Emile Aben

dblp:49/8891 · DBLP profile ↗
← Back
20ranked-venue papers
0as first author
5since 2021 · last 2025
0000-0002-8275-5460ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 4 since 2021Security and privacy · 4 · 1 since 2021
YearPublicationVenuePosition
2025 Metis: Selecting Diverse Atlas Vantage Points
abstract
The popularity of the RIPE Atlas measurement platform comes primarily from its openness and unprecedented scale. The platform provides users with over ten thousand vantage points, called probes, and is usually considered as giving a reasonably faithful view of the Internet. A good use of Atlas, however, requires a clear understanding of its limitations and bias. In this work we highlight the influence of probe locations on Atlas measurements and advocate the importance of selecting a diverse set of probes for fair measurements. We propose Metis, a data-driven probe selection method, that picks a diverse set of probes based on topological properties (e.g., round-trip time or AS-path length). Using real experiments we show that, compared to Atlas’ default probe selection, Metis’ probe selections collect more comprehensive measurement results in terms of geographical, topological, RIR, and industry-type coverage. Metis triples the number of probes from the underrepresented AFRINIC and LACNIC regions, and improves geographical diversity by increasing the number of unique countries included in the probe set by up to 59%. In addition, we extend Metis to identify locations on the Internet where new probes would be the most beneficial for improving Atlas’ footprint. Finally, we present a website where we publish periodically updated results and provide easy integration of Metis’ selections with Atlas.
Malte Tashiro, Emile Aben, Romain Fontugne
IEEE Trans. Netw. Serv. Manag.2
2024 The Wisdom of the Measurement Crowd: Building the Internet Yellow Pages a Knowledge Graph for the Internet
abstract
The Internet measurement community has significantly advanced our understanding of the Internet by documenting its various components. Subsequent research often builds on these efforts, using previously published datasets. This process is fundamental for researchers, but a laborious task due to the diverse data formats, terminologies, and areas of expertise involved. Additionally, the time-consuming task of merging datasets is undertaken only if the expected benefits are worthwhile, posing a barrier to simple exploration and innovation. In this paper we present the Internet Yellow Pages (IYP), a knowledge graph for Internet resources. By leveraging the flexibility of graph databases and ontology-based data integration, we compile datasets (currently 46) from diverse and independent sources into a single harmonized database where the meaning of each entity and relationship is unequivocal. Using simple examples, we illustrate how IYP allows us to seamlessly navigate data coming from numerous underlying sources. As a result, IYP significantly reduces time to insight, which we demonstrate by reproducing two past studies and extending them by incorporating additional datasets available in IYP. Finally, we discuss how IYP can foster the sharing of datasets as it provides a universal platform for querying and describing data. This is a seminal effort to bootstrap what we envision as a community-driven project where dataset curation and ontology definitions evolve with the Internet measurement community.
Romain Fontugne, Malte Tashiro, Raffaele Sommese, Mattijs Jonker, Zachary S. Bischof, Emile Aben
IMC6
2023 RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
abstract
The Resource Public Key Infrastructure (RPKI) is a system to add security to the Internet routing. In recent years, the publication of Route Origin Authorization (ROA) objects, which bind IP prefixes to their legitimate origin ASN, has been rapidly increasing. However, ROAs are effective only if the routers use them to verify and filter invalid BGP announcements, a process called Route Origin Validation (ROV).
Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, Taejoong Chung
IMC4
2023 Intercept and Inject: DNS Response Manipulation in the Wild
Yevheniya Nosyk, Qasim Lone, Yury Zhauniarovich, Carlos Gañán, Emile Aben, Giovane Cesar Moreira Moura, Samaneh Tajalizadehkhoob, Andrzej Duda, Maciej Korczynski
PAM5
2021 Towards a traffic map of the Internet Connecting the dots between popular services and users: Connecting the dots between popular services and users
abstract
The impact of Internet phenomena depends on how they impact users, but researchers lack visibility into how to translate Internet events into their impact. Distressingly, the research community seems to have lost hope of obtaining this information without relying on privileged viewpoints. We argue for optimism thanks to new network measurement methods and changes in Internet structure which make it possible to construct an "Internet traffic map". This map would identify the locations of users and major services, the paths between them, and the relative activity levels routed along these paths. We sketch our vision for the map, detail new measurement ideas for map construction, and identify key challenges that the research community should tackle. The realization of an Internet traffic map will be an Internet-scale research effort with Internet-scale impacts that reach far beyond the research community, and so we hope our fellow researchers are excited to join us in addressing this challenge.
Weifan Jiang, Petros Gigis, Kevin Vermeulen, Emile Aben, Matt Calder, Ethan Katz-Bassett, Lefteris Manassakis, Georgios Smaragdakis, Narseo Vallina-Rodriguez
HotNets7
2020 The Internet in Crimea: a Case Study on Routing Interregnum
Romain Fontugne, Ksenia Ermoshina, Emile Aben
Networking3
2019 RPKI is Coming of Age: A Longitudinal Study of RPKI Deployment and Invalid Route Origins
abstract
Despite its critical role in Internet connectivity, the Border Gateway Protocol (BGP) remains highly vulnerable to attacks such as prefix hijacking, where an Autonomous System (AS) announces routes for IP space it does not control. To address this issue, the Resource Public Key Infrastructure (RPKI) was developed starting in 2008, with deployment beginning in 2011. This paper performs the first comprehensive, longitudinal study of the deployment, coverage, and quality of RPKI. We use a unique dataset containing all RPKI Route Origin Authorizations (ROAs) from the moment RPKI was first deployed, more than 8 years ago. We combine this dataset with BGP announcements from more than 3,300 BGP collectors worldwide. Our analysis shows the after a gradual start, RPKI has seen a rapid increase in adoption over the past two years. We also show that although misconfigurations were rampant when RPKI was first deployed (causing many announcements to appear as invalid) they are quite rare today. We develop a taxonomy of invalid RPKI announcements, then quantify their prevalence. We further identify suspicious announcements indicative of prefix hijacking and present case studies of likely hijacks. Overall, we conclude that while misconfigurations still do occur, RPKI is "ready for the big screen," and routing security can be increased by dropping invalid announcements. To foster reproducibility and further studies, we release all RPKI data and the tools we used to analyze it into the public domain.
Taejoong Chung, Emile Aben, Tim Bruijnzeels, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Roland van Rijswijk-Deij, John P. Rula, Nick Sullivan
Internet Measurement Conference2
2019 BGP Zombies: An Analysis of Beacons Stuck Routes
Romain Fontugne, Esteban Bautista, Colin Petrie, Yutaro Nomura, Patrice Abry, Paulo Gonçalves 0001, Kensuke Fukuda, Emile Aben
PAM8
2019 Tracking the deployment of IPv6: Topology, routing and performance
Siyuan Jia, Matthew J. Luckie, Bradley Huffaker, Ahmed Elmokashfi, Emile Aben, K. C. Claffy, Amogh Dhamdhere
Comput. Networks5
2018 The (Thin) Bridges of AS Connectivity: Measuring Dependency Using AS Hegemony
Romain Fontugne, Anant Shah, Emile Aben
PAM3
2017 Vantage point selection for IPv6 measurements: Benefits and limitations of RIPE Atlas tags
abstract
RIPE Atlas consists of ∼9.1K probes (as of Jan 2017) connected in core, access and home networks. RIPE Atlas has recently (Jul 2014) introduced a tagging mechanism for fine-grained vantage point selection of probes. These tags are subdivided into user and system tags. User tags are based on a manual process which is largely dependent on proactive participation of probe hosts. We show that only ∼2.8% of probe hosts ever update their user tags which may lead to user tags that tend to become stale over time. System tags on the other hand being automatically assigned and frequently updated (every 4 hours) are stable and accurate. We show an application of system tags by performing a vantage point selection of dual-stacked probes. This exploration reveals that with ∼2.3K (∼26%) connected dual-stacked probes, RIPE Atlas provides the richest source of vantage points for IPv6 measurement studies. These dual-stacked probes span 88 countries and cover 822 ASNs. ∼83% of these dual-stacked probes are connected within access networks with 782 probes deployed at homes with native IPv6 connectivity. These home dual-stacked probes are evenly split across DSL, cable and fibre deployments. We show that IPv6 latencies from these probes to RIPE Atlas anchors appear comparable to IPv4, although IPv4 performs marginally better. By applying a correlation against APNIC IPv6 user population estimate, we further reveal underrepresented countries (such as BE and JP) which would benefit from deployment of more probes for IPv6 measurement studies.
Vaibhav Bajpai, Steffie Jacob Eravuchira, Jürgen Schönwälder, Robert Kisteleki, Emile Aben
IM5
2017 Pinpointing delay and forwarding anomalies using large-scale traceroute measurements
abstract
Understanding data plane health is essential to improving Internet reliability and usability. For instance, detecting disruptions in distant networks can identify repairable connectivity problems. Currently this task is difficult and time consuming as operators have poor visibility beyond their network's border. In this paper we leverage the diversity of RIPE Atlas traceroute measurements to solve the classic problem of monitoring in-network delays and get credible delay change estimations to monitor network conditions in the wild. We demonstrate a set of complementary methods to detect network disruptions and report them in near real time. The first method detects delay changes for intermediate links in traceroutes. Second, a packet forwarding model predicts traffic paths and identifies faulty routers and links in cases of packet loss. In addition, we define an alarm score that aggregates changes into a single value per AS in order to easily monitor its sanity, reducing the effect of uninteresting alarms. Using only existing public data we monitor hundreds of thousands of link delays while adding no burden to the network. We present three cases demonstrating that the proposed methods detect real disruptions and provide valuable insights, as well as surprising findings, on the location and impact of the identified events.
Romain Fontugne, Cristel Pelsser, Emile Aben, Randy Bush
Internet Measurement Conference3
2017 Detecting Peering Infrastructure Outages in the Wild
abstract
Peering infrastructures, namely, colocation facilities and Internet exchange points, are located in every major city, have hundreds of network members, and support hundreds of thousands of interconnections around the globe. These infrastructures are well provisioned and managed, but outages have to be expected, e.g., due to power failures, human errors, attacks, and natural disasters. However, little is known about the frequency and impact of outages at these critical infrastructures with high peering concentration.
Vasileios Giotsas, Christoph Dietzel, Georgios Smaragdakis, Anja Feldmann, Arthur W. Berger, Emile Aben
SIGCOMM6
2017 Four years tracking unrevealed topological changes in the african interdomain
Rodérick Fanou, Pierre François, Emile Aben, Michuki Mwangi, N. Goburdhan, Francisco Valera
Comput. Commun.3
2016 Reasons Dynamic Addresses Change
Ramakrishna Padmanabhan, Amogh Dhamdhere, Emile Aben, K. C. Claffy, Neil Spring
Internet Measurement Conference3
2015 On the Diversity of Interdomain Routing in Africa
Rodérick Fanou, Pierre François, Emile Aben
PAM3
2014 Analysis of Country-Wide Internet Outages Caused by Censorship
abstract
In the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper, we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data, unsolicited data plane traffic to unassigned address space, active macroscopic traceroute measurements, RIR delegation files, and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin autonomous systems (ASs) using publicly available BGP data repositories in the US and Europe. We then analyzed observable activity related to these sets of prefixes and ASs throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions.
Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè
IEEE/ACM Trans. Netw.3
2013 Gaining insight into AS-level outages through analysis of Internet background radiation
abstract
Internet Background Radiation (IBR) is unsolicited network traffic mostly generated by malicious software, e.g., worms, scans. In previous work, we extracted a signal from IBR traffic arriving at a large (/8) segment of unassigned IPv4 address space to identify large-scale disruptions of connectivity at an Autonomous System (AS) granularity, and used our technique to study episodes of government censorship and natural disasters [1]. Here we explore other IBR-derived metrics that may provide insights into the causes of macroscopic connectivity disruptions. We propose metrics indicating packet loss (e.g., due to link congestion) along a path from a specific AS to our observation point. We use three case studies to illustrate how our metrics can help identify packet loss characteristics of an outage. These metrics could be used in the diagnostic component of a semiautomated system for detecting and characterizing large-scale outages.
Karyn Benson, Alberto Dainotti, K. C. Claffy, Emile Aben
INFOCOM4
2012 Measuring the deployment of IPv6: topology, routing and performance
abstract
We use historical BGP data and recent active measurements to analyze trends in the growth, structure, dynamics and performance of the evolving IPv6 Internet, and compare them to the evolution of IPv4. We find that the IPv6 network is maturing, albeit slowly. While most core Internet transit providers have deployed IPv6, edge networks are lagging. Early IPv6 network deployment was stronger in Europe and the Asia-Pacific region, than in North America. Current IPv6 network deployment still shows the same pattern. The IPv6 topology is characterized by a single dominant player -- Hurricane Electric -- which appears in a large fraction of IPv6 AS paths, and is more dominant in IPv6 than the most dominant player in IPv4. Routing dynamics in the IPv6 topology are largely similar to those in IPv4, and churn in both networks grows at the same rate as the underlying topologies. Our measurements suggest that performance over IPv6 paths is comparable to that over IPv4 paths if the AS-level paths are the same, but can be much worse than IPv4 if the AS-level paths differ.
Amogh Dhamdhere, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Ahmed Elmokashfi, Emile Aben
Internet Measurement Conference6
2011 Analysis of country-wide internet outages caused by censorship
abstract
In the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data; unsolicited data plane traffic to unassigned address space; active macroscopic traceroute measurements; RIR delegation files; and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin ASes using publicly available BGP data repositories in the U.S. and Europe. We then analyzed observable activity related to these sets of prefixes and ASes throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions.
Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè
Internet Measurement Conference3