Michael G. Kallitsis

dblp:68/4656 · also Michalis Kallitsis 0001 · DBLP profile ↗
← Back
16ranked-venue papers
5as first author
7since 2021 · last 2024
0000-0001-8086-499XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 3 first-author · 4 since 2021Security and privacy · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2024 Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS Handshakes
Diwen Xue, Michael G. Kallitsis, Amir Houmansadr, Roya Ensafi
USENIX Security Symposium2
2023 Cloud Watching: Understanding Attacks Against Cloud-Hosted Services
abstract
Cloud computing has dramatically changed service deployment patterns. In this work, we analyze how attackers identify and target cloud services in contrast to traditional enterprise networks and network telescopes. Using a diverse set of cloud honeypots in 5 providers and 23 countries as well as 2 educational networks and 1 network telescope, we analyze how IP address assignment, geography, network, and service-port selection, influence what services are targeted in the cloud. We find that scanners that target cloud compute are selective: they avoid scanning networks without legitimate services and they discriminate between geographic regions. Further, attackers mine Internet-service search engines to find exploitable services and, in some cases, they avoid targeting IANA-assigned protocols, causing researchers to misclassify at least 15% of traffic on select ports. Based on our results, we derive recommendations for researchers and operators.
Liz Izhikevich, Manda Tran, Michael G. Kallitsis, Aurore Fass, Zakir Durumeric
IMC3
2023 How to Operate a Meta-Telescope in your Spare Time
abstract
Unsolicited traffic sent to advertised network space that does not host active services provides insights about misconfigurations as well as potentially malicious activities, including the spread of Botnets, DDoS campaigns, and exploitation of vulnerabilities. Network telescopes have been used for many years to monitor such unsolicited traffic. Unfortunately, they are limi the available address space for such tasks and, thus, limited to specific geographic and/or network regions.
Sahil Ashish Ranadive, Harm Griffioen, Michael G. Kallitsis, Alberto Dainotti, Georgios Smaragdakis, Anja Feldmann
IMC4
2022 AMON-SENSS: Scalable and Accurate Detection of Volumetric DDoS Attacks at ISPs
abstract
Distributed Denial of Service (DDoS) attacks continue to be a severe threat to the Internet, and have been evolving both in traffic volume and in sophistication. While many attack detection approaches exist, few of them provide easily interpretable and actionable network-level signatures. Further, most tools are either not scalable or are prohibitively expensive, and thus are not broadly available to network operators. We bridge this gap by proposing AMON-SENSS, an open-source system for scalable, accurate DDoS detection and signature generation in large networks. AMON-SENSS employs hash-based binning with multiple bin layers for scalability, observes traffic at multiple granularities, and deploys traffic volume and traffic asymmetry change-point detection techniques to identify attacks. It proactively devises network-level attack signatures, which can be used to filter attack traffic. We evaluate AMON-SENSS against two commercial defense systems, using 37 days of real traffic from a mid-size Internet Service Provider (ISP). We find that our proposed approach exhibits superior performance in terms of accuracy, detection time and network signature quality over commercial alternatives. AMON-SENSS is deployable today, it is free, and requires no hardware or routing changes.
Rajat Tandon, Pithayuth Charnsethikul, Michael G. Kallitsis, Jelena Mirkovic
GLOBECOM3
2022 OpenVPN is Open to VPN Fingerprinting
Diwen Xue, Reethika Ramesh, Arham Jain, Michael G. Kallitsis, J. Alex Halderman, Jedidiah R. Crandall, Roya Ensafi
USENIX Security Symposium4
2022 Detecting and Interpreting Changes in Scanning Behavior in Large Network Telescopes
abstract
Network telescopes or “Darknets” received unsolicited Internet-wide traffic, thus providing a unique window into macroscopic Internet activities associated with malware propagation, denial of service attacks, network reconnaissance, misconfigurations and network outages. Analysis of the resulting data can provide actionable insights to security analysts that can be used to prevent or mitigate cyber-threats. Large network telescopes, however, observe millions of nefarious scanning activities on a daily basis which makes the transformation of the captured information into meaningful threat intelligence challenging. To address this challenge, we present a novel framework for characterizing the structure and temporal evolution of scanning behaviors observed in network telescopes. The proposed framework includes four components. It (i) extracts a rich, high-dimensional representation ofscanning profilescomposed of features distilled from network telescope data; (ii) learns, in an unsupervised fashion, information-preservingsuccinct representationsof these scanning behaviors usingdeep representation learningthat is amenable to clustering; (iii) performsclusteringof the scanner profiles in the resulting latent representation space on daily Darknet data, and (iv)detects temporal changesin scanning behavior using techniques fromoptimal mass transport. We robustly evaluate the proposed system using both synthetic data and real-world Darknet data. We demonstrate its ability to detect real-world, high-impact cybersecurity incidents such as the onset of the Mirai botnet in late 2016 and several interesting cluster formations in early 2022 (e.g., heavy scanners, evolved Mirai variants, Darknet “backscatter” activities, etc.). Comparisons with state-of-the-art methods showcase that the integration of the proposed features with the deep representation learning scheme leads to better classification performance of Darknet scanners.
Michael G. Kallitsis, Rupesh Prajapati, Vasant G. Honavar, Dinghao Wu, John Yen
IEEE Trans. Inf. Forensics Secur.1
2021 Shedding light into the darknet: scanning characterization and detection of temporal changes
abstract
Network telescopes provide a unique window into Internet-wide malicious activities associated with malware propagation, denial of service attacks, network reconnaissance, and others. Analyses of this telescope data can highlight ongoing malicious events in the Internet which can be used to prevent or mitigate cyber-threats in real-time. However, large telescopes observe millions of events on a daily basis which renders the task of transforming this knowledge to meaningful insights challenging. In order to address this, we present a novel framework for characterizing Internet's background radiation and for tracking its temporal evolution. The proposed framework: (i) Extracts a high dimensional representation of telescope scanners composed of features distilled from telescope data and learns an information-preserving low-dimensional representation of these events that is amenable to clustering; (ii) Performs clustering of resulting representation space to characterize the scanners and (iii) Utilizes the clustering outcomes as "signatures" to detect temporal changes in the network telescope.
Rupesh Prajapati, Vasant G. Honavar, Dinghao Wu, John Yen, Michael G. Kallitsis
CoNEXT5
2020 Running Refraction Networking for Real
abstract
Abstract Refraction networking is a next-generation censorship circumvention approach that locates proxy functionality in the network itself, at participating ISPs or other network operators. Following years of research and development and a brief pilot, we established the world’s first production deployment of a Refraction Networking system. Our deployment uses a highperformance implementation of the TapDance protocol and is enabled as a transport in the popular circumvention app Psiphon. It uses TapDance stations at four physical uplink locations of a mid-sized ISP, Merit Network, with an aggregate bandwidth of 140 Gbps. By the end of 2019, our system was enabled as a transport option in 559,000 installations of Psiphon, and it served upwards of 33,000 unique users per month. This paper reports on our experience building the deployment and operating it for the first year. We describe how we overcame engineering challenges, present detailed performance metrics, and analyze how our system has responded to dynamic censor behavior. Finally, we review lessons learned from operating this unique artifact and discuss prospects for further scaling Refraction Networking to meet the needs of censored users.
Benjamin VanderSloot, Sergey Frolov, Jack Wampler, Sze Chuen Tan, Irv Simpson, Michael G. Kallitsis, J. Alex Halderman, Nikita Borisov, Eric Wustrow
Proc. Priv. Enhancing Technol.6
2017 Understanding the Mirai Botnet
Manos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michael G. Kallitsis, Deepak Kumar 0006, Charles Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas
USENIX Security Symposium10
2016 AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis, and Forensics of Multi-Gigabit Streams
abstract
The Internet, as a global system of interconnected networks, carries an extensive array of information resources and services. Key requirements include good quality-of-service and protection of the infrastructure from nefarious activity [e.g., distributed denial of service (DDoS) attacks]. Network monitoring is essential to network engineering, capacity planning, and prevention/mitigation of threats. We develop an open-source architecture, All-packet MONitor (AMON), for online monitoring and analysis of multi-gigabit network streams. It leverages the high-performance packet monitor PF_RING and is readily deployable on commodity hardware. AMON examines all packets, partitions traffic into sub-streams by using rapid hashing and computes certain real-time data products. The resulting data structures provide views of the intensity and connectivity structure of network traffic at the time-scale of routing. The proposed integrated framework includes modules for the identification of heavy-hitters as well as for visualization and statistical detection at the time-of-onset of high-impact events such as DDoS. This allows operators to quickly visualize and diagnose attacks, and limit offline and time-consuming post-mortem analysis. We demonstrate our system in the context of real-world attack incidents, and validate it against state-of-the-art alternatives. AMON has been deployed and is currently processing multi-gigabit live Internet traffic at Merit Network. It is extensible and allows the addition of further statistical and filtering modules for real-time forensics.
Michael G. Kallitsis, Stilian Stoev, Shrijita Bhattacharya, George Michailidis
IEEE J. Sel. Areas Commun.1
2015 Leveraging Internet Background Radiation for Opportunistic Network Analysis
abstract
For more than a decade, unsolicited traffic sent to unused regions of the address space has provided valuable insight into malicious Internet activities. In this paper, we explore the utility of this traffic, known as Internet Background Radiation (IBR), for a different purpose: as a data source of Internet-wide measurements. We collect and analyze IBR from two large darknets, carefully deconstructing its various components and characterizing them along dimensions applicable to Internet-wide measurements. Intuitively, IBR can provide insight into network properties when traffic from that network contains relevant information and is of sufficient volume. We turn this intuition into a scientific investigation, examining which networks send IBR, identifying components of IBR that enable opportunistic network inferences, and characterizing the frequency and granularity of traffic sources. We also consider the influences of time of collection and position in the address space on our results. We leverage IBR properties in three case studies to show that IBR can supplement existing techniques by improving coverage and/or diversity of analyzable networks while reducing measurement overhead. Our main contribution is a new framework for understanding the circumstances and properties for which unsolicited traffic is an appropriate data source for inference of macroscopic Internet properties, which can help other researchers assess its utility for a given study.
Karyn Benson, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Michael G. Kallitsis
Internet Measurement Conference5
2014 Taming the 800 Pound Gorilla: The Rise and Decline of NTP DDoS Attacks
abstract
Distributed Denial of Service (DDoS) attacks based on Network Time Protocol (NTP) amplification, which became prominent in December 2013, have received significant global attention. We chronicle how this attack rapidly rose from obscurity to become the dominant large DDoS vector. Via the lens of five distinct datasets, we characterize the advent and evolution of these attacks. Through a dataset that measures a large fraction of global Internet traffic, we show a three order of magnitude rise in NTP. Using a large darknet, we observe a similar rise in global scanning activity, both malicious and research. We then dissect an active probing dataset, which reveals that the pool of amplifiers totaled 2.2M unique IPs and includes a small number of "mega amplifiers," servers that replied to a single tiny probe packet with gigabytes of data. This dataset also allows us, for the first time, to analyze global DDoS attack victims (including ports attacked) and incidents, where we show 437K unique IPs targeted with at least 3 trillion packets, totaling more than a petabyte. Finally, ISP datasets shed light on the local impact of these attacks. In aggregate, we show the magnitude of this major Internet threat, the community's response, and the effect of that response.
Jakub Czyz, Michael G. Kallitsis, Manaf Gharaibeh, Christos Papadopoulos, Michael D. Bailey, Manish Karir
Internet Measurement Conference2
2013 Understanding IPv6 internet background radiation
abstract
We report the results of a study to collect and analyze IPv6 Internet background radiation. This study, the largest of its kind, collects unclaimed traffic on the IPv6 Internet by announcing five large covering prefixes; these cover the majority of allocated IPv6 space on today's Internet. Our analysis characterizes the nature of this traffic across regions, over time, and by the allocation and routing status of the intended destinations, which we show help to identify the causes of this traffic. We compare results to unclaimed traffic in IPv4, and highlight case studies that explain a large fraction of the data or highlight notable properties. We describe how announced covering prefixes differ from traditional network telescopes, and show how this technique can help both network operators and the research community identify additional potential issues and misconfigurations in this critical Internet transition period.
Jakub Czyz, Kyle Lady, Sam G. Miller, Michael D. Bailey, Michael G. Kallitsis, Manish Karir
Internet Measurement Conference5
2011 Network Decomposition in Practice: An Application to Optimal Resource Allocation
abstract
In this paper, we propose the use of network decomposition under an optimal resource allocation framework. We develop a methodology where recursive formulas can be utilized for calculating the desired end-to-end performance bounds (i.e., backlog bound violation probability) of flows traversing tandem, acyclic queueing networks. We use those performance metrics in an optimization framework that allocates resources to network services with specific quality-of-service requirements. Finally, we evaluate our framework and compare its performance against a system utilizing deterministic bounds obtained from network calculus.
Michael G. Kallitsis, George Michailidis, Michael Devetsikiotis
GLOBECOM1
2009 Measurement-based optimal resource allocation for network services with pricing differentiation
Michael G. Kallitsis, George Michailidis, Michael Devetsikiotis
Perform. Evaluation1
2008 Distributed and Dynamic Resource Allocation for Delay Sensitive Network Services
abstract
In this paper, we present a distributed algorithm to dynamically allocate the available resources of a service-oriented network to delay sensitive network services. We use a utility-based framework to differentiate services based on both their relative profitability and quality-of-service requirements. Our performance metric is the end-to-end delay that a service class experiences in the network. We use network calculus to obtain a deterministic upper bound of this delay and we incorporate this information into our optimization problem formulation. We leverage a moving average control scheme to capture traffic shifts in real time, which makes our solution to react adaptively to traffic dynamics. Finally, we evaluate our system using real traces of instant messaging service traffic.
Michael G. Kallitsis, Robert D. Callaway, Michael Devetsikiotis, George Michailidis
GLOBECOM1