Rob Sherwood

dblp:63/4719 · DBLP profile ↗
← Back
19ranked-venue papers
10as first author
2since 2021 · last 2024
0009-0001-7798-8462ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 5 first-author · 2 since 2021Security and privacy · 4 · 3 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
10 papers
Network management and operations · 46% Software-defined and programmable networks · 29% Network measurement and analytics · 18%
Network and information security
4 papers
Network security · 85% Authentication and access control · 8% Privacy and data protection · 7%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Distributed systems · 73% Cloud and datacenter computing · 27%

Topics — the 26 heaviest of 31, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network management and operations
network testing
0.922024
Netcastle: Network Infrastructure Testing At Scale · NSDI 2024
Can the Production Network Be the Testbed? · OSDI 2010
Network management and operations
network verification
0.722023
P4Testgen: An Extensible Test Oracle For P4-16 · SIGCOMM 2023
Can the Production Network Be the Testbed? · OSDI 2010
Software-defined and programmable networks
programmable data plane
0.712023
P4Testgen: An Extensible Test Oracle For P4-16 · SIGCOMM 2023
Distributed systems
peer-to-peer systems
0.122009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Cooperative Peer Groups in NICE · INFOCOM 2003
Cloud and datacenter computing
datacenter network
0.112018
FBOSS: building switch software at scale · SIGCOMM 2018
Network security › attack resilience › attack mitigation › denial-of-service defense
denial-of-service resistance
0.112009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Network security › intrusion detection and prevention
intrusion detection
0.112009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Network security › intrusion detection and prevention › intrusion detection › network intrusion detection
malicious node detection
0.112009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Network security › content filtering
spam filtering
0.112009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Distributed systems › peer-to-peer systems
distributed hash table
0.112009
Fighting Spam with the NeighborhoodWatch DHT · INFOCOM 2009
Network measurement and analytics › topology discovery
alias resolution
0.112008
Fixing ally's growing pains with velocity modeling · Internet Measurement Conference 2008
Network measurement and analytics
internet topology mapping
0.112008
Fixing ally's growing pains with velocity modeling · Internet Measurement Conference 2008
Internet architecture and protocols
network topology
0.112008
Discarte: a disjunctive internet cartographer · SIGCOMM 2008
Network measurement and analytics
topology discovery
0.112008
Discarte: a disjunctive internet cartographer · SIGCOMM 2008
Network measurement and analytics
internet topology measurement
0.112006
Touring the internet in a TCP sidecar · Internet Measurement Conference 2006
Network measurement and analytics › topology discovery
router-level topology discovery
0.112006
Touring the internet in a TCP sidecar · Internet Measurement Conference 2006
Transport protocols and congestion control
congestion collapse
0.112005
Misbehaving TCP receivers can cause internet-wide congestion collapse · CCS 2005
Authentication and access control › trust management
trust evaluation
0.012003
Cooperative Peer Groups in NICE · INFOCOM 2003
Distributed systems › distributed system security › trust management
trust and reputation
0.012003
Cooperative Peer Groups in NICE · INFOCOM 2003
Privacy and data protection
anonymity
0.012002
P5: A Protocol for Scalable Anonymous Communication · S&P 2002
Network security
anonymity networks
0.012002
P5: A Protocol for Scalable Anonymous Communication · S&P 2002
Network measurement and analytics › topology measurement
router-level topology
0.012008
Fixing ally's growing pains with velocity modeling · Internet Measurement Conference 2008
Routing and switching
MPLS
0.012006
Touring the internet in a TCP sidecar · Internet Measurement Conference 2006
Network security › attack strategy
denial-of-service attack
0.012005
Misbehaving TCP receivers can cause internet-wide congestion collapse · CCS 2005
Content delivery and video streaming
server load reduction
0.012004
Slurpie: A Cooperative Bulk Data Transfer Protocol · INFOCOM 2004
Internet architecture and protocols › peer-to-peer networks
peer-to-peer protocols
0.012002
P5: A Protocol for Scalable Anonymous Communication · S&P 2002

Methods — techniques the papers use, named apart from their topics

taint tracking · 0.7concolic execution · 0.7cryptographic certificates · 0.2byzantine fault tolerance · 0.2simulation · 0.1optimistic acknowledgment attack · 0.1velocity modeling · 0.1distributed reputation storage · 0.1disjunctive cartography · 0.1active probing · 0.1TTL-limited probes · 0.1TCP sidecar · 0.1IP record route option · 0.1ICMP extensions · 0.1packet-level simulation · 0.0
YearPublicationVenuePosition
2024 Netcastle: Network Infrastructure Testing At Scale
Rob Sherwood, Jinghao Shi, Ying Zhang 0022, Neil Spring, Srikanth Sundaresan, Jasmeet Bagga, Prathyusha Peddi, Vineela Kukkadapu, Rashmi Shrivastava, Manikantan K., Pavan Patil, Srikrishna Gopu, Varun Varadan, Ethan Shi, Hany Morsy, Yuting Bu, Renjie Yang, Rasmus Jonsson, Jesus Jussepen Arredondo, Diana Saha, Sean Choi
NSDI1
2023 P4Testgen: An Extensible Test Oracle For P4-16
abstract
We present P4Testgen, a test oracle for the P416 language. P4Testgen supports automatic test generation for any P4 target and is designed to be extensible to many P4 targets. It models the complete semantics of the target's packet-processing pipeline including the P4 language, architectures and externs, and target-specific extensions. To handle non-deterministic behaviors and complex externs (e.g., checksums and hash functions), P4Testgen uses taint tracking and concolic execution. It also provides path selection strategies that reduce the number of tests required to achieve full coverage.
Fabian Ruffy, Jed Liu, Prathima Kotikalapudi, Vojtech Havel, Hanneli Tavante, Rob Sherwood, Vladyslav Dubina, Vladimir S. Peschanenko, Anirudh Sivaraman, Nate Foster
SIGCOMM6
2018 FBOSS: building switch software at scale
abstract
The conventional software running on network devices, such as switches and routers, is typically vendor-supplied, proprietary and closed-source; as a result, it tends to contain extraneous features that a single operator will not most likely fully utilize. Furthermore, cloud-scale data center networks often times have software and operational requirements that may not be well addressed by the switch vendors.
Sean Choi, Boris Burkov, Alex Eckert, Tian Fang, Saman Kazemkhani, Rob Sherwood, Ying Zhang 0022, Hongyi Zeng
SIGCOMM6
2012 OFLOPS: An Open Framework for OpenFlow Switch Evaluation
Charalampos Rotsos, Nadi Sarrar, Steve Uhlig, Rob Sherwood, Andrew W. Moore 0002
PAM4
2010 Can the Production Network Be the Testbed?
Rob Sherwood, Glen Gibb, Kok-Kiong Yap, Guido Appenzeller, Martín Casado, Nick McKeown, Guru M. Parulkar
OSDI1
2009 Fighting Spam with the NeighborhoodWatch DHT
abstract
In this paper, we present DHTBL, an anti-spam blacklist built upon a novel secure distributed hash table (DHT). We show how DHTBL can be used to replace existing DNS-based blacklists (DNSBLs) of IP addresses of mail relays that forward spam. Implementing a blacklist on a DHT improves resilience to DoS attacks and secures message delivery, when compared to DNSBLs. However, due to the sensitive nature of the blacklist, storing the data in a peer-to-peer DHT would invite attackers to infiltrate the system. Typical DHTs can withstand fail-stop failures, but malicious nodes may provide incorrect routing information, refuse to return published items, or simply ignore certain queries. The neighborhoodwatch DHT is resilient to malicious nodes and maintains the O(logiV) bounds on routing table size and expected lookup time. NeighborhoodWatch depends on two assumptions in order to make these guarantees: (1) the existence of an on-line trusted authority that periodically contacts and issues signed certificates to each node, and (2) for every sequence of k + 1 consecutive nodes in the ID space, at least one is alive and non-malicious. We show how NeighborhoodWatch maintains many of its security properties even when the second assumption is violated. Honest nodes in NeighborhoodWatch can detect malicious behavior and expel the responsible nodes from the DHT.
Adam Bender, Rob Sherwood, Derek Monner, Nathan Goergen, Neil Spring, Bobby Bhattacharjee
INFOCOM2
2008 Fixing ally's growing pains with velocity modeling
abstract
Mapping the router topology is an important component of Internet measurement. Alias resolution, the process of mapping IP addresses to routers, is critical to accurate Internet mapping. Ally, a popular alias resolution tool, was developed to resolve aliases in individual ISPs, but its probabilistic accuracy and need to send O(n2) probes to infer aliases among n IP addresses make it unappealing for large-scale Internet mapping. In this paper, we present RadarGun, a tool that uses IP identifier velocity modeling to improve the accuracy and scalability of the Ally-based resolution technique. We provide analytical bounds on Ally's accuracy and validate our predicted aliases against Ally. Additionally, we show that velocity modeling requires only O(n) probes and thus scales to Internet-sized mapping efforts.
Adam Bender, Rob Sherwood, Neil Spring
Internet Measurement Conference2
2008 Discarte: a disjunctive internet cartographer
Rob Sherwood, Adam Bender, Neil Spring
SIGCOMM1
2006 Touring the internet in a TCP sidecar
abstract
An accurate router-level topology of the Internet would benefit many research areas, including network diagnosis, inter-domain traffic engineering, and overlay construction. We present TCP Sidecar and Passenger, two elements of a system for router-level Internet topology discovery. Sidecar transparently injects measurement probes into non-measurement TCP streams, while Passenger combines TTL-limited probes with the often-ignored IP record route option. The combined approach mitigates problems associated with traceroute-based topology discovery, including abuse reports, spurious edge inference from multi-path routing, unresolved IP aliases, long network timeouts, and link discovery behind NATs and firewalls. We believe that we are the first mapping project to measure MPLS use with ICMP extensions and record route behavior when the TTL is not decremented. We are able to discover NATs when monitoring TCP connections that tunnel through them. In this paper, we present preliminary results for TCP Sidecar and Passenger on PlanetLab. Our experiments inject measurement probes into traffic generated both from the CoDeeN Web proxy project and from a custom web crawler to 166,745 web sites.
Rob Sherwood, Neil Spring
Internet Measurement Conference1
2006 Cooperative peer groups in NICE
Rob Sherwood, Seungjoon Lee, Bobby Bhattacharjee
Comput. Networks1
2005 Misbehaving TCP receivers can cause internet-wide congestion collapse
abstract
An optimistic acknowledgment (opt-ack) is an acknowledgment sent by a misbehaving client for a data segment that it has not received. Whereas previous work has focused on opt-ack as a means to greedily improve end-to-end performance, we study opt-ack exclusively as a denial of service attack. Specifically, an attacker sends optimistic acknowledgments to many victims in parallel, thereby amplifying its effective bandwidth by a factor of 30 million (worst case). Thus, even a relatively modest attacker can totally saturate the paths from many victims back to the attacker. Worse, a distributed network of compromised machines ("zombies") attacking in parallel can exploit over-provisioning in the Internet to bring about wide-spread, sustained congestion collapse.We implement this attack both in simulation and in a wide-area network, and show it severity both in terms of number of packets and total traffic generated. We engineer and implement a novel solution that does not require client or network modifications allowing for practical deployment. Additionally, we demonstrate the solution's efficiency on a real network.
Rob Sherwood, Bobby Bhattacharjee, Ryan Braud
CCS1
2005 An autonomous Earth observing sensorweb
abstract
We describe a network of sensors linked by software and the Internet to an autonomous satellite observation response capability. This system of systems is designed with a flexible, modular, architecture to facilitate expansion in sensors, customization of trigger conditions, and customization of responses. This system has been used to implement a global surveillance program of science phenomena including: volcanoes, flooding, cryosphere events, and atmospheric phenomena. In this paper we describe the importance of the earth observing sensorweb application as well as overall architecture for the system of systems.
Steve A. Chien, Benjamin Cichy, Ashley Davies, Daniel Tran, Gregg R. Rabideau, Rebecca Castaño, Rob Sherwood, Son V. Nghiem, Ronald Greeley, Thomas Doggett, Victor R. Baker, James M. Dohm, Felipe Ip, Dan Mandl, Stuart Frye, Seth Shulman, Stephen G. Ungar, Thomas Brakke, Jacques Descloitres, Jeremy Jones, Sandy Grosvenor, Rob Wright, Luke Flynn, Andy Harris, G. Robert Brakenridge, Sebastien Cacquard
SMC7
2005 The autonomous sciencecraft embedded systems architecture
abstract
An Autonomous Science Agent has been flying onboard the Earth Observing One spacecraft since 2003. This software enables the spacecraft to autonomously detect and responds to science events occurring on the Earth such as volcanoes, flooding, and snow melt. This agent includes artificial intelligence software systems that perform science data analysis, deliberative planning, and run-time robust execution. This software is in routine use to fly the EO-1 mission. In this paper we discuss the architecture used to integrate these systems and lessons learned from its multi-year flight on EO-1.
Steve A. Chien, Rob Sherwood, Daniel Tran, Benjamin Cichy, Gregg R. Rabideau, Rebecca Castaño, Ashley Davies, Stuart Frye, Bruce Trout, Jeff D'Agostino, Seth Shulman, Dan Mandl, Darrell Boyer, Sandra C. Hayden, Adam Sweet, Scott Christa
SMC2
2005 P5: A protocol for scalable anonymous communication
abstract
We present a protocol for anonymous communication over the Internet. Our protocol, called P 5 (Peer-to-Peer Personal Privacy Protocol) provides sender–, receiver–, and sender–receiver anonymity. P 5 is designed to be implemented over the current Inte
Rob Sherwood, Bobby Bhattacharjee, Aravind Srinivasan
J. Comput. Secur.1
2004 The Autonomous Sciencecraft Experiment Onboard the EO-1 Spacecraft
Daniel Tran, Steve A. Chien, Rob Sherwood, Rebecca Castaño, Benjamin Cichy, Ashley Davies, Gregg R. Rabideau
AAAI3
2004 Slurpie: A Cooperative Bulk Data Transfer Protocol
abstract
We present Slurpie: a peer-to-peer protocol for bulk data transfer. Slurpie is specifically designed to reduce client download times for large, popular files, and to reduce load on servers that serve these files. Slurpie employs a novel adaptive downloading strategy to increase client performance, and employs a randomized backoff strategy to precisely control load on the server. We describe a full implementation of the Slurpie protocol, and present results from both controlled local-area and wide-area testbeds. Our results show that Slurpie clients improve performance as the size of the network increases, and the server is completely insulated from large flash crowds entering the Slurpie network.
Rob Sherwood, Ryan Braud
INFOCOM1
2003 Cooperative Peer Groups in NICE
abstract
A distributed scheme for trust inference in peer-to-peer networks is presented. Our work is in context of the NICE system, which is a platform for implementing cooperative applications over the Internet. We describe a technique for efficiently storing user reputation information in a completely decentralized manner, and show how this information can be used to efficiently identify noncooperative users in NICE. We present a simulation based study of our algorithms, in which we show our scheme scales to thousands of users using modest amounts of storage, processing, and bandwidth at any individual node. Lastly, we show that our scheme is robust and can form cooperative groups in systems where the vast majority of users are malicious.
Seungjoon Lee, Rob Sherwood, Samrat Bhattacharjee
INFOCOM2
2002 P5: A Protocol for Scalable Anonymous Communication
abstract
We present a protocol for anonymous communication over the Internet. Our protocol, called P/sup 5/ (peer-to-peer personal privacy protocol) provides sender-, receiver-, and sender-receiver anonymity. P/sup 5/ is designed to be implemented over current Internet protocols, and does not require any special infrastructure support. A novel feature of P/sup 5/ is that it allows individual participants to trade-off degree of anonymity for communication efficiency, and hence can be used to scalably implement large anonymous groups. We present a description of P/sup 5/, an analysis of its anonymity and communication efficiency, and evaluate its performance using detailed packet-level simulations.
Rob Sherwood, Bobby Bhattacharjee, Aravind Srinivasan
S&P1
2001 Autonomously generating operations sequences for a Mars rover using AI-based planning
abstract
This paper discusses a proof-of-concept prototype for ground-based automatic generation of validated rover command sequences. This prototype is based on ASPEN (Automated Scheduling and Planning Environment). This Artificial Intelligence (AI) based planning and scheduling system will automatically generate a command sequence that will execute: within resource constraints and satisfy flight rules. An automated planning and scheduling system encodes rover design knowledge and uses the search and reasoning techniques to automatically generate low-level command sequences while respecting the rover operability constraints. This prototype planning system has been field-tested using the Rocky-7 rover at JPL, and will be field-tested on more complex rovers to prove its effectiveness before transferring the technology to flight operations for an upcoming NASA mission. The goal-driven commanding of planetary rovers greatly reduces the requirements for highly skilled rover engineering personnel. This in turn greatly reduces mission operations costs and permits a faster response to changes in rover states.
Rob Sherwood, Andrew Mishkin, Tara A. Estlin, Steve A. Chien, Paul Backes, Jeffrey S. Norris, Brian K. Cooper, Scott Maxwell, Gregg R. Rabideau
IROS1