VLDB 2026 Research / reviewers in the wild / expert
Anna Sperotto
dblp:59/2521
· DBLP profile ↗
56ranked-venue papers
2as first author
20since 2021 · last 2025
0000-0002-9481-5846ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 2 first-author · 2 since 2021Security and privacy · 8 · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | 90th Minute: A First Look to Collateral Damages and Efficacy of the Italian Piracy ShieldabstractIn the fight against illegal football streaming, Italy introduced Piracy Shield, a platform through which copyright holders can notify the national regulator (AGCOM), which in turn orders ISPs to block infringing resources -- such as IP addresses and Fully Qualified Domain Names (FQDNs) -- within 30 minutes. In this paper, we present the first investigation into the platform's real-world impact by reconstructing and analyzing its blocking activity. Our analysis shows that the platform causes significant collateral damage. Indiscriminate IP-level blocking has disrupted and continues to disrupt hundreds of legitimate, non-streaming websites. At the same time, the platform's effectiveness may have been undermined by streamers who evaded enforcement by migrating to new infrastructure and unfiltered IP address space. Based on these findings, we call on Italian authorities and policymakers to critically reconsider the platform's core blocking principles. The evidence suggests that its broad impact on legitimate services and the potential national security risks outweigh its intended benefits. Raffaele Sommese, Anna Sperotto, Antonio Prado, Jeroen van der Ham, Antonia Affinito |
CNSM | 2 |
| 2025 | Double-Edged Sword: An Empirical Study on the Contribution of Cloud Providers in Malicious InfrastructureabstractCloud computing offers flexibility and costeffectiveness, but can also be abused for malicious activities. In this study, we conduct an empirical analysis of the cloud infrastructure of malicious (blocklisted) domains, with a focus on three core infrastructural components — web hosting, DNS, and email — and we compare them against a baseline of general domains. Our goal is to assess the rate of abuse targeting these components as they represent fundamental pillars of Internet communication. Leveraging DNS data from OpenINTEL, cloud classification from IP2Location, and a curated ground-truth list of cloud providers, we evaluate the role of major providers in hosting malicious infrastructure. Our results show that malicious domains are increasingly shifting toward partial cloud infrastructure outsourcing, with a strong preference for cloud-based web hosting while avoiding full-stack cloud adoption. We also observe a high degree of diversity of malicious infrastructure deployment across all three components. Finally, our country analysis highlights a growing concentration of malicious hosting activity in the Asia-Pacific region. Sousan Tarahomi, Raffaele Sommese, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 5 |
| 2025 | Investigating Middlebox Deployment and Characteristics in Dutch Autonomous SystemsabstractMiddleboxes shape modern network behavior by enforcing security policies and optimizing traffic, but their opaque operations reduce network transparency and complicate digital sovereignty efforts. In this study, we analyze middlebox deployment and behavior across Dutch Autonomous Systems (ASes), motivated by the strategic position of the Netherlands in European network infrastructure. We classify ASes into sectorsgovernmental, private, educational, and digital infrastructureand using active probing and third-party datasets, we examined 989 ASes and 5.1 million IPs, identified 310 middleboxes, with high confidence, registered to and located within Dutch ASes. Our results reveal several sector-specific interference patterns. ISPs and hosting providers show diverse modifications, governmental ASes exhibit consistent policy enforcement at the edge, and private ASes adopt hybrid strategies, combining TCP option stripping with deeper manipulation of TCP state. Exposed management interfaces and outdated software further increase operational risks, whether tied to the middleboxes themselves or co-located devices. Our findings highlight the value of AS-level investigation for understanding middlebox behavior and underscore the need for proactive auditing and secure configuration to support resilient and sovereign network infrastructure. Bulut Ulukapi, Anna Sperotto, Ralph Holz |
CNSM | 2 |
| 2025 | Web Crawl Refusals: Insights From Common Crawl
Mostafa Ansar, Anna Sperotto, Ralph Holz |
PAM | 2 |
| 2025 | Risk Response - An Adversarial Discourse Game and Group Modelling Tool
Max Willis, Greta Adamo, Anna Sperotto |
RCIS (1) | 3 |
| 2025 | Victimization in DDoS attacks: The role of popularity and industry sectorabstractDistributed denial-of-service (DDoS) attacks may be driven not only by economic motives such as extortion, but also by social or political goals, including hacktivism and state-sponsored operations. Therefore, the monetary value of a target alone does not fully explain why some organizations are more frequently victimized. While cloud providers deploy advanced defenses — such as Anycast routing, traffic scrubbing, and filtering — they also concentrate many potential targets within a shared infrastructure, increasing their exposure to DDoS attacks. This study aims to understand what makes organizations more suitable DDoS targets by examining two key attributes: visibility and perceived value, represented by website popularity and industry sector. We also investigate how the customer portfolio of cloud and data center providers influences the DDoS threat to their infrastructure. Research Questions: • How do organizational characteristics related to value and visibility — specifically, popularity and industry sector — correlate with the threat of DDoS attacks? • How does the diversity of customer business sectors hosted by a cloud or data center provider influence the DDoS threat to its infrastructure? Methodology: We conducted a large-scale analysis of DDoS incidents inferred from network telescope data spanning five years. We estimated target visibility and value using Alexa ranks and Cisco Umbrella content categories. We also analyzed the relationship between customer sector composition and DDoS threat at the provider level. Key Findings: • Popular websites are more frequently attacked, though this pattern weakened during the COVID-19 pandemic. • Certain industry sectors face significantly higher and repeated DDoS threats. • Cloud providers serving a higher proportion of high-risk sectors are more likely to face frequent DDoS attacks. Muhammad Yasir Muzayan Haq, Antonia Affinito, Alessio Botta, Anna Sperotto, Lambert J. M. Nieuwenhuis, Mattijs Jonker, Abhishta |
J. Inf. Secur. Appl. | 4 |
| 2024 | A First Look at User-Installed Residential Proxies From a Network Operator's PerspectiveabstractResidential proxies (RESIP) enable the tunneling of traffic through non-data center Internet connections. Previous research has focused on malicious software on end-user devices that made them part of RESIP networks. This study investigates RESIP networks that users voluntarily join in exchange for monetary rewards, aiming to understand the activities facilitated through these services. We developed a testbed environment to operate and monitor eight different residential proxy applications over 7.5 months, enabling us to collect and analyze 368 GB of proxied network traffic, the majority of which is encrypted.In this work, we highlight three distinct case studies that suggest these proxies are used in practices not advertised by the RESIP providers and in one case, shed light on the scale of the proxied campaigns. Firstly, we discuss the use of RESIPs on two dating apps, Tinder and happn, highlighting their likely role in facilitating fraudulent activities. Secondly, an analysis of metadata suggests that RESIPs may play a crucial part in phishing campaigns. Thirdly, a collaboration with a leading technology company in the travel industry allows us to analyze the behavior of web scrapers.Our results underscore the need for enhanced detection mechanisms to mitigate fraud and protect users. Etienne Khan, Elisa Chiapponi, Martijn Verkleij, Anna Sperotto, Roland van Rijswijk-Deij, Jeroen van der Ham |
CNSM | 4 |
| 2024 | Analyzing Privacy Implications of Mobile Apps Data Collection across Age GroupsabstractMobile applications increasingly access a wide range of personal information, raising significant privacy concerns, particularly for children and teenagers. Previous studies have shown low compliance between privacy policies and permissions in mobile apps. However, current research has not yet explored how an app’s target age group influences the permissions it requests, especially among minors. While recent regulatory frameworks like COPPA, CCPA, and GDPR establish clear rules for data acquisition and privacy for specific age groups, their practical application remains uncertain. This research investigates how data collection practices align with privacy policies among mobile applications targeting different age groups. We show that, on average, the same application collects more user data when downloaded from Google Play than the Apple App Store. Furthermore, applications targeting teenagers collect data more frequently than those targeting other age groups, indicating the necessity for strict regulations for this age group. Adamo Mariani, Matteo Liberato, Anna Sperotto, Antonia Affinito |
CNSM | 3 |
| 2024 | Is a Name Enough? A First Look into Detecting Clouds Using DNS Pointer RecordsabstractThe flexibility and scalability of cloud services have led to their adoption across various industries. While it is easy to identify deployments of very large cloud providers (hypergiants) as they often publish the allocation of their network resources, this is much less commonly the case for smaller providers. Despite efforts by commercial IP intelligence providers to bridge this gap, it is not clear how complete and reliable their data is, which is compounded by the lack of transparency surrounding their identification methods. In this early study, we utilize reverse DNS, a public data source provided and used by network operators, to identify the IP cloud space. We develop a Markov chain-based classifier to identify patterns and structures in the reverse DNS naming schemes of cloud providers. Our results indicate that cloud infrastructure naming often differs significantly from that of residential IP space, although there are some overlaps that require further investigation. We believe that our model can be used by network operators to identify cloud deployments with varying levels of confidence. Sousan Tarahomi, Raffaele Sommese, Pieter-Tjerk de Boer, Jeroen Linssen, Ralph Holz, Anna Sperotto |
CNSM | 6 |
| 2024 | Glossy Mirrors: On the Role of Open Resolvers in Reflection and Amplification DDoS AttacksabstractOpen DNS resolvers are infamous contributors to DDoS attacks. Characteristics of open DNS resolvers have been studied in different aspects in the past. However, there is a gap in knowledge on the actual role of open resolvers acting involuntarily as DNS reflectors in DDoS attacks.In this paper, we study DNS reflectors in more than half a million DDoS events using a large-scale DDoS telemetry dataset provided by a DDoS protection service provider with a global footprint. Our findings reveal that while the majority (∼79%) of reflectors misused in attacks are open resolvers capable of delivering large DNS responses, the contribution of reflectors with very small response sizes is not negligible either. Additionally, our analyses reveal that the distribution of misused open resolvers is biased toward certain countries and network operators, likely impacted by the IP churn of reflectors, while in terms of network types, there is no outstanding bias visible in an aggregated view. Finally, comparing the pool of misused open resolvers to the pool of all exposed and potentially abusable resolvers, the latter dwarfs the former, suggesting that the firepower of DNS-based DDoS attacks could substantially increase in the future. Ramin Yazdani, Max Resing, Anna Sperotto |
CNSM | 3 |
| 2024 | Unpacking the Semantics of Risk in Climate Change DiscoursesabstractThe climate change assessment community relies on widely accepted definitions of risk and its components, e.g. hazard, exposure, and vulnerability, provided by the well-known international organisation Intergovernmental Panel on Climate Change (IPCC). Those definitions of risk have been changing through the years and are presented in a general and “common sense” form as they need to be understandable by the public society and accommodate notions of risk as embraced by different research streams. However, these definitions have proven ineffective in operational climate risk assessment procedures, which exposes the critical need for disambiguation. This paper addresses the lack of semantic clarity of risk and cognate concepts in the context of climate change assessment by unpacking the ontological commitments underlying the IPCC’s most recent definitions and glossary using the Common Ontology of Value and Risk (COVER) as a primary guideline. This study provides a more precise and refined ontological foundation of risk in climate change research that better aligns with the complexities of scenarios and assessments, and contributes to climate change research on mitigation and adaptation by supporting more effective communication and assessment of climate-related risks and humanity’s responses to them. Greta Adamo, Anna Sperotto, Mattia Fumagalli, Alessandro Mosca 0001, Tiago Prince Sales, Giancarlo Guizzardi |
FOIS | 2 |
| 2024 | Swamp of Reflectors: Investigating the Ecosystem of Open DNS Resolvers
Ramin Yazdani, Mattijs Jonker, Anna Sperotto |
PAM (2) | 3 |
| 2023 | Quantifying Security Risks in Cloud Infrastructures: A Data-driven ApproachabstractBusinesses increasingly outsource their ICT services to cloud environments, mostly driven by considerations about costs, processes and security. However concerns around cloud exposure against cyber-security attacks are also growing. This bring about the question if the cloud really makes us more secure, or if it merely changes the type of threats we are exposed to. This PhD project aims at addressing this question by focusing on cloud infrastructure security. Using Internet measurements, we will take a data-driven approach to identify vulnerabilities and single points of failure in cloud infrastructure. Based on our analysis, we will propose solutions to mitigate these vulnerabilities and enhance the overall security of cloud environments. Sousan Tarahomi, Ralph Holz, Anna Sperotto |
NetSoft | 3 |
| 2023 | Stranger VPNs: Investigating the Geo-Unblocking Capabilities of Commercial VPN Providers
Etienne Khan, Anna Sperotto, Jeroen van der Ham, Roland van Rijswijk-Deij |
PAM | 2 |
| 2022 | Investigating the impact of DDoS attacks on DNS infrastructureabstractDenial of Service (DDoS) attacks both abuse and target core Internet infrastructures and services, including the Domain Name System (DNS). To characterize recent DDoS attacks against authoritative DNS infrastructure, we join two existing data sets - DoS activity inferred from a sizable darknet, and contemporaneous DNS measurement data - for a 17-month period (Nov. 20 - Mar. 22). Our measurements reveal evidence that millions of domains (up to 5% of the DNS namespace) experienced a DoS attack during our observation window. Most attacks did not substantially harm DNS performance, but in some cases we saw 100-fold increases in DNS resolution time, or complete unreachability. Our measurements captured a devastating attack against a large provider in the Netherlands (TransIP), and attacks against Russian infrastructure. Our data corroborates the value of known best practices to improve DNS resilience to attacks, including the use of anycast and topological redundancy in nameserver infrastructure. We discuss the strengths and weaknesses of our data sets for DDoS tracking and impact on the DNS, and promising next steps to improve our understanding of the evolving DDoS ecosystem. Raffaele Sommese, K. C. Claffy, Roland van Rijswijk-Deij, Arnab Chattopadhyay, Alberto Dainotti, Anna Sperotto, Mattijs Jonker |
IMC | 6 |
| 2022 | Saving Brian's privacy: the perils of privacy exposure through reverse DNSabstractGiven the importance of privacy, many Internet protocols are nowadays designed with privacy in mind (e.g., using TLS for confidentiality). Foreseeing all privacy issues at the time of protocol design is, however, challenging and may become near impossible when interaction out of protocol bounds occurs. One demonstrably not well understood interaction occurs when DHCP exchanges are accompanied by automated changes to the global DNS (e.g., to dynamically add hostnames for allocated IP addresses). As we will substantiate, this is a privacy risk: one may be able to infer device presence and network dynamics from virtually anywhere on the Internet --- and even identify and track individuals --- even if other mechanisms to limit tracking by outsiders (e.g., blocking pings) are in place. Olivier van der Toorn, Roland van Rijswijk-Deij, Raffaele Sommese, Anna Sperotto, Mattijs Jonker |
IMC | 4 |
| 2022 | DMEF: Dynamic Malware Evaluation FrameworkabstractBotnets are the top concern responsible for SPAM, Cryptomining, DDoS attacks and offer a variety of attacks-as-a-service to disrupt IT infrastructure and services. Current approaches to detect and analyze Botnet characteristics rely on disassembly and reverse engineering, and single instance deployments in an isolated environment. However, Botnets consist of distributed and interconnected instances and thus current approaches only observe a fraction of a Botnet and its characteristics. In this paper, we introduce the framework DMEF to deploy and analyze malware in a scalable, distributed and secure environment. DMEF provides a training environment for network administrators and researchers in the fight against malware and contributes to optimize intrusion response. Christian Dietz, Marcel Antzek, Gabi Dreo Rodosek, Anna Sperotto, Aiko Pras |
NOMS | 4 |
| 2022 | A Matter of Degree: Characterizing the Amplification Power of Open DNS Resolvers
Ramin Yazdani, Roland van Rijswijk-Deij, Mattijs Jonker, Anna Sperotto |
PAM | 4 |
| 2022 | Mirrors in the Sky: On the Potential of Clouds in DNS Reflection-based Denial-of-Service AttacksabstractClouds are likely to be well-provisioned in terms of network capacity by design. The rapid growth of cloud-based services means an increased availability of network infrastructure for all types of customers. However, it could also provide attackers opportunity to misuse cloud infrastructure to bring about attacks, or to target the cloud infrastructure itself. Ramin Yazdani, Alden Hilton, Jeroen van der Ham, Roland van Rijswijk-Deij, Casey T. Deccio, Anna Sperotto, Mattijs Jonker |
RAID | 6 |
| 2021 | ANYway: Measuring the Amplification DDoS Potential of DomainsabstractDDoS attacks threaten Internet security and stability, with attacks reaching the Tbps range. A popular approach involves DNS-based reflection and amplification, a type of attack in which a domain name, known to return a large answer, is queried using spoofed requests. Do the chosen names offer the largest amplification, however, or have we yet to see the full amplification potential? And while operational countermeasures are proposed, chiefly limiting responses to ‘ANY’ queries, up to what point will these countermeasures be effective? In this paper we make three main contributions. First, we propose and validate a scalable method to estimate the amplification potential of a domain name, based on the expected ANY response size. Second, we create estimates for hundreds of millions of domain names and rank them by their amplification potential. By comparing the overall ranking to the set of domains observed in actual attacks in honeypot data, we show whether attackers are using the most-potent domains for their attacks, or if we may expect larger attacks in the future. Finally, we evaluate the effectiveness of blocking ANY queries, as proposed by the IETF, to limit DNS-based DDoS attacks, by estimating the decrease in attack volume when switching from ANY to other query types. Our results show that by blocking ANY, the response size of domains observed in attacks can be reduced by 57%, and the size of most-potent domains decreases by 69%. However, we also show that dropping ANY is not an absolute solution to DNS-based DDoS, as a small but potent portion of domains remain leading to an expected response size of over 2,048 bytes to queries other than ANY. Olivier van der Toorn, Johannes Krupp, Mattijs Jonker, Roland van Rijswijk-Deij, Christian Rossow, Anna Sperotto |
CNSM | 6 |
| 2020 | MAnycast2: Using Anycast to Measure AnycastabstractAnycast addressing - assigning the same IP address to multiple, distributed devices - has become a fundamental approach to improving the resilience and performance of Internet services, but its conventional deployment model makes it impossible to infer from the address itself that it is anycast. Existing methods to detect anycast IPv4 prefixes present accuracy challenges stemming from routing and latency dynamics, and efficiency and scalability challenges related to measurement load. We review these challenges and introduce a new technique we call "MAnycast2" that can help overcome them. Our technique uses a distributed measurement platform of anycast vantage points as sources to probe potential anycast destinations. This approach eliminates any sensitivity to latency dynamics, and greatly improves efficiency and scalability. We discuss alternatives to overcome remaining challenges relating to routing dynamics, suggesting a path toward establishing the capability to complete, in under 3 hours, a full census of which IPv4 prefixes in the ISI hitlist are anycast. Raffaele Sommese, Leandro Marcio Bertholdo, Gautam Akiwate, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
Internet Measurement Conference | 8 |
| 2020 | Towards Adversarial Resilience in Proactive Detection of Botnet Domain Names by using MTDabstractArtificial Intelligence is often part of state-of-the-art Intrusion Detection Systems. However, attackers use Artificial Intelligence to improve their attacks and circumvent IDS systems. Botnets use artificial intelligence to improve their Domain Name Generation Algorithms. Botnets pose a serious threat to networks that are connected to the Internet and are an enabler for many cyber-criminal activities (e.g., DDoS attacks, banking fraud and cyber-espionage) and cause substantial economic damage. To circumvent detection and prevent takedown actions, bot-masters use DGAs to create, maintain and hide C&C infrastructures. Furthermore, botmasters often release its source code to prevent detection, leading to numerous similar botnets that are created and maintained by different botmasters. As these botnets are based on nearly the same source code basis, they often share similar observable behavior. Current work on detection of DGAs is often based on applying machine learning techniques, as they are capable to generalize and to also detect yet unknown derivatives of a known botnets. However, these machine learning based classifiers can be circumvented by applying adversarial learning techniques. As a consequence, there is a need for resilience against adversarial learning in current Intrusion Detection Systems. In our work, we focus on adversarial learning in DNS based IDSs from the perspective of a network operator. Further, we present our concept to make existing and future machine learning based IDSs more resilient against adversarial learning attacks by applying multi-level Moving Target Defense strategies. Christian Dietz, Gabi Dreo Rodosek, Anna Sperotto, Aiko Pras |
NOMS | 3 |
| 2020 | DDoS Mitigation: A Measurement-Based ApproachabstractSociety heavily relies upon the Internet for global communications. Simultaneously, Internet stability and reliability are continuously subject to deliberate threats. These threats include (Distributed) Denial-of-Service (DDoS) attacks, which can potentially be devastating. As a result of DDoS, businesses lose hundreds of millions of dollars annually. Moreover, when it comes to vital infrastructure, national safety and even lives could be at stake. Effective defenses are therefore an absolute necessity. Prospective users of readily available mitigation solutions find themselves having many shapes and sizes to choose from, the right fit of which may, however, not always be apparent. In addition, the deployment and operation of mitigation solutions may come with hidden hazards that need to be better understood. Policy makers and governments also find themselves facing questions concerning what needs to be done to promote cybersafety on a national level. Developing an optimal course of action to deal with DDoS, therefore, also brings about societal challenges. Even though the DDoS problem is by no means new, the scale of the problem is still unclear. We do not know exactly what it is we are defending against and getting a better understanding of attacks is essential to addressing the problem head-on. To advance situational awareness, many technical and societal challenges need still to be tackled. Given the central importance of better understanding the DDoS problem to improve overall Internet security, the thesis that we summarize in this paper has three main contributions. First, we rigorously characterize attacks and attacked targets at scale. Second, we advance knowledge about the Internet-wide adoption, deployment and operational use of various mitigation solutions. Finally, we investigate hidden hazards that can render mitigation solutions altogether ineffective. Mattijs Jonker, Anna Sperotto, Aiko Pras |
NOMS | 2 |
| 2020 | Distributed DDoS Defense: A collaborative Approach at Internet ScaleabstractDistributed large-scale cyber attacks targeting the availability of computing and network resources still remain a serious threat. To limit the effects caused by those attacks and to provide a proactive defense, mitigation should move to the networks of Internet Service Providers (ISPs). In this context, this thesis focuses on a development of a collaborative, automated approach to mitigate the effects of Distributed Denial of Service (DDoS) attacks at Internet Scale. This thesis has the following contributions: i) a systematic and multifaceted study on mitigation of large-scale cyber attacks at ISPs. ii) A detailed guidance selecting an exchange format and protocol suitable to use to disseminate threat information. iii) To overcome the shortcomings of missing flow-based interoperability of current exchange formats, a development of the exchange format Flow-based Event Exchange Format (FLEX). iv) A communication process to facilitate the automated defense in response to ongoing network-based attacks, v) a model to select and perform a semi-automatic deployment of suitable response actions. vi) An investigation of the effectiveness of the defense techniques moving-target using Software Defined Networking (SDN) and their applicability in context of large-scale cyber attacks and the networks of ISPs. Finally, a trust model that determines a trust and a knowledge level of a security event to deploy semi-automated remediations and facilitate the dissemination of security event information using the exchange format FLEX in context of ISP networks. Jessica Steinberger, Anna Sperotto, Harald Baier, Aiko Pras |
NOMS | 2 |
| 2020 | When Parents and Children Disagree: Diving into DNS Delegation Inconsistency
Raffaele Sommese, Giovane Cesar Moreira Moura, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
PAM | 7 |
| 2018 | A First Joint Look at DoS Attacks and BGP Blackholing in the Wild
Mattijs Jonker, Aiko Pras, Alberto Dainotti, Anna Sperotto |
Internet Measurement Conference | 4 |
| 2018 | DDoS defense using MTD and SDNabstractDistributed large-scale cyber attacks targeting the availability of computing and network resources still remains a serious threat. In order to limit the effects caused by those attacks and to provide a proactive defense, mitigation should move to the networks of Internet Service Providers. In this context, Moving Target Defense (MTD) is a technique that increases uncertainty due to an ever-changing attack surface. In combination with Software Defined Networking (SDN), MTD has the potential to reduce the effects of a large-scale cyber attack. In this paper, we combine the defense techniques moving-target using Software Defined Networking and investigate their effectiveness. We review current moving-target defense strategies and their applicability in context of large-scale cyber attacks and the networks of Internet Service Providers. Further, we enforce the implementation of moving target defense strategies using Software Defined Networks in a collaborative environment. In particular, we focus on ISPs that cooperate among trusted partners. We found that the effects of a large-scale cyber attack can be significantly reduced using the moving-target defense and Software Defined Networking. Moreover, we show that Software Defined Networking is an appropriate approach to enforce implementation of the moving target defense and thus mitigate the effects caused by large-scale cyber attacks. Jessica Steinberger, Benjamin Kuhnert, Christian Dietz, Lisa Ball, Anna Sperotto, Harald Baier, Aiko Pras, Gabi Dreo Rodosek |
NOMS | 5 |
| 2018 | Melting the snow: Using active DNS measurements to detect snowshoe spam domainsabstractSnowshoe spam is a type of spam that is notoriously hard to detect. Anti-abuse vendors estimate that 15% of spam can be classified as snowshoe spam. Differently from regular spam, snowshoe spammers distribute sending of spam over many hosts, in order to evade detection by spam reputation systems (blacklists). To be successful spammers need to appear as legitimate as possible, for example, by adopting email best practices, such as the Sender Policy Framework (SPF). This requires spammers to register and configure legitimate DNS domains. Many previous studies have relied on DNS data to detect spam. However, this often happens based on passive DNS data. This limits detection to domains that have actually been used and have been observed on passive DNS sensors. To overcome this limitation, we take a different approach. We make use of active DNS measurements, covering more than 60% of the global DNS namespace, in combination with machine learning to identify malicious domains crafted for snowshoe spam. Our results show that we are able to detect snowshoe spam domains with a precision of over 93%. More importantly, we are able to detect a significant fraction of the malicious domains up to 100 days earlier than existing blacklists, which suggests our method can give us a time advantage in the fight against spam. In addition to testing the efficacy of our approach in comparison to existing blacklists, we validated our approach over a 3-month period in an actual mail filter system at a major Dutch network operator. Not only did this demonstrate that our approach works in practice, the operator has actually decided to deploy our method in production, based on the results obtained. Olivier van der Toorn, Roland van Rijswijk-Deij, Bart Geesink, Anna Sperotto |
NOMS | 4 |
| 2017 | Measuring exposure in DDoS protection servicesabstractDenial-of-Service attacks have rapidly gained in popularity over the last decade. The increase in frequency, size, and complexity of attacks has made DDoS Protection Services (DPS) an attractive mitigation solution to which the protection of services can be outsourced. Despite a thriving market and increasing adoption of protection services, a DPS can often be bypassed, and direct attacks can be launched against the origin of a target. Many protection services leverage the Domain Name System (DNS) to protect, e.g., Web sites. When the DNS is misconfigured, the origin IP address of a target can leak to attackers, which defeats the purpose of outsourcing protection. We perform a large-scale analysis of this phenomenon by using three large data sets that cover a 16-month period: a data set of active DNS measurements; a DNS-based data set that focuses on DPS adoption; and a data set of DoS attacks inferred from backscatter traffic to a sizable darknet. We analyze nearly 11k Web sites on Alexa's top 1M that outsource protection, for eight leading DPS providers. Our results show that 40% of these Web sites expose the origin in the DNS. Moreover, we show that the origin of 19% of these Web sites is targeted after outsourcing protection. Mattijs Jonker, Anna Sperotto |
CNSM | 2 |
| 2017 | Millions of targets under attack: a macroscopic characterization of the DoS ecosystemabstractDenial-of-Service attacks have rapidly increased in terms of frequency and intensity, steadily becoming one of the biggest threats to Internet stability and reliability. However, a rigorous comprehensive characterization of this phenomenon, and of countermeasures to mitigate the associated risks, faces many infrastructure and analytic challenges. We make progress toward this goal, by introducing and applying a new framework to enable a macroscopic characterization of attacks, attack targets, and DDoS Protection Services (DPSs). Our analysis leverages data from four independent global Internet measurement infrastructures over the last two years: backscatter traffic to a large network telescope; logs from amplification honeypots; a DNS measurement platform covering 60% of the current namespace; and a DNS-based data set focusing on DPS adoption. Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all / 24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks. In our data, Web servers were the most prominent attack target; an average of 3% of the Web sites in .com, .net, and .org were involved with attacks, daily. Finally, we shed light on factors influencing migration to a DPS. Mattijs Jonker, Alistair King, Johannes Krupp, Christian Rossow, Anna Sperotto, Alberto Dainotti |
Internet Measurement Conference | 5 |
| 2017 | The Performance Impact of Elliptic Curve Cryptography on DNSSEC ValidationabstractThe domain name system (DNS) is a core Internet infrastructure that translates names to machine-readable information, such as IP addresses. Security flaws in DNS led to a major overhaul, with the introduction of the DNS security (DNSSEC) extensions. DNSSEC adds integrity and authenticity to the DNS using digital signatures. DNSSEC, however, has its own concerns. It suffers from availability problems due to packet fragmentation and is a potent source of distributed denial-of-service attacks. In earlier work, we argued that many issues with DNSSEC stem from the choice of RSA as default signature algorithm. A switch to alternatives based on elliptic curve cryptography (ECC) can resolve these issues. Yet switching to ECC introduces a new problem: ECC signature validation is much slower than RSA validation. Thus, switching DNSSEC to ECC imposes a significant additional burden on DNS resolvers, pushing load toward the edges of the network. Therefore, in this paper, we study the question: will switching DNSSEC to ECC lead to problems for DNS resolvers, or can they handle the extra load? To answer this question, we developed a model that accurately predicts how many signature validations DNS resolvers have to perform. This allows us to calculate the additional CPU load ECC imposes on a resolver. Using real-world measurements from four DNS resolvers and with two open-source DNS implementations, we evaluate future scenarios where DNSSEC is universally deployed. Our results conclusively show that switching DNSSEC to ECC signature schemes does not impose an insurmountable load on DNS resolvers, even in worst case scenarios. Roland van Rijswijk-Deij, Kaspar Hageman, Anna Sperotto, Aiko Pras |
IEEE/ACM Trans. Netw. | 3 |
| 2016 | On the adoption of the elliptic curve digital signature algorithm (ECDSA) in DNSSECabstractThe Domain Name System Security Extensions (DNSSEC) are steadily being deployed across the Internet. DNSSEC extends the DNS protocol with two vital security properties, authenticity and integrity, using digital signatures. While DNSSEC is meant to solve security issues in the DNS, it also introduces a new one: the digital signatures significantly increase DNS packet sizes, making DNSSEC an attractive vector to abuse in amplification denial-of-service attacks. By default, DNSSEC uses RSA for digital signatures. Earlier work has shown that alternative signature schemes, based on elliptic curve cryptography, can significantly reduce the impact of signatures on DNS response sizes. In this paper we study the actual adoption of ECDSA by DNSSEC operators, based on longitudinal datasets covering over 50% of the global DNS namespace over a period of 1.5 years. Adoption is still marginal, with just 2.3% of DNSSEC-signed domains in the .com TLD using ECDSA. Nevertheless, use of ECDSA is growing, with at least one large operator leading the pack. And adoption could be up to 42% higher. As we demonstrate, there are barriers to deployment that hamper adoption. Operators wishing to deploy DNSSEC using current recommendations (with ECDSA as signing algorithm) must be mindful of this when planning their deployment. Roland van Rijswijk-Deij, Mattijs Jonker, Anna Sperotto |
CNSM | 3 |
| 2016 | Measuring the Adoption of DDoS Protection Services
Mattijs Jonker, Anna Sperotto, Roland van Rijswijk-Deij, Ramin Sadre, Aiko Pras |
Internet Measurement Conference | 2 |
| 2016 | Collaborative DDoS defense using flow-based security event informationabstractOver recent years, network-based attacks evolved to the top concerns responsible for network infrastructure and service outages. To counteract such attacks, an approach is to move mitigation from the target network to the networks of Internet Service Providers (ISP). In addition, exchanging threat information among trusted partners is used to reduce the time needed to detect and respond to large-scale network-based attacks. However, exchanging threat information is currently done on an ad-hoc basis via email or telephone, and there is still no interoperable standard to exchange threat information among trusted partners. To facilitate the exchange of security event information in conjunction with widely adopted monitoring technologies, in particular network flows, we make use of the exchange format FLEX. The goal of this paper is to present a communication process that supports the dissemination of threat information based on FLEX in context of ISPs. We show that this communication process helps organizations to speed up their mitigation and response capabilities without the need to modify the current network infrastructure, and hence make it viable to use for network operators. Jessica Steinberger, Benjamin Kuhnert, Anna Sperotto, Harald Baier, Aiko Pras |
NOMS | 3 |
| 2016 | A High-Performance, Scalable Infrastructure for Large-Scale Active DNS MeasurementsabstractThe domain name system (DNS) is a core component of the Internet. It performs the vital task of mapping human readable names into machine readable data (such as IP addresses, which hosts handle e-mail, and so on). The content of the DNS reveals a lot about the technical operations of a domain. Thus, studying the state of large parts of the DNS over time reveals valuable information about the evolution of the Internet. We collect a unique long-term data set with daily DNS measurements for all the domains under the main top-level domains (TLDs) on the Internet (including .com, .net, and .org, comprising 50% of the global DNS name space). This paper discusses the challenges of performing such a large-scale active measurement. These challenges include scaling the daily measurement to collect data for the largest TLD (.com, with 123M names) and ensuring that a measurement of this scale does not impose an unacceptable burden on the global DNS infrastructure. The paper discusses the design choices we have made to meet these challenges and documents the design of the measurement system we implemented based on these choices. Two case studies related to cloud e-mail services illustrate the value of measuring the DNS at this scale. The data this system collects is valuable to the network research community. Therefore, we end this paper by discussing how we make the data accessible to other researchers. Roland van Rijswijk-Deij, Mattijs Jonker, Anna Sperotto, Aiko Pras |
IEEE J. Sel. Areas Commun. | 3 |
| 2015 | Unveiling flat traffic on the Internet: An SSH attack case studyabstractMany types of brute-force attacks are known to exhibit a characteristic `flat' behavior at the network-level, meaning that connections belonging to an attack feature a similar number of packets and bytes, and duration. Flat traffic usually results from repeating similar application-layer actions, such as login attempts in a brute-force attack. For typical attacks, hundreds of attempts span over multiple connections, with each connection containing the same, small number of attempts. The characteristic flat behavior is used by many Intrusion Detection Systems (IDSes), both for identifying the presence of attacks and - once detected - for observing deviations, pointing out potential compromises, for example. However, flatness of network traffic may become indistinct when TCP retransmissions and control information come into play. These TCP phenomena affect not only intrusion detection, but also other forms of network traffic analysis. The contribution of this work is twofold. First, we analyze the impact of retransmissions and control information on network traffic based on traffic measurements. To do so, we have developed a flow exporter extension that was deployed in both a campus and a backbone network. Second, we show that intrusion detection results improve dramatically by up to 16 percentage points once IDSes are able to `flatten' network traffic again, which we have validated by means of analyzing log files of almost 60 hosts over a period of one month. Mattijs Jonker, Rick Hofstede, Anna Sperotto, Aiko Pras |
IM | 3 |
| 2015 | Inside booters: An analysis on operational databasesabstractDistributed Denial of Service (DDoS) attacks are an increasing threat on the Internet. One of the reasons is that Web sites selling attacks for prices starting from $1.00 are becoming popular. These Web sites, called Booters, facilitate attacks by making transparent the needed infrastructure to perform attacks and by lowering the knowledge to control it. As a consequence, any user on the Internet is able to launch attacks at any time. Although security experts and operators acknowledge the potential of Booters for DDoS attacks, little is known about Booters operational aspects in terms of users, attacks and infrastructure. The existing works that investigate this phenomenon are all restricted to the analysis of a single Booter and therefore provide a narrow overview of the phenomenon. In this paper we extend the existing work by providing an extensive analysis on 15 distinct Booters. We analyze their operational databases containing logs of users, attacks, and the infrastructure used to perform attacks. Among our findings we reveal that (i) some Booters have several database records completely equal, (ii) users that access Booters via proxies and VPNs performed much more attacks than those that accessed using a single IP address, and (iii) the infrastructure used to perform attacks is slightly different from what is known through existing work. The contribution of our work is to bring awareness of Booter characteristics facilitating future works to mitigate this phenomenon. José Jair Santanna, Romain Durban, Anna Sperotto, Aiko Pras |
IM | 3 |
| 2015 | Booters - An analysis of DDoS-as-a-service attacksabstractIn 2012, the Dutch National Research and Education Network, SURFnet, observed a multitude of Distributed Denial of Service (DDoS) attacks against educational institutions. These attacks were effective enough to cause the online exams of hundreds of students to be cancelled. Surprisingly, these attacks were purchased by students from Web sites, known as Booters. These sites provide DDoS attacks as a paid service (DDoS-as-a-Service) at costs starting from 1 USD. Since this problem was first identified by SURFnet, Booters have been used repeatedly to perform attacks on schools in SURFnet's constituency. Very little is known, however, about the characteristics of Booters, and particularly how their attacks are structure. This is vital information needed to mitigate these attacks. In this paper we analyse the characteristics of 14 distinct Booters based on more than 250 GB of network data from real attacks. Our findings show that Booters pose a real threat that should not be underestimated, especially since our analysis suggests that they can easily increase their firepower based on their current infrastructure. José Jair Santanna, Roland van Rijswijk-Deij, Rick Hofstede, Anna Sperotto, Mark Wierbosch, Lisandro Z. Granville, Aiko Pras |
IM | 4 |
| 2015 | Real-time DDoS attack detection for Cisco IOS using NetFlowabstractFlow-based DDoS attack detection is typically performed by analysis applications that are installed on or close to a flow collector. Although this approach allows for easy deployment, it makes detection far from real-time and susceptible to DDoS attacks for the following reasons. First, the fact that the flow export process is timeout-based and that flow collectors typically provide data to analysis applications in chunks, can result in detection delays in the order of several minutes. Second, by the nature of flow export, attack traffic may be amplified by the flow export process if the original packets are small enough and are part of small flows. We have shown in a previous work how to perform DDoS attack detection on a flow exporter instead of a flow collector, i.e., close to the data source and in a real-time fashion, which however required access to a fully-extendible flow monitoring infrastructure. In this work, we investigate whether it is possible to operate the same detection system on a widely deployed networking platform: Cisco IOS. Since our ultimate goal is to identify besides the presence of an attack also attackers and targets, we rely on NetFlow. In this context, we present our DDoS attack detection prototype that has shown to generate a constant load on the underlying platform - even under attacks - underlining that DDoS attack detection can be performed on a Cisco Catalyst 6500 in production networks, if enough spare capacity is available. Daniel van der Steeg, Rick Hofstede, Anna Sperotto, Aiko Pras |
IM | 3 |
| 2015 | Collaborative attack mitigation and response: A surveyabstractOver recent years, network-based attacks have become one of the top causes of network infrastructure and service outages. To counteract such attacks, an approach is to move mitigation from the target network to the networks of Internet Service Providers (ISP). However, it remains unclear to what extent countermeasures are set up and which mitigation approaches are adopted by ISPs. The goal of this paper is to present the results of a survey that aims to gain insight into processes, structures and capabilities of ISPs to mitigate and respond to network-based attacks. Jessica Steinberger, Anna Sperotto, Harald Baier, Aiko Pras |
IM | 2 |
| 2015 | How to exchange security events? Overview and evaluation of formats and protocolsabstractNetwork-based attacks pose a strong threat to the Internet landscape. Recent approaches to mitigate and resolve these threats focus on cooperation of Internet service providers and their exchange of security event information. A major benefit of a cooperation is that it might counteract a network-based attack at its root and provides the possibility to inform other cooperative partners about the occurrence of anomalous events as a proactive service. In this paper we provide a structured overview of existing exchange formats and protocols. We evaluate and compare the exchange formats and protocols in context of high-speed networks. In particular, we focus on flow data. In addition, we investigate the exchange of potentially sensitive data. For our overview, we review different exchange formats and protocols with respect to their use-case scenario, their interoperability with network flow-based data, their scalability in a high-speed network context and develop a classification. Jessica Steinberger, Anna Sperotto, Mario Golling, Harald Baier |
IM | 2 |
| 2015 | A first look at HTTP(S) intrusion detection using NetFlow/IPFIXabstractBrute-force attacks against Web site are a common area of concern, both for Web site owners and hosters. This is mainly due to the impact of potential compromises resulting therefrom, and the increased load on the underlying infrastructure. The latter may even result in a Denial-of-Service (DoS). Detecting brute-force attacks - and ultimately mitigating them - is therefore of great importance. In this paper, we take the first step in this direction, by presenting a network-based approach for detecting HTTP(S) dictionary attacks using NetFlow/IPFIX. We have developed a prototype Intrusion Detection System (IDS), released as open-source software, by means of which we can achieve accuracies close to 100%. Olivier van der Toorn, Rick Hofstede, Mattijs Jonker, Anna Sperotto |
IM | 4 |
| 2015 | The Internet of Names: A DNS Big DatasetabstractThe Domain Name System (DNS) is part of the core infrastructure of the Internet. Tracking changes in the DNS over time provides valuable information about the evolution of the Internet's infrastructure. Until now, only one large-scale approach to perform these kinds of measurements existed, passive DNS (pDNS). While pDNS is useful for applications like tracing security incidents, it does not provide sufficient information to reliably track DNS changes over time. We use a complementary approach based on active measurements, which provides a unique, comprehensive dataset on the evolution of DNS over time. Our high-performance infrastructure performs Internet-scale active measurements, currently querying over 50% of the DNS name space on a daily basis. Our infrastructure is designed from the ground up to enable big data analysis approaches on, e.g., a Hadoop cluster. With this novel approach we aim for a quantum leap in DNS-based measurement and analysis of the Internet. Roland van Rijswijk-Deij, Mattijs Jonker, Anna Sperotto, Aiko Pras |
SIGCOMM | 3 |
| 2015 | Impact of Packet Sampling on Link DimensioningabstractLink dimensioning is used by network operators to properly provision the capacity of their network links. Proposed methods for link dimensioning often require statistics, such as traffic variance, that need to be calculated from packet-level measurements. In practice, due to increasing traffic volume, operators deploy packet sampling techniques aiming to reduce the burden of traffic monitoring, but little is known about how link dimensioning is affected by such measurements. In this paper, we make use of a previously proposed and validated dimensioning formula that requires traffic variance to estimate required link capacity. We assess the impact of three packet sampling techniques on link dimensioning, namely, Bernoulli, n-in-N and sFlow sampling. To account for the additional variance introduced by the sampling algorithms, we propose approaches to better estimate traffic variance from sampled data according to the employed technique. Results show that, depending on sampling rate and link load, packet sampling does not negatively impact on link dimensioning accuracy even at very short timescales such as 10 ms. Moreover, we also show that the loss of inter-arrival time of sampled packets due to the exporting process in sFlow does not harm the estimations, given that an appropriate sampling rate is used. Our study is validated using a large dataset consisting of traffic packet traces captured at several locations around the globe. Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Hans van den Berg, Aiko Pras |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2014 | DNSSEC and its potential for DDoS attacks: a comprehensive measurement studyabstractOver the past five years we have witnessed the introduction of DNSSEC, a security extension to the DNS that relies on digital signatures. DNSSEC strengthens DNS by preventing attacks such as cache poisoning. However, a common argument against the deployment of DNSSEC is its potential for abuse in Distributed Denial of Service (DDoS) attacks, in particular reflection and amplification attacks. DNS responses for a DNSSEC-signed domain are typically larger than those for an unsigned domain, thus, it may seem that DNSSEC could actually worsen the problem of DNS-based DDoS attacks. The potential for abuse in DNSSEC-signed domains has, however, never been assessed on a large scale. Roland van Rijswijk-Deij, Anna Sperotto, Aiko Pras |
Internet Measurement Conference | 2 |
| 2014 | A hybrid procedure for efficient link dimensioning
Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Hans van den Berg, Aiko Pras |
Comput. Networks | 3 |
| 2013 | Towards real-time intrusion detection for NetFlow and IPFIXabstractDDoS attacks bring serious economic and technical damage to networks and enterprises. Timely detection and mitigation are therefore of great importance. However, when flow monitoring systems are used for intrusion detection, as it is often the case in campus, enterprise and backbone networks, timely data analysis is constrained by the architecture of NetFlow and IPFIX. In their current architecture, the analysis is performed after certain timeouts, which generally delays the intrusion detection for several minutes. This paper presents a functional extension for both NetFlow and IPFIX flow exporters, to allow for timely intrusion detection and mitigation of large flooding attacks. The contribution of this paper is threefold. First, we integrate a lightweight intrusion detection module into a flow exporter, which moves detection closer to the traffic observation point. Second, our approach mitigates attacks in near real-time by instructing firewalls to filter malicious traffic. Third, we filter flow data of malicious traffic to prevent flow collectors from overload. We validate our approach by means of a prototype that has been deployed on a backbone link of the Czech national research and education network CESNET. Rick Hofstede, Václav Bartos, Anna Sperotto, Aiko Pras |
CNSM | 3 |
| 2013 | Lightweight link dimensioning using sFlow samplingabstractOperators use link dimensioning to provision network links. In practice, traffic averages are obtained via SNMP are used to roughly estimate required capacity. More accurate solutions often require traffic statistics easily obtained from packet captures, e.g. variance. However, packet capturing may not be trivial in high-speed links. Aiming scalability, operators often deploy packet sampling on monitoring, but little is known how it affects link dimensioning. In this paper we assess the feasibility of lightweight link dimensioning using sFlow, which is a widely-deployed traffic monitoring tool. We implement sFlow sampling algorithm and use a previously proposed and validated dimensioning formula that needs traffic variance.We validate our approach using packet captures from real networks. Results show that the proposed procedure is successful for a range of sampling rates and that, due to randomness of sampling algorithm, the error introduced by scaling the traffic variance yields more conservative results that cope with short-term traffic fluctuations. Ricardo de Oliveira Schmidt, Ramin Sadre, Anna Sperotto, Aiko Pras |
CNSM | 3 |
| 2013 | Evaluating third-party Bad Neighborhood blacklists for Spam detection
Giovane Cesar Moreira Moura, Anna Sperotto, Ramin Sadre, Aiko Pras |
IM | 2 |
| 2013 | Measurement Artifacts in NetFlow Data
Rick Hofstede, Idilio Drago, Anna Sperotto, Ramin Sadre, Aiko Pras |
PAM | 3 |
| 2012 | Inside dropbox: understanding personal cloud storage servicesabstractPersonal cloud storage services are gaining popularity. With a rush of providers to enter the market and an increasing offer of cheap storage space, it is to be expected that cloud storage will soon generate a high amount of Internet traffic. Very little is known about the architecture and the performance of such systems, and the workload they have to face. This understanding is essential for designing efficient cloud storage systems and predicting their impact on the network. Idilio Drago, Marco Mellia, Maurizio M. Munafò, Anna Sperotto, Ramin Sadre, Aiko Pras |
Internet Measurement Conference | 4 |
| 2012 | Internet bad neighborhoods aggregationabstractInternet Bad Neighborhoods have proven to be an innovative approach for fighting spam. They have also helped to understand how spammers are distributed on the Internet. In our previous works, the size of each bad neighborhood was fixed to a /24 subnetwork. In this paper, however, we investigate if it is feasible to aggregate Internet bad neighborhoods not only at /24, but to any network prefix. To do that, we propose two different aggregation strategies: fixed prefix and variable prefix. The motivation for doing that is to reduce the number of entries in the bad neighborhood list, thus reducing memory storage requirements for intrusion detection solutions. We also introduce two error measures that allow to quantify how much error was incurred by the aggregation process. An evaluation of both strategies was conducted by analyzing real world data in our aggregation prototype. Giovane Cesar Moreira Moura, Ramin Sadre, Anna Sperotto, Aiko Pras |
NOMS | 3 |
| 2012 | The effects of DDoS attacks on flow monitoring applicationsabstractFlow-based monitoring has become a popular approach in many areas of network management. However, flow monitoring is, by design, susceptible to anomalies that generate a large number of flows, such as Distributed Denial-Of-Service attacks. This paper aims at getting a better understanding on how a flow monitoring application reacts to the presence of massive attacks. We analyze the performance of a flow monitoring application from the perspective of the flow data it has to process. We first identify the changes in the flow data caused by a massive attack and propose a simple queueing model that describes the behavior of the flow monitoring application. Secondly, we present a case study based on a real attack trace collected at the University of Twente and we analyze the performance of the flow monitoring application by means of simulation experiments. We conclude that the observed changes in the flow data might cause unwanted effects in monitoring applications. Furthermore, our results show that our model can help to parametrize and dimension flow-based monitoring systems. Ramin Sadre, Anna Sperotto, Aiko Pras |
NOMS | 2 |
| 2012 | Autonomic Parameter Tuning of Anomaly-Based IDSs: an SSH Case StudyabstractAnomaly-based intrusion detection systems classify network traffic instances by comparing them with a model of the normal network behavior. To be effective, such systems are expected to precisely detect intrusions (high true positive rate) while limiting the number of false alarms (low false positive rate). However, there exists a natural trade-off between detecting all anomalies (at the expense of raising alarms too often), and missing anomalies (but not issuing any false alarms). The parameters of a detection system play a central role in this trade-off, since they determine how responsive the system is to an intrusion attempt. Despite the importance of properly tuning the system parameters, the literature has put little emphasis on the topic, and the task of adjusting such parameters is usually left to the expertise of the system manager or expert IT personnel. In this paper, we present an autonomic approach for tuning the parameters of anomaly-based intrusion detection systems in case of SSH traffic. We propose a procedure that aims to automatically tune the system parameters and, by doing so, to optimize the system performance. We validate our approach by testing it on a flow-based probabilistic detection system for the detection of SSH attacks. Anna Sperotto, Michel Mandjes, Ramin Sadre, Pieter-Tjerk de Boer, Aiko Pras |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2011 | Flow-based intrusion detectionabstractThe spread of 1-10 Gbps technology has in recent years paved the way to a flourishing landscape of new, high-bandwidth Internet services. At the same time, we have also observed increasingly frequent and widely diversified attacks. To this threat, the research community has answered with a growing interest in intrusion detection, aiming to timely detect intruders and prevent damage. We believe that the detection problem is a key component in the field of intrusion detection. Our studies, however, made us realize that additional research is needed, in particular focusing on validation and automatic tuning of Intrusion Detection Systems (IDSs). Anna Sperotto, Aiko Pras |
Integrated Network Management | 1 |
| 2009 | Self-management of hybrid networks: Can we trust netflow data?abstractNetwork measurement provides vital information on the health of managed networks. The collection of network information can be used for several reasons (e.g., accounting or security) depending on the purpose the collected data will be used for. At the University of Twente (UT), an automatic decision process for hybrid networks that relies on collected network information has been investigated. This approach, called self-management of hybrid networks requires information retrieved from measuring processes in order to automatically decide on establishing/releasing lambda-connections for IP flows that are long in duration and big in volume (known as elephant flows). Nonetheless, the employed measurement technique can break the self-management decisions if the reported information does not accurately describe the actual behavior and characteristics of the observed flows. Within this context, this paper presents an investigation on the trustfulness of measurements performed using the popular NetFlow monitoring solution when elephant flows are especially observed. We primarily focus on the use of NetFlow with sampling in order to collect network information and investigate how reliable such information is for the self-management processes. This is important because the self-management approach decides which flows should be off-loaded to the optical level based on the current state of the network and its running flows. We observe three specific flow metrics: octets, packets, and flow duration. Our analysis shows that NetFlow provides reliable information regarding octets and packets. On the other hand, the flow duration reported when sampling is employed tends to be shorter than the actual duration. Tiago Fioreze, Lisandro Z. Granville, Aiko Pras, Anna Sperotto, Ramin Sadre |
Integrated Network Management | 4 |