge of the network, however, remains an elusive goal. We argue that at its root the problem is one of incentives. Today's measurement platforms build on the assumption that the goals of experimenters and those hosting the platform are the same. As much of the Internet growth occurs in residential broadband networks, this assumption no longer holds. We present a measurement experimentation platform that reaches the network edge by explicitly aligning the objectives of the experimenters with those of the users hosting the platform. Dasu-our current prototype-is designed to support both network measurement experimentation and broadband characterization. Dasu has been publicly available since July 2010 and has been installed by over 100 000 users with a heterogeneous set of connections spreading across 2431 autonomous systems (ASs) and 166 countries. We discuss some of the challenges we faced building and using a platform for the Internet's edge, describe its design and implementation, and illustrate the unique perspective its current deployment brings to Internet measurement.
Mario A. Sánchez, John S. Otto, Zachary S. Bischof, David R. Choffnes, Fabián E. Bustamante, Balachander Krishnamurthy, Walter Willinger
IEEE/ACM Trans. Netw.4
2014 Analysis of SSL certificate reissues and revocations in the wake of heartbleed
abstract
Central to the secure operation of a public key infrastructure (PKI) is the ability to revoke certificates. While much of users' security rests on this process taking place quickly, in practice, revocation typically requires a human to decide to reissue a new certificate and revoke the old one. Thus, having a proper understanding of how often systems administrators reissue and revoke certificates is crucial to understanding the integrity of a PKI. Unfortunately, this is typically difficult to measure: while it is relatively easy to determine when a certificate is revoked, it is difficult to determine whether and when an administrator should have revoked.
Liang Zhang 0022, David R. Choffnes, Dave Levin, Tudor Dumitras, Alan Mislove, Aaron Schulman, Christo Wilson
Internet Measurement Conference2
2014 Demo: Mapping global mobile performance trends with mobilyzer and mobiPerf
abstract
Mobilyzer is an open-source network measurement library that coordinates network measurement tasks among different applications, facilitates measurement task design, and allows for more effective measurement task management than in existing standalone approaches. Unifying various network tasks into one framework greatly simplifies the problem of developing, deploying and managing measurement tasks which may otherwise interfere with one another. An intelligent scheduler, coordinated by a central server, dynamically schedules tasks to run in the background, preserving the user's battery life and respecting limits set by the user on task frequency and data consumption. We will demo MobiPerf, an open-source mobile network measurement tool built using the Mobilyzer library. MobiPerf collects a wide range of network performance data, ranging from the latency and throughput measurements common in existing client-based measurement frameworks, to HTTP loading times for specific URLs, to inferring RRC state configuration parameters and their impact on performance. We will also demo an interface for viewing a large, open dataset of performance data from around the world collected by MobiPerf.
Sanae Rosen, Hongyi Yao, Ashkan Nikravesh, Yunhan Jia, David R. Choffnes, Z. Morley Mao
MobiSys5
2014 Mobile Network Performance from User Devices: A Longitudinal, Multidimensional Analysis
Ashkan Nikravesh, David R. Choffnes, Ethan Katz-Bassett, Z. Morley Mao, Matt Welsh
PAM2
2014 Diagnosing Path Inflation of Mobile Client Traffic
Kyriakos Zarifis, Tobias Flach, Srikanth Nori, David R. Choffnes, Ramesh Govindan, Ethan Katz-Bassett, Z. Morley Mao, Matt Welsh
PAM4
2014 Identifying traffic differentiation on cellular data networks
abstract
The goal of this research is to detect traffic differentiation in cellular data networks. We define service differentiation as any attempt to change the performance of network traffic traversing an ISP's boundaries. ISPs may implement differentiation policies for a number of reasons, including load balancing, bandwidth management, or business reasons. Specifically, we focus on detecting whether certain types of network traffic receive better (or worse) performance. As an example, a wireless provider might limit the performance of third-party VoIP or video calling services (or any other competing services) by introducing delays or reducing transfer rates to encourage users to use services provided by the wireless provider. Previous work explored this problem in limited environments. Glasnost focused on BitTorrent in the desktop/laptop environment, and lacked the ability to conduct controlled experiments to provide strong evidence of differentiation. NetDiff covered a wide range of passively gathered traffic from a large ISP but likewise did not support targeted, controlled experiments. We address these limitations with Mobile Replay.
Arash Molavi Kakhki, Abbas Razaghpanah, Rajesh Golani, David R. Choffnes, Phillipa Gill, Alan Mislove
SIGCOMM4
2014 Where the Sidewalk Ends: Extending the Internet AS Graph Using Traceroutes from P2P Users
abstract
An accurate Internet topology graph is important in many areas of networking, from understanding ISP business relationships to diagnosing network anomalies. Most Internet mapping efforts have derived the network structure, at the level of interconnected autonomous systems (ASes), from a rather limited set of vantage points. In this paper, we argue that a promising approach to revealing the hidden areas of the Internet topology is through active measurement from an observation platform that scales with the growing Internet. By leveraging measurements performed by an extension to a popular P2P system, we show that this approach indeed exposes significant new topological information. Our study is based on traceroute measurements from more than 992,000 IPs in over 3,700 ASes distributed across the Internet hierarchy, many in regions of the Internet not covered by publicly available path information. To address this issue we develop heuristics that identify 23,914 new AS links not visible in the publicly-available BGP data-12.86 percent more customer-provider links and 40.99 percent more peering links, than previously reported. We validate our heuristics using data from a tier-1 ISP, and show that they successfully filter out all false links introduced by public IP-to-AS mapping. We analyze properties of the Internet graph that includes these new links and characterize why they are missing. Finally, we have made the identified set of links and their inferred relationships publicly available.
Kai Chen 0005, David R. Choffnes, Rahul Potharaju, Yan Chen 0004, Fabián E. Bustamante, Dan Pei, Yao Zhao 0003
IEEE Trans. Computers2
2013 Dasu: Pushing Experiments to the Internet's Edge
Mario A. Sánchez, John S. Otto, Zachary S. Bischof, David R. Choffnes, Fabián E. Bustamante, Balachander Krishnamurthy, Walter Willinger
NSDI4
2013 PoiRoot: investigating the root cause of interdomain path changes
abstract
Interdomain path changes occur frequently. Because routing protocols expose insufficient information to reason about all changes, the general problem of identifying the root cause remains unsolved. In this work, we design and evaluate PoiRoot, a real-time system that allows a provider to accurately isolate the root cause (the network responsible) of path changes affecting its prefixes. First, we develop a new model describing path changes and use it to provably identify the set of all potentially responsible networks. Next, we develop a recursive algorithm that accurately isolates the root cause of any path change. We observe that the algorithm requires monitoring paths that are generally not visible using standard measurement tools. To address this limitation, we combine existing measurement tools in new ways to acquire path information required for isolating the root cause of a path change. We evaluate PoiRoot on path changes obtained through controlled Internet experiments, simulations, and "in-the-wild" measurements. We demonstrate that PoiRoot is highly accurate, works well even with partial information, and generally narrows down the root cause to a single network or two neighboring ones. On controlled experiments PoiRoot is 100% accurate, as opposed to prior work which is accurate only 61.7% of the time.
Umar Javed, Ítalo S. Cunha, David R. Choffnes, Ethan Katz-Bassett, Thomas E. Anderson, Arvind Krishnamurthy
SIGCOMM3
2013 Towards efficient traffic-analysis resistant anonymity networks
abstract
Existing IP anonymity systems tend to sacrifice one of low latency, high bandwidth, or resistance to traffic-analysis. High-latency mix-nets like Mixminion batch messages to resist traffic-analysis at the expense of low latency. Onion routing schemes like Tor deliver low latency and high bandwidth, but are not designed to withstand traffic analysis. Designs based on DC-nets or broadcast channels resist traffic analysis and provide low latency, but are limited to low bandwidth communication.
Stevens Le Blond, David R. Choffnes, Wenxuan Zhou 0003, Peter Druschel, Hitesh Ballani, Paul Francis
SIGCOMM2
2012 LIFEGUARD: practical repair of persistent route failures
abstract
The Internet was designed to always find a route if there is a policy-compliant path. However, in many cases, connectivity is disrupted despite the existence of an underlying valid path. The research community has focused on short-term outages that occur during route convergence. There has been less progress on addressing avoidable long-lasting outages. Our measurements show that long-lasting events contribute significantly to overall unavailability.
Ethan Katz-Bassett, Colin Scott, David R. Choffnes, Ítalo S. Cunha, Vytautas Valancius, Nick Feamster, Harsha V. Madhyastha, Thomas E. Anderson, Arvind Krishnamurthy
SIGCOMM3
2011 Machiavellian routing: improving internet availability with BGP poisoning
abstract
We propose a new approach to mitigate disruptions of Internet connectivity. The Internet was designed to always find a route if there is a policy-compliant path; however, in many cases, connectivity is disrupted despite the existence of an underlying valid path. The research community has done considerable work on this problem, much of it focused on short-term outages that occur during route convergence. There has been less progress on addressing avoidable long-lasting outages. Our measurements show that long-lasting events contribute significantly to overall unavailability.
Ethan Katz-Bassett, David R. Choffnes, Ítalo S. Cunha, Colin Scott, Thomas E. Anderson, Arvind Krishnamurthy
HotNets2
2011 Privacy Revelations for Web and Mobile Apps
David Wetherall, David R. Choffnes, Ben Greenstein, Seungyeop Han, Peter Hornyack, Jaeyeon Jung, Stuart E. Schechter, Xiao Sophia Wang
HotOS2
2011 On blind mice and the elephant: understanding the network impact of a large distributed system
abstract
A thorough understanding of the network impact of emerging large-scale distributed systems -- where traffic flows and what it costs -- must encompass users' behavior, the traffic they generate and the topology over which that traffic flows. In the case of BitTorrent, however, previous studies have been limited by narrow perspectives that restrict such analysis.
John S. Otto, Mario A. Sánchez, David R. Choffnes, Fabián E. Bustamante, Georgos Siganos
SIGCOMM3
2010 Network Positioning from the Edge - An Empirical Study of the Effectiveness of Network Positioning in P2P Systems
abstract
Network positioning systems provide an important service to large- scale P2P systems, potentially enabling clients to achieve higher performance, reduce cross-ISP traffic and improve the robustness of the system to failures. Because traces representative of this environment are generally unavailable, and there is no platform suited for experimentation at the appropriate scale, network positioning systems have been commonly imple- mented and evaluated in simulation and on research testbeds. The performance of network positioning remains an open question for large deployments at the edges of the network. This paper evaluates how four key classes of network po- sitioning systems fare when deployed at scale and measured in P2P systems where they are used. Using 2 billion network measurements gathered from more than 43,000 IP addresses probing over 8 million other IPs worldwide, we show that network positioning exhibits noticeably worse performance than previously reported in studies conducted on research testbeds. To explain this result, we identify several key properties of this environment that call into question fundamental assumptions driving network positioning research.
David R. Choffnes, Mario A. Sánchez, Fabián E. Bustamante
INFOCOM1
2010 Crowdsourcing service-level network event monitoring
abstract
The user experience for networked applications is becoming a key benchmark for customers and network providers. Perceived user experience is largely determined by the frequency, duration and severity of network events that impact a service. While today's networks implement sophisticated infrastructure that issues alarms for most failures, there remains a class of silent outages (e.g., caused by configuration errors) that are not detected. Further, existing alarms provide little information to help operators understand the impact of network events on services. Attempts to address this through infrastructure that monitors end-to-end performance for customers have been hampered by the cost of deployment and by the volume of data generated by these solutions.
David R. Choffnes, Fabián E. Bustamante, Zihui Ge
SIGCOMM1
2009 Where the sidewalk ends: extending the internet as graph using traceroutes from P2P users
abstract
An accurate Internet topology graph is important in many areas of networking, from deciding ISP business relationships to diagnosing network anomalies. Most Internet mapping efforts have derived the network structure, at the level of interconnected autonomous systems (ASes), from a limited number of either BGP- or traceroute- based data sources. While techniques for charting the topology continue to improve, the growth of the number of vantage points is significantly outpaced by the rapid growth of the Internet.
Kai Chen 0005, David R. Choffnes, Rahul Potharaju, Yan Chen 0004, Fabián E. Bustamante, Dan Pei, Yao Zhao 0003
CoNEXT2
2009 On the Effectiveness of Measurement Reuse for Performance-Based Detouring
abstract
For both technological and economic reasons, the default path between two end systems in the wide-area Internet can be suboptimal. This observation has motivated a number of systems that attempt to improve reliability and performance by routing over one or more hops in an overlay. Most of the proposed solutions, however, fall at an extreme in the cost-performance trade-off. While some provide near-optimal performance with an un-scalable measurement overhead, others avoid measurement when selecting routes around network failures but make no attempt to optimize performance. This paper presents an experimental evaluation of an alternative approach to scalable, performance detouring based on the strategic reuse of measurements from other large distributed systems, namely content distribution networks (CDNs). By relying on CDN redirections as hints on network conditions, higher performance paths are readily found with little overhead and no active network measurement. We report results from a study of more than 13,700 paths between 170 widely-distributed hosts over a three-week period, showing the benefits of this approach. We demonstrate that it is practical by implementing an FTP suite that uses our publicly available Side Step library to take advantage of these alternative Internet routes.
David R. Choffnes, Fabián E. Bustamante
INFOCOM1
2009 Drafting behind Akamai: inferring network conditions based on CDN redirections
Ao-Jan Su, David R. Choffnes, Aleksandar Kuzmanovic, Fabián E. Bustamante
IEEE/ACM Trans. Netw.2
2008 Relative Network Positioning via CDN Redirections
abstract
Many large-scale distributed systems can benefit from a service that allows them to select among alternative nodes based on their relative network positions. A variety of approaches propose new measurement infrastructures that attempt to scale this service to large numbers of nodes by reducing the amount of direct measurements to end hosts. In this paper, we introduce a new approach to relative network positioning that eliminates direct probing by leveraging pre-existing infrastructure. Specifically, we exploit the dynamic association of nodes with replica servers from large content distribution networks (CDNs) to determine relative position information - we call this approach CDN-based relative network positioning (CRP). We demonstrate how CRP can support two common examples of location information used by distributed applications: server selection and dynamic node clustering. After describing CRP in detail, we present results from an extensive wide-area evaluation that demonstrates its effectiveness.
Ao-Jan Su, David R. Choffnes, Fabián E. Bustamante, Aleksandar Kuzmanovic
ICDCS2
2008 Taming the torrent: a practical approach to reducing cross-isp traffic in peer-to-peer systems
abstract
Peer-to-peer (P2P) systems, which provide a variety of popular services, such as file sharing, video streaming and voice-over-IP, contribute a significant portion of today's Internet traffic. By building overlay networks that are oblivious to the underlying Internet topology and routing, these systems have become one of the greatest traffic-engineering challenges for Internet Service Providers (ISPs) and the source of costly data traffic flows. In an attempt to reduce these operational costs, ISPs have tried to shape, block or otherwise limit P2P traffic, much to the chagrin of their subscribers, who consistently finds ways to eschew these controls or simply switch providers.
David R. Choffnes, Fabián E. Bustamante
SIGCOMM1
2006 Drafting behind Akamai (travelocity-based detouring)
abstract
To enhance web browsing experiences, content distribution networks (CDNs) move web content "closer" to clients by caching copies of web objects on thousands of servers worldwide. Additionally, to minimize client download times, such systems perform extensive network and server measurements, and use them to redirect clients to different servers over short time scales. In this paper, we explore techniques for inferring and exploiting network measurements performed by the largest CDN, Akamai; our objective is to locate and utilize quality Internet paths without performing extensive path probing or monitoring.Our contributions are threefold. First, we conduct a broad measurement study of Akamai's CDN. We probe Akamai's network from 140 PlanetLab vantage points for two months. We find that Akamai redirection times, while slightly higher than advertised, are sufficiently low to be useful for network control. Second, we empirically show that Akamai redirections overwhelmingly correlate with network latencies on the paths between clients and the Akamai servers. Finally, we illustrate how large-scale overlay networks can exploit Akamai redirections to identify the best detouring nodes for one-hop source routing. Our research shows that in more than 50% of investigated scenarios, it is better to route through the nodes "recommended" by Akamai, than to use the direct paths. Because this is not the case for the rest of the scenarios, we develop lowoverhead pruning algorithms that avoid Akamai-driven paths when they are not beneficial.
Ao-Jan Su, David R. Choffnes, Aleksandar Kuzmanovic, Fabián E. Bustamante
SIGCOMM2