VLDB 2026 Research / reviewers in the wild / expert
K. C. Claffy
dblp:68/4966 · also Kimberly C. Claffy
· DBLP profile ↗
107ranked-venue papers
5as first author
35since 2021 · last 2026
0000-0003-4824-3493ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 71 · 3 first-author · 26 since 2021Security and privacy · 24 · 8 since 2021Systems, architecture and hardware · 8 · 1 first-authorSoftware engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Modernizing BGP Data Access with BGPFiend
Thomas Krenc, Justin Loye, Dimitrios Giakatos, Hans Kuhn, Owen A. Conway, Ties de Kock, K. C. Claffy |
INFOCOM | 7 |
| 2026 | Through a Smaller Lens: Revisiting Opportunistic Analysis Using Network Telescopes
Bernhard Degen, Nils Kempen, K. C. Claffy, Ricky K. P. Mok, Ralph Holz, Roland van Rijswijk-Deij, Raffaele Sommese, Mattijs Jonker |
PAM | 3 |
| 2026 | Different Policies for Different NodeBs: Comparing Downlink Schedulers in Cellular Base Stations
Zesen Zhang, Jon Larrea, Jarrett Huddleston, Haoran Wan, Ricky K. P. Mok, Bradley Huffaker, K. C. Claffy, Kyle Jamieson, Alexander Marder, Aaron Schulman |
PAM | 7 |
| 2025 | Noisy Neighbours: Keep the Neighbourhood QuietabstractThe Border Gateway Protocol (BGP) is a crucial inter-domain routing protocol that uses update messages to enable Autonomous Systems (ASes) to share network reachability information. Typically, ASes should only trigger update messages to reflect configuration changes and link failures for optimal path selection. However, we have identified recurring patterns of highfrequency repeated updates without any topological changes, which consume unnecessary resources of the route collectors for archiving and storage, and complicate downstream analysis. Although the phenomenon of noisy BGP peers and prefixes is known, current work has not quantified its scope and characteristics. This study fills this gap and analyzes over 80 billion update messages from multiple RouteViews collectors spanning several years. We identify and characterize high-frequency repeated updates driven by a small fraction of sessions and prefixes. For instance, fewer than 2% of the prefixes accounted for over 90% of update messages in some BGP update traces. Ebrima Jaw, Thomas Krenc, K. C. Claffy, Lambert J. M. Nieuwenhuis, Cristian Hesselman |
CNSM | 4 |
| 2025 | R&E Routing Policy: Inference and ImplicationabstractBGP hides information that is crucial for building accurate routing models. In this paper, we combine BGP and active probing to infer relative route preference policies of research and education R&E connected ASes. We inferred that systems in ≈88% of <12K prefixes that 2,578 ASes announced in the R&E ecosystem were insensitive to AS path length when selecting provider routes -- only ≈8-9% appeared to assign the same local preference to available R&E and commodity routes. We validate our method, and discuss broader application of the method to infer relative route preference, a crucial step in being able to accurately model routing policies. Matthew J. Luckie, Steven Wallace, Karl Newell, Jeff Bartig, Sadi Koçak, Niels den Otter, Kaj Koole, James Deaton, K. C. Claffy |
IMC | 9 |
| 2025 | An Integrated Active Measurement Programming Environment
Matthew J. Luckie, Shivani Hariprasad, Raffaele Sommese, Brendon Jones, Ken Keys, Ricky K. P. Mok, K. C. Claffy |
PAM | 7 |
| 2025 | Marionette Measurement: Measurement Support Under the PacketLab Model
Tzu-Bin Yan, Zesen Zhang, Bradley Huffaker, Ricky K. P. Mok, K. C. Claffy, Kirill Levchenko |
PAM | 5 |
| 2025 | Lessons Learned from Operating a Large Network TelescopeabstractNetwork telescopes (aka darknets) collect unsolicited Internet traffic (aka Internet background radiation or IBR), which includes benign and malicious scanning as well as artifacts of spoofed denial-of-service attacks and misconfigured software and hosts. Analysis of this traffic has revealed macroscopic insights into security-related events and global network dynamics such as outages. Operating a large-scale network telescope is challenging but often taken for granted, more so than in more mature scientific disciplines. We offer the first study documenting our experiences operating the UCSD Network Telescope, the largest and longest-operating network telescope supporting scientific research. We provide background on the history of the telescope, and focus on increasing operational challenges as the underlying network evolves. We develop and apply techniques to leverage third-party scanning activity to validate the integrity of the data, and to discover misconfigurations in the instrumentation. These insights are crucial for understanding measurement results, which we illustrate using concrete examples. We discuss how our findings generalize to support the expanding ecosystem of other passive techniques, such as honeypots, to track security phenomena. Alexander Männel 0002, Jonas Mücke, K. C. Claffy, Max Gao, Ricky K. P. Mok, Marcin Nawrocki, Thomas C. Schmidt, Matthias Wählisch |
SIGCOMM | 3 |
| 2024 | Sublet Your Subnet: Inferring IP Leasing in the WildabstractIPv4 addresses have become a commodity with monetary value since the exhaustion of unallocated IPv4 space. This led to the rise of a secondary market for buying, selling, and leasing IPv4 addresses. While prior work has studied the IPv4 transfer behavior, the IPv4 leasing ecosystem remains largely unexplored. In this paper, we analyze the IPv4 leasing ecosystem by designing a methodology to infer leased address space for all RIRs and study its impact on routing and hosting security. We infer that 4.1% of all advertised IPv4 prefixes (0.9% of routed v4 address space) were leased in April 2024. Our method achieves 98% precision when evaluated against our validated dataset. Finally, we show that leased address space is five times more likely to be abused compared to non-leased space. Ben Du, Romain Fontugne, Cecilia Testart, Alex C. Snoeren, K. C. Claffy |
IMC | 5 |
| 2024 | DarkSim: A similarity-based time-series analytic framework for darknet trafficabstractNetwork Telescopes, often referred to as darknets, capture unsolicited traffic directed toward advertised but unused IP spaces, enabling researchers and operators to monitor malicious, Internet-wide network phenomena such as vulnerability scanning, botnet propagation, and DoS backscatter. Detecting these events, however, has become increasingly challenging due to the growing traffic volumes that telescopes receive. To address this, we introduce DarkSim, a novel analytic framework that utilizes Dynamic Time Warping to measure similarities within the high-dimensional time series of network traffic. DarkSim combines traditional raw packet processing with statistical approaches, identifying traffic anomalies while enabling rapid time-to-insight. We evaluate our framework against DarkGLASSO, an existing method based on the Graphical LASSO algorithm, using data from the UCSD Network Telescope. Based on our manually classified detections, DarkSim showcased perfect precision and an overlap of up to 91% of DarkGLASSO's detections in contrast to DarkGLASSO's maximum of 73.3% precision and detection overlap of 37.5% with the former. We further demonstrate DarkSim's capability to detect two real-world events in our case studies: (1) an increase in scanning activities surrounding CVE public disclosures, and (2) shifts in country- and network-level scanning patterns that indicate aggressive scanning. DarkSim provides a detailed and interpretable analysis framework for time-series anomalies, representing a new contribution to network security analytics. Max Gao, Ricky K. P. Mok, Esteban Carisimo, Shubham Kulkarni, K. C. Claffy |
IMC | 6 |
| 2024 | The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS AssessmentsabstractMotivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities. Raphael Hiesgen, Marcin Nawrocki, Marinho P. Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky K. P. Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, K. C. Claffy |
IMC | 17 |
| 2024 | DarkDNS: Revisiting the Value of Rapid Zone UpdateabstractMalicious actors exploit the DNS namespace to launch spam campaigns, phishing attacks, malware, and other harmful activities. Combating these threats requires visibility into domain existence, ownership and nameservice activity that the DNS protocol does not itself provide. To facilitate visibility and security-related study of the expanding gTLD namespace, ICANN introduced the Centralized Zone Data Service (CZDS) that shares daily zone file snapshots of new gTLD zones. However, a remarkably high concentration of malicious activity is associated with domains that do not live long enough make it into these daily snapshots. Using public and private sources of newly observed domains, we discover that even with the best available data there is a considerable visibility gap in detecting short-lived domains. We find that the daily snapshots miss at least 1% of newly registered and short-lived domains, which are frequently registered with likely malicious intent. In reducing this critical visibility gap using public sources of data, we demonstrate how more timely access to TLD zone changes can provide valuable data to better prevent abuse. We hope that this work sparks a discussion in the community on how to effectively and safely revive the concept of sharing Rapid Zone Updates for security research. Finally, we release a public live feed of newly registered domains, with the aim of enabling further research in abuse identification. Raffaele Sommese, Gautam Akiwate, Antonia Affinito, Mattijs Jonker, K. C. Claffy |
IMC | 6 |
| 2024 | The Next Generation of BGP Data Collection PlatformsabstractBGP data collection platforms as currently architected face fundamental challenges that threaten their long-term sustainability. Inspired by recent work, we analyze, prototype, and evaluate a new optimization paradigm for BGP collection. Our system scales data collection with two components: analyzing redundancy between BGP updates and using it to optimize sampling of the incoming streams of BGP data. An appropriate definition of redundancy across updates depends on the analysis objective. Our contributions include: a survey, measurements, and simulations to demonstrate the limitations of current systems; a general framework and algorithms to assess and remove redundancy in BGP observations; and quantitative analysis of the benefit of our approach in terms of accuracy and coverage for several canonical BGP routing analyses such as hijack detection and topology mapping. Finally, we implement and deploy a new BGP peering collection system that automates peering expansion using our redundancy analytics, which provides a path forward for more thorough evaluation of this approach. Thomas Alfroy, Thomas Holterbach, Thomas Krenc, K. C. Claffy, Cristel Pelsser |
SIGCOMM | 4 |
| 2023 | Internet Science Moonshot: Expanding BGP Data HorizonsabstractDramatic growth in Internet connectivity poses a challenge for the resource-constrained data collection efforts that support scientific and operational analysis of interdomain routing. Inspired by tradeoffs made in other disciplines, we explore a fundamental reconceptualization to how we design public BGP data collection architectures: an overshoot-and-discard approach that can accommodate an order of magnitude increase in vantage points by discarding redundant data shortly after its collection. As defining redundant depends on the context, we design algorithms that filter redundant updates without optimizing for one objective, and evaluate our approach in terms of detecting two noteworthy phenomena using BGP data: AS-topology mapping and hijacks. Our approach can generalize to other types of Internet data (e.g., traceroute, traffic). We offer this study as a first step to a potentially new area of Internet measurement research. Thomas Alfroy, Thomas Holterbach, Thomas Krenc, K. C. Claffy, Cristel Pelsser |
HotNets | 4 |
| 2023 | IRRegularities in the Internet Routing RegistryabstractThe Internet Routing Registry (IRR) is a set of distributed databases used by networks to register routing policy information and to validate messages received in the Border Gateway Protocol (BGP). First deployed in the 1990s, the IRR remains the most widely used database for routing security purposes, despite the existence of more recent and more secure alternatives. Yet, the IRR lacks a strict validation standard and the limited coordination across different database providers can lead to inaccuracies. Moreover, it has been reported that attackers have begun to register false records in the IRR to bypass operators' defenses when launching attacks on the Internet routing system, such as BGP hijacks. In this paper, we provide a longitudinal analysis of the IRR over the span of 1.5 years. We develop a workflow to identify irregular IRR records that contain conflicting information compared to different routing data sources. We identify 34,199 irregular route objects out of 1,542,724 route objects from November 2021 to May 2023 in the largest IRR database and find 6,373 to be potentially suspicious. Ben Du, Katherine Izhikevich, Sumanth Rao, Gautam Akiwate, Cecilia Testart, Alex C. Snoeren, K. C. Claffy |
IMC | 7 |
| 2023 | On the Importance of Being an AS: An Approach to Country-Level AS RankingsabstractRecent geopolitical events demonstrate that control of Internet infrastructure in a region is critical to economic activity and defense against armed conflict. This geopolitical importance necessitates novel empirical techniques to assess which countries remain susceptible to degraded or severed Internet connectivity because they rely heavily on networks based in other nation states. Currently, two preeminent BGP-based methods exist to identify influential or market-dominant networks on a global scale-network-level customer cone size and path hegemony-but these metrics fail to capture regional or national differences. Bradley Huffaker, Romain Fontugne, Alexander Marder, K. C. Claffy |
IMC | 4 |
| 2023 | Coarse-grained Inference of BGP Community IntentabstractBGP communities allow operators to influence routing decisions made by other networks (action communities) and to annotate their network's routing information with metadata such as where each route was learned or the relationship the network has with their neighbor (information communities). BGP communities also help researchers understand complex Internet routing behaviors. However, there is no standard convention for how operators assign community values, and significant efforts to scalably infer community meanings have ignored this high-level classification. We discovered that doing so comes at significant cost in accuracy, of both inference and validation. To advance this narrow but powerful direction in Internet infrastructure research, we design and validate an algorithm to execute this first fundamental step: inferring whether a BGP community is action or information. We applied our method to 78,480 community values observed in public BGP data for May 2023. Validating our inferences (24,376 action and 54,104 informational communities) against available ground truth (6,259 communities) we find that our method classified 96.5% correctly. We found that the precision of a state-of-the-art location community inference method increased from 68.2% to 94.8% with our classifications. We publicly share our code, dictionaries, inferences, and datasets to enable the community to benefit from them. Thomas Krenc, Matthew J. Luckie, Alexander Marder, K. C. Claffy |
IMC | 4 |
| 2023 | Poster: Empirically Testing the PacketLab ModelabstractPacketLab is a recently proposed model for accessing remote vantage points. The core design is for the vantage points to export low-level network operations that measurement researchers could rely on to construct more complex measurements. Motivating the model is the assumption that such an approach can overcome persistent challenges such as the operational cost and security concerns of vantage point sharing that researchers face in launching distributed active Internet measurement experiments. However, the limitations imposed by the core design merit a deeper analysis of the applicability of such model to real-world measurements of interest. We undertook this analysis based on a survey of recent Internet measurement studies, followed by an empirical comparison of PacketLab-based versus native implementations of common measurement methods. We showed that for several canonical measurement types common in past studies, PacketLab yielded similar results to native versions of the same measurements. Our results suggest that PacketLab could help reproduce or extend around 16.4% (28 out of 171) of all surveyed studies and accommodate a variety of measurements from latency, throughput, network path, to non-timing data. Tzu-Bin Yan, Zesen Zhang, Bradley Huffaker, Ricky K. P. Mok, K. C. Claffy, Kirill Levchenko |
IMC | 5 |
| 2023 | Poster: Taking the Low Road: How RPKI Invalids PropagateabstractThe Border Gateway Protocol (BGP) includes no mechanism to verify the correctness of routing information exchanged between networks. To defend against unauthorized use of address space, the IETF developed the Resource Public Key Infrastructure (RPKI), a cryptographically attested database system that facilitates validation of BGP messages. Networks can use RPKI to check whether the Autonomous System (AS) at the origin of the AS path in a BGP announcement is authorized to originate the IP prefixes being announced. Ben Du, Cecilia Testart, Romain Fontugne, Alex C. Snoeren, K. C. Claffy |
SIGCOMM | 5 |
| 2023 | Access Denied: Assessing Physical Risks to Internet Access Networks
Alexander Marder, Zesen Zhang, Ricky K. P. Mok, Ramakrishna Padmanabhan, Bradley Huffaker, Matthew J. Luckie, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Aaron Schulman |
USENIX Security Symposium | 8 |
| 2022 | Retroactive identification of targeted DNS infrastructure hijackingabstractIn 2019, the US Department of Homeland Security issued an emergency warning about DNS infrastructure tampering. This alert, in response to a series of attacks against foreign government websites, highlighted how a sophisticated attacker could leverage access to key DNS infrastructure to then hijack traffic and harvest valid login credentials for target organizations. However, even armed with this knowledge, identifying the existence of such incidents has been almost entirely via post hoc forensic reports (i.e., after a breach was found via some other method). Indeed, such attacks are particularly challenging to detect because they can be very short lived, bypass the protections of TLS and DNSSEC, and are imperceptible to users. Identifying them retroactively is even more complicated by the lack of fine-grained Internet-scale forensic data. This paper is a first attempt to make progress at this latter goal. Combining a range of longitudinal data from Internet-wide scans, passive DNS records, and Certificate Transparency logs, we have constructed a methodology for identifying potential victims of sophisticated DNS infrastructure hijacking and have used it to identify a range of victims (primarily government agencies), both those named in prior reporting, and others previously unknown. Gautam Akiwate, Raffaele Sommese, Mattijs Jonker, Zakir Durumeric, K. C. Claffy, Geoffrey M. Voelker, Stefan Savage |
IMC | 5 |
| 2022 | Mind your MANRS: measuring the MANRS ecosystemabstractMutually Agreed Norms on Routing Security (MANRS) is an industry-led initiative to improve Internet routing security by encouraging participating networks to implement a series of mandatory or recommended actions. MANRS members must register their IP prefixes in a trusted routing database and use such information to prevent propagation of invalid routing information. MANRS membership has increased significantly in recent years, but the impact of the MANRS initiative on the overall Internet routing security remains unclear. In this paper, we provide the first independent look into the MANRS ecosystem by using publicly available data to analyze the routing behavior of participant networks. We quantify MANRS participants' level of conformance with the stated requirements, and compare the behavior of MANRS and non-MANRS networks. While not all MANRS members fully comply with all required actions, we find that they are more likely to implement routing security practices described in MANRS actions. We assess the relevance of the MANRS effort in securing the overall routing ecosystem. We found that as of May 2022, over 83% of MANRS networks were conformant to the route filtering requirement by dropping BGP messages with invalid information according to authoritative records, and over 95% were conformant to the routing information facilitation requirement, registering their resources in authoritative databases. Ben Du, Cecilia Testart, Romain Fontugne, Gautam Akiwate, Alex C. Snoeren, K. C. Claffy |
IMC | 6 |
| 2022 | Where .ru?: assessing the impact of conflict on russian domain infrastructureabstractThe hostilities in Ukraine have driven unprecedented forces, both from third-party countries and in Russia, to create economic barriers. In the Internet, these manifest both as internal pressures on Russian sites to (re-)patriate the infrastructure they depend on (e.g., naming and hosting) and external pressures arising from Western providers disassociating from some or all Russian customers. While quite a bit has been written about this both from a policy perspective and anecdotally, our paper places the question on an empirical footing and directly measures longitudinal changes in the makeup of naming, hosting and certificate issuance for domains in the Russian Federation. Mattijs Jonker, Gautam Akiwate, Antonia Affinito, K. C. Claffy, Alessio Botta, Geoffrey M. Voelker, Roland van Rijswijk-Deij, Stefan Savage |
IMC | 4 |
| 2022 | Stop, DROP, and ROA: effectiveness of defenses through the lens of DROPabstractWe analyze the properties of 712 prefixes that appeared in Spamhaus' Don't Route Or Peer (DROP) list over a nearly three-year period from June 2019 to March 2022. We show that attackers are subverting multiple defenses against malicious use of address space, including creating fraudulent Internet Routing Registry records for prefixes shortly before using them. Other attackers disguised their activities by announcing routes with spoofed origin ASes consistent with historic route announcements, and in one case, with the ASN in a Route Origin Authorization. We quantify the substantial and actively-exploited attack surface in unrouted address space, which warrants reconsideration of RPKI eligibility restrictions by RIRs, and reconsideration of AS0 policies by both operators and RIRs. Leo Oliver, Gautam Akiwate, Matthew J. Luckie, Ben Du, K. C. Claffy |
IMC | 5 |
| 2022 | Observable KINDNS: validating DNS hygieneabstractThe Internet's naming system (DNS) is a hierarchically structured database, with hundreds of millions of domains in a radically distributed management architecture. The distributed nature of the DNS is the primary factor that allowed it to scale to its current size, but it also brings security and stability risks. The Internet standards community (IETF) has published several operational best practices to improve DNS resilience, but operators must make their own decisions that tradeoff security, cost, and complexity. Since these decisions can impact the security of billions of Internet users, recently ICANN has proposed an initiative to codify best practices into a set of global norms to improve security: the Knowledge-Sharing and Instantiating Norms for DNS and Naming Security (KINDNS) [4]. A similar effort for routing security - Mutually Agreed Norms for Routing Security - provided inspiration for this effort. The MANRS program encourages operators to voluntarily commit to a set of practices that will improve collective routing security - a challenge when incentives to conform with these practices does not generate a clear return on investment for operators. One challenge for both initiatives is independent verification of conformance with the practices. The KINDNS conversation has just started, and stakeholders are still debating what should be in the set of practices. At this early stage, we analyze possible best practices in terms of their measurability by third parties, including a review of DNS measurement studies and available data sets (Table 1). Raffaele Sommese, Mattijs Jonker, K. C. Claffy |
IMC | 3 |
| 2022 | Investigating the impact of DDoS attacks on DNS infrastructureabstractDenial of Service (DDoS) attacks both abuse and target core Internet infrastructures and services, including the Domain Name System (DNS). To characterize recent DDoS attacks against authoritative DNS infrastructure, we join two existing data sets - DoS activity inferred from a sizable darknet, and contemporaneous DNS measurement data - for a 17-month period (Nov. 20 - Mar. 22). Our measurements reveal evidence that millions of domains (up to 5% of the DNS namespace) experienced a DoS attack during our observation window. Most attacks did not substantially harm DNS performance, but in some cases we saw 100-fold increases in DNS resolution time, or complete unreachability. Our measurements captured a devastating attack against a large provider in the Netherlands (TransIP), and attacks against Russian infrastructure. Our data corroborates the value of known best practices to improve DNS resilience to attacks, including the use of anycast and topological redundancy in nameserver infrastructure. We discuss the strengths and weaknesses of our data sets for DDoS tracking and impact on the DNS, and promising next steps to improve our understanding of the evolving DDoS ecosystem. Raffaele Sommese, K. C. Claffy, Roland van Rijswijk-Deij, Arnab Chattopadhyay, Alberto Dainotti, Anna Sperotto, Mattijs Jonker |
IMC | 2 |
| 2022 | PacketLab: tools alpha release and demoabstractThe PacketLab universal measurement endpoint interface design facilitates vantage point sharing among experimenters and measurement endpoint operators [1]. We have continued working on fleshing out the design details of PacketLab components and adding enhancements to facilitate adoption. These include designing the PacketLab certificate system, adding support for measurement creation via a wrapper tool and a C library module, enhancement of reference endpoint ability for measurement flexibility and experiment scheduling, and devising a proxy program to accommodate experimenters without a public IP address. With the code base stabilizing, we are ready to announce our first open release of the PacketLab software package (available at pktlab.github.io). We invite network measurement researchers to try out our tools and welcome any feedback from the research community. Tzu-Bin Yan, Anthea Chen, Zesen Zhang, Bradley Huffaker, Ricky K. P. Mok, Kirill Levchenko, K. C. Claffy |
IMC | 8 |
| 2022 | Jitterbug: A New Framework for Jitter-Based Congestion Inference
Esteban Carisimo, Ricky K. P. Mok, David D. Clark, K. C. Claffy |
PAM | 4 |
| 2022 | IRR Hygiene in the RPKI Era
Ben Du, Gautam Akiwate, Thomas Krenc, Cecilia Testart, Alexander Marder, Bradley Huffaker, Alex C. Snoeren, K. C. Claffy |
PAM | 8 |
| 2021 | Learning to extract geographic information from internet router hostnamesabstractGeolocating Internet routers is a long-standing and notoriously difficult challenge, and current solutions lack the accuracy and adaptability to yield reliable results. We revisit this problem, designing a solution capable of accurately and comprehensively extracting geographic information that network operators embed into router interface hostnames. We train our system using dictionaries that map geographic codes to known locations, and constrain inferences with delay measurements conducted from a distributed set of vantage points. While most operators use known geographic codes, some devise their own mnemonic codes for locations, which our system also extracts and interprets. Matthew J. Luckie, Bradley Huffaker, Alexander Marder, Zachary S. Bischof, Marianne Fletcher, K. C. Claffy |
CoNEXT | 6 |
| 2021 | Risky BIZness: risks derived from registrar name managementabstractIn this paper, we explore a domain hijacking risk that is an accidental byproduct of undocumented operational practices between domain registrars and registries. We show how over the last nine years over 512K domains have been implicitly exposed to the risk of hijacking, affecting names in most popular TLDs (including .com and .net) as well as legacy TLDs with tight registration control (such as .edu and .gov). Moreover, we show that this weakness has been actively exploited by multiple parties who, over the years, have assumed control over 163K domains without having any ownership interest in those names. In addition to characterizing the nature and size of this problem, we also report on the efficacy of the remediation in response to our outreach with registrars. Gautam Akiwate, Stefan Savage, Geoffrey M. Voelker, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2021 | Measuring the network performance of Google cloud platformabstractPublic cloud platforms are vital in supporting online applications for remote learning and telecommuting during the COVID-19 pandemic. The network performance between cloud regions and access networks directly impacts application performance and users' quality of experience (QoE). However, the location and network connectivity of vantage points often limits the visibility of edge-based measurement platforms (e.g., RIPE Atlas). Ricky K. P. Mok, Hongyu Zou, Rui Yang 0036, Tom Koch, Ethan Katz-Bassett, K. C. Claffy |
Internet Measurement Conference | 6 |
| 2021 | Follow the scent: defeating IPv6 prefix rotation privacyabstractIPv6's large address space allows ample freedom for choosing and assigning addresses. To improve client privacy and resist IP-based tracking, standardized techniques leverage this large address space, including privacy extensions and provider prefix rotation. Ephemeral and dynamic IPv6 addresses confound not only tracking and traffic correlation attempts, but also traditional network measurements, logging, and defense mechanisms. We show that the intended anti-tracking capability of these widely deployed mechanisms is unwittingly subverted by edge routers using legacy IPv6 addressing schemes that embed unique identifiers. Erik C. Rye, Robert Beverly, K. C. Claffy |
Internet Measurement Conference | 3 |
| 2021 | Inferring regional access network topologies: methods and applicationsabstractUsing a toolbox of Internet cartography methods, and new ways of applying them, we have undertaken a comprehensive active measurement-driven study of the topology of U.S. regional access ISPs. We used state-of-the-art approaches in various combinations to accommodate the geographic scope, scale, and architectural richness of U.S. regional access ISPs. In addition to vantage points from research platforms, we used public WiFi hotspots and public transit of mobile devices to acquire the visibility needed to thoroughly map access networks across regions. We observed many different approaches to aggregation and redundancy, across links, nodes, buildings, and at different levels of the hierarchy. One result is substantial disparity in latency from some Edge COs to their backbone COs, with implications for end users of cloud services. Our methods and results can inform future analysis of critical infrastructure, including resilience to disasters, persistence of the digital divide, and challenges for the future of 5G and edge computing. Zesen Zhang, Alexander Marder, Ricky K. P. Mok, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy, Aaron Schulman |
Internet Measurement Conference | 6 |
| 2021 | Inferring Cloud Interconnections: Validation, Geolocation, and Routing Behavior
Alexander Marder, K. C. Claffy, Alex C. Snoeren |
PAM | 2 |
| 2020 | Unresolved Issues: Prevalence, Persistence, and Perils of Lame DelegationsabstractThe modern Internet relies on the Domain Name System (DNS) to convert between human-readable domain names and IP addresses. However, the correct and efficient implementation of this function is jeopardized when the configuration data binding domains, nameservers and glue records is faulty. In particular lame delegations, which occur when a nameserver responsible for a domain is unable to provide authoritative information about it, introduce both performance and security risks. We perform a broad-based measurement study of lame delegations, using both longitudinal zone data and active querying. We show that lame delegations of various kinds are common (affecting roughly 14% of domains we queried), that they can significantly degrade lookup latency (when they do not lead to outright failure), and that they expose hundreds of thousands of domains to adversarial takeover. We also explore circumstances that give rise to this surprising prevalence of lame delegations, including unforeseen interactions between the operational procedures of registrars and registries. Gautam Akiwate, Mattijs Jonker, Raffaele Sommese, Ian D. Foster, Geoffrey M. Voelker, Stefan Savage, K. C. Claffy |
Internet Measurement Conference | 7 |
| 2020 | Learning to Extract and Use ASNs in HostnamesabstractWe present the design, implementation, evaluation, and validation of a system that learns regular expressions (regexes) to extract Autonomous System Numbers (ASNs) from hostnames associated with router interfaces. We train our system with ASNs inferred by Router-ToAsAssignment and bdrmapIT using topological constraints from traceroute paths, as well as ASNs recorded by operators in PeeringDB, to learn regexes for 206 different suffixes. Because these methods for inferring router ownership can infer the wrong ASN, we modify bdrmapIT to integrate this new capability to extract ASNs from hostnames. Evaluating against ground truth, our modification correctly distinguished stale from correct hostnames for 92.5% of hostnames with an ASN different from bdrmapIT's initial inference. This modification allowed bdrmapIT to increase the agreement between extracted and inferred ASNs for these routers in the January 2020 ITDK from 87.4% to 97.1% and reduce the error rate from 1/7.9 to 1/34.5. This work opens a broader horizon of opportunity for evidence-based router ownership inference. Matthew J. Luckie, Alexander Marder, Marianne Fletcher, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 5 |
| 2020 | MAnycast2: Using Anycast to Measure AnycastabstractAnycast addressing - assigning the same IP address to multiple, distributed devices - has become a fundamental approach to improving the resilience and performance of Internet services, but its conventional deployment model makes it impossible to infer from the address itself that it is anycast. Existing methods to detect anycast IPv4 prefixes present accuracy challenges stemming from routing and latency dynamics, and efficiency and scalability challenges related to measurement load. We review these challenges and introduce a new technique we call "MAnycast2" that can help overcome them. Our technique uses a distributed measurement platform of anycast vantage points as sources to probe potential anycast destinations. This approach eliminates any sensitivity to latency dynamics, and greatly improves efficiency and scalability. We discuss alternatives to overcome remaining challenges relating to routing dynamics, suggesting a path toward establishing the capability to complete, in under 3 hours, a full census of which IPv4 prefixes in the ISI hitlist are anycast. Raffaele Sommese, Leandro Marcio Bertholdo, Gautam Akiwate, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
Internet Measurement Conference | 7 |
| 2020 | Unintended Consequences: Effects of Submarine Cable Deployment on Internet Routing
Rodérick Fanou, Bradley Huffaker, Ricky K. P. Mok, K. C. Claffy |
PAM | 4 |
| 2020 | When Parents and Children Disagree: Diving into DNS Delegation Inconsistency
Raffaele Sommese, Giovane Cesar Moreira Moura, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
PAM | 6 |
| 2020 | Spoofed traffic inference at IXPs: Challenges, methods and analysis
Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
Comput. Networks | 4 |
| 2019 | Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetabstractThe Spoofer project has collected data on the deployment and characteristics of IP source address validation on the Internet since 2005. Data from the project comes from participants who install an active probing client that runs in the background. The client automatically runs tests both periodically and when it detects a new network attachment point. We analyze the rich dataset of Spoofer tests in multiple dimensions: across time, networks, autonomous systems, countries, and by Internet protocol version. In our data for the year ending August 2019, at least a quarter of tested ASes did not filter packets with spoofed source addresses leaving their networks. We show that routers performing Network Address Translation do not always filter spoofed packets, as 6.4% of IPv4/24 tested in the year ending August 2019 did not filter. Worse, at least two thirds of tested ASes did not filter packets entering their networks with source addresses claiming to be from within their network that arrived from outside their network. We explore several approaches to encouraging remediation and the challenges of evaluating their impact. While we have been able to remediate 352 IPv4/24, we have found an order of magnitude more IPv4/24 that remains unremediated, despite myriad remediation strategies, with 21% unremediated for more than six months. Our analysis provides the most complete and confident picture of the Internet's susceptibility to date of this long-standing vulnerability. Although there is no simple solution to address the remaining long-tail of unremediated networks, we conclude with a discussion of possible non-technical interventions, and demonstrate how the platform can support evaluation of the impact of such interventions over time. Matthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys, Joshua A. Kroll, K. C. Claffy |
CCS | 6 |
| 2019 | Challenges in inferring spoofed traffic at IXPsabstractAscertaining that a network will forward spoofed traffic usually requires an active probing vantage point in that network, effectively preventing a comprehensive view of this global Internet vulnerability. Recently, researchers have proposed using Internet Exchange Points (IXPs) as observatories to detect spoofed packets, by leveraging Autonomous System (AS) topology knowledge extracted from Border Gateway Protocol (BGP) data to infer which source addresses should legitimately appear across parts of the IXP switch fabric. We demonstrate that the existing literature does not capture several fundamental challenges to this approach, including noise in BGP data sources, heuristic AS relationship inference, and idiosyncrasies in IXP interconnectivity fabrics. We propose a novel method to navigate these challenges, leveraging customer cone semantics of AS relationships to guide precise classification of inter-domain traffic as in-cone, out-of-cone (spoofed), unverifiable, bogon, and unassigned. We apply our method to a mid-size IXP with approximately 200 members, and find an upper bound volume of out-of-cone traffic to be more than an order of magnitude less than the previous method inferred on the same data. Our work illustrates the subtleties of scientific assessments of operational Internet infrastructure, and the need for a community focus on reproducing and repeating previous methods. Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
CoNEXT | 4 |
| 2019 | Learning Regexes to Extract Router Names from HostnamesabstractWe present the design, implementation, evaluation, and validation of a system that automatically learns to extract router names (router identifiers) from hostnames stored by network operators in different DNS zones, which we represent by regular expressions (regexes). Our supervised-learning approach evaluates automatically generated candidate regexes against sets of hostnames for IP addresses that other alias resolution techniques previously inferred to identify interfaces on the same router. Conceptually, if three conditions hold: (1) a regex extracts the same value from a set of hostnames associated with IP addresses on the same router; (2) the value is unique to that router; and (3) the regex extracts names for multiple routers in the suffix, then we conclude the regex accurately represents the naming convention for the suffix. Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 3 |
| 2019 | Tracking the deployment of IPv6: Topology, routing and performance
Siyuan Jia, Matthew J. Luckie, Bradley Huffaker, Ahmed Elmokashfi, Emile Aben, K. C. Claffy, Amogh Dhamdhere |
Comput. Networks | 6 |
| 2018 | Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale
Alexander Marder, Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, K. C. Claffy, Jonathan M. Smith |
Internet Measurement Conference | 5 |
| 2018 | Revealing the Load-Balancing Behavior of YouTube Traffic on Interdomain Links
Ricky K. P. Mok, Vaibhav Bajpai, Amogh Dhamdhere, K. C. Claffy |
PAM | 4 |
| 2018 | Inferring persistent interdomain congestionabstractThere is significant interest in the technical and policy communities regarding the extent, scope, and consumer harm of persistent interdomain congestion. We provide empirical grounding for discussions of interdomain congestion by developing a system and method to measure congestion on thousands of interdomain links without direct access to them. We implement a system based on the Time Series Latency Probes (TSLP) technique that identifies links with evidence of recurring congestion suggestive of an under-provisioned link. We deploy our system at 86 vantage points worldwide and show that congestion inferred using our lightweight TSLP method correlates with other metrics of interconnection performance impairment. We use our method to study interdomain links of eight large U.S. broadband access providers from March 2016 to December 2017, and validate our inferences against ground-truth traffic statistics from two of the providers. For the period of time over which we gathered measurements, we did not find evidence of widespread endemic congestion on interdomain links between access ISPs and directly connected transit and content providers, although some such links exhibited recurring congestion patterns. We describe limitations, open challenges, and a path toward the use of this method for large-scale third-party monitoring of the Internet interconnection ecosystem. Amogh Dhamdhere, David D. Clark, Alexander Gamero-Garrido, Matthew J. Luckie, Ricky K. P. Mok, Gautam Akiwate, Kabir Gogia, Vaibhav Bajpai, Alex C. Snoeren, K. C. Claffy |
SIGCOMM | 10 |
| 2017 | Packetlab: a universal measurement endpoint interfaceabstractThe right vantage point is critical to the success of any active measurement. However, most research groups cannot afford to design, deploy, and maintain their own network of measurement endpoints, and thus rely measurement infrastructure shared by others. Unfortunately, the mechanism by which we share access to measurement endpoints today is not frictionless; indeed, issues of compatibility, trust, and a lack of incentives get in the way of efficiently sharing measurement infrastructure. Kirill Levchenko, Amogh Dhamdhere, Bradley Huffaker, K. C. Claffy, Mark Allman, Vern Paxson |
Internet Measurement Conference | 4 |
| 2017 | TCP congestion signaturesabstractWe develop and validate Internet path measurement techniques to distinguish congestion experienced when a flow self-induces congestion in the path from when a flow is affected by an already congested path. One application of this technique is for speed tests, when the user is affected by congestion either in the last mile or in an interconnect link. This difference is important because in the latter case, the user is constrained by their service plan (i.e., what they are paying for), and in the former case, they are constrained by forces outside of their control. We exploit TCP congestion control dynamics to distinguish these cases for Internet paths that are predominantly TCP traffic. In TCP terms, we re-articulate the question: was a TCP flow bottlenecked by an already congested (possibly interconnect) link, or did it induce congestion in an otherwise idle (possibly a last-mile) link? Srikanth Sundaresan, Mark Allman, Amogh Dhamdhere, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2016 | bdrmap: Inference of Borders Between IP Networks
Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, David D. Clark, K. C. Claffy |
Internet Measurement Conference | 5 |
| 2016 | Reasons Dynamic Addresses Change
Ramakrishna Padmanabhan, Amogh Dhamdhere, Emile Aben, K. C. Claffy, Neil Spring |
Internet Measurement Conference | 4 |
| 2016 | Periscope: Unifying Looking Glass Querying
Vasileios Giotsas, Amogh Dhamdhere, K. C. Claffy |
PAM | 3 |
| 2016 | NAT Revelio: Detecting NAT444 in the ISP
Andra Lutu, Marcelo Bagnulo, Amogh Dhamdhere, K. C. Claffy |
PAM | 4 |
| 2016 | Measuring and Troubleshooting the Internet: Algorithms, Tools and ApplicationsabstractThe ubiquity of Internet access and the wide variety of Internet-enabled devices and applications have made the Internet a principal pillar of the Information Society. Decentralized and diverse, the Internet is resilient and universal. However, its distributed nature leads to operational brittleness and difficulty in identifying and tracking the root causes of performance and availability issues. Maurizio Dusi, Alessandro Finamore, K. C. Claffy, Nevil Brownlee, Darryl Veitch |
IEEE J. Sel. Areas Commun. | 3 |
| 2015 | Mapping peering interconnections to a facilityabstractAnnotating Internet interconnections with robust physical coordinates at the level of a building facilitates network management including interdomain troubleshooting, but also has practical value for helping to locate points of attacks, congestion, or instability on the Internet. But, like most other aspects of Internet interconnection, its geophysical locus is generally not public; the facility used for a given link must be inferred to construct a macroscopic map of peering. We develop a methodology, called constrained facility search, to infer the physical interconnection facility where an interconnection occurs among all possible candidates. We rely on publicly available data about the presence of networks at different facilities, and execute traceroute measurements from more than 8,500 available measurement servers scattered around the world to identify the technical approach used to establish an interconnection. A key insight of our method is that inference of the technical approach for an interconnection sufficiently constrains the number of candidate facilities such that it is often possible to identify the specific facility where a given interconnection occurs. Validation via private communication with operators confirms the accuracy of our method, which outperforms heuristics based on naming schemes and IP geolocation. Our study also reveals the multiple roles that routers play at interconnection facilities; in many cases the same router implements both private interconnections and public peerings, in some cases via multiple Internet exchange points. Our study also sheds light on peering engineering strategies used by different types of networks around the globe. Vasileios Giotsas, Georgios Smaragdakis, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy |
CoNEXT | 5 |
| 2015 | Leveraging Internet Background Radiation for Opportunistic Network AnalysisabstractFor more than a decade, unsolicited traffic sent to unused regions of the address space has provided valuable insight into malicious Internet activities. In this paper, we explore the utility of this traffic, known as Internet Background Radiation (IBR), for a different purpose: as a data source of Internet-wide measurements. We collect and analyze IBR from two large darknets, carefully deconstructing its various components and characterizing them along dimensions applicable to Internet-wide measurements. Intuitively, IBR can provide insight into network properties when traffic from that network contains relevant information and is of sufficient volume. We turn this intuition into a scientific investigation, examining which networks send IBR, identifying components of IBR that enable opportunistic network inferences, and characterizing the frequency and granularity of traffic sources. We also consider the influences of time of collection and position in the address space on our results. We leverage IBR properties in three case studies to show that IBR can supplement existing techniques by improving coverage and/or diversity of analyzable networks while reducing measurement overhead. Our main contribution is a new framework for understanding the circumstances and properties for which unsolicited traffic is an appropriate data source for inference of macroscopic Internet properties, which can help other researchers assess its utility for a given study. Karyn Benson, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Michael G. Kallitsis |
Internet Measurement Conference | 3 |
| 2015 | Resilience of Deployed TCP to Blind AttacksabstractAs part of TCP's steady evolution, recent standards have recommended mechanisms to protect against weaknesses in TCP. But adoption, configuration, and deployment of TCP improvements can be slow. In this work, we consider the resilience of deployed TCP implementations to blind in-window attacks, where an off-path adversary disrupts an established connection by sending a packet that the victim believes came from its peer, causing data corruption or connection reset. We tested operating systems (and middleboxes deployed in front) of webservers in the wild in September 2015 and found 22% of connections vulnerable to in-window SYN and reset packets, 30% vulnerable to in-window data packets, and 38.4% vulnerable to at least one of three in-window attacks we tested. We also tested out-of-window packets and found that while few deployed systems were vulnerable to reset and SYN packets, 5.4% of connections accepted in-window data with an invalid acknowledgment number. In addition to evaluating commodity TCP stacks, we found vulnerabilities in 12 of 14 of the routers and switches we characterized -- critical network infrastructure where the potential impact of any TCP vulnerabilities is particularly acute. This surprisingly high level of extant vulnerabilities in the most mature Internet transport protocol in use today is a perfect illustration of the Internet's fragility. Embedded in historical context, it also provides a strong case for more systematic, scientific, and longitudinal measurement and quantitative analysis of fundamental properties of critical Internet infrastructure, as well as for the importance of better mechanisms to get best security practices deployed. Matthew J. Luckie, Robert Beverly, Tiange Wu, Mark Allman, K. C. Claffy |
Internet Measurement Conference | 5 |
| 2015 | Measuring and Characterizing IPv6 Router Availability
Robert Beverly, Matthew J. Luckie, Lorenza Mosley, K. C. Claffy |
PAM | 4 |
| 2015 | IPv6 AS Relationships, Cliques, and Congruence
Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
PAM | 4 |
| 2015 | Analysis of a "/0" Stealth Scan From a BotnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
IEEE/ACM Trans. Netw. | 3 |
| 2014 | Inferring Complex AS RelationshipsabstractThe traditional approach of modeling relationships between ASes abstracts relationship types into three broad categories: transit, peering, and sibling. More complicated configurations exist, and understanding them may advance our knowledge of Internet economics and improve models of routing. We use BGP, traceroute, and geolocation data to extend CAIDA's AS relationship inference algorithm to infer two types of complex relationships: hybrid relationships, where two ASes have different relationships at different interconnection points, and partial transit relationships, which restrict the scope of a customer relationship to the provider's peers and customers. Using this new algorithm, we find 4.5% of the 90,272 provider-customer relationships observed in March 2014 were complex, including 1,071 hybrid relationships and 2,955 partial-transit relationships. Because most peering relationships are invisible, we believe these numbers are lower bounds. We used feedback from operators, and relationships encoded in BGP communities and RPSL, to validate 20% and 6.9% of our partial transit and hybrid inferences, respectively, and found our inferences have 92.9% and 97.0% positive predictive values. Hybrid relationships are not only established betweenlarge transit providers; in 57% of the inferred hybrid transit/peering relationships the customer had a customer cone of fewer than 5 ASes. Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2014 | Challenges in Inferring Internet Interdomain CongestionabstractWe introduce and demonstrate the utility of a method to localize and quantify inter-domain congestion in the Internet. Our Time Sequence Latency Probes (TSLP) method depends on two facts: Internet traffic patterns are typically diurnal, and queues increase packet delay through a router during periods of adjacent link congestion. Repeated round trip delay measurements from a single test point to the two edges of a congested link will show sustained increased latency to the far (but not to the near) side of the link, a delay pattern that differs from the typical diurnal pattern of an uncongested link. We describe our technique and its surprising potential,carefully analyze the biggest challenge with the methodology (interdomain router-level topology inference), describe other less severe challenges, and present initial results that are sufficiently promising to motivate further attention to overcoming the challenges. Matthew J. Luckie, Amogh Dhamdhere, David D. Clark, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 5 |
| 2014 | A Second Look at Detecting Third-Party Addresses in Traceroute Traces with the IP Timestamp Option
Matthew J. Luckie, K. C. Claffy |
PAM | 2 |
| 2014 | Volume-Based Transit Pricing: Is 95 the Right Percentile?
Vamseedhar Reddyvari Raja, Amogh Dhamdhere, Alessandra Scicchitano, Srinivas Shakkottai, K. C. Claffy, Simon Leinen |
PAM | 5 |
| 2014 | Nightlights: Entropy-Based Metrics for Classifying Darkspace Traffic Patterns
Tanja Zseby, Nevil Brownlee, Alistair King, K. C. Claffy |
PAM | 4 |
| 2014 | Analysis of Country-Wide Internet Outages Caused by CensorshipabstractIn the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper, we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data, unsolicited data plane traffic to unassigned address space, active macroscopic traceroute measurements, RIR delegation files, and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin autonomous systems (ASs) using publicly available BGP data repositories in the US and Europe. We then analyzed observable activity related to these sets of prefixes and ASs throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions. Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè |
IEEE/ACM Trans. Netw. | 4 |
| 2013 | Inferring multilateral peeringabstractThe AS topology incompleteness problem is derived from difficulties in the discovery of p2p links, and is amplified by the increasing popularity of Internet eXchange Points (IXPs) to support peering interconnection. We describe, implement, and validate a method for discovering currently invisible IXP peering links by mining BGP communities used by IXP route servers to implement multilateral peering (MLP), including communities that signal the intent to restrict announcements to a subset of participants at a given IXP. Using route server data juxtaposed with a mapping of BGP community values, we can infer 206K p2p links from 13 large European IXPs, four times more p2p links than what is directly observable in public BGP data. The advantages of the proposed technique are threefold. First, it utilizes existing BGP data sources and does not require the deployment of additional vantage points nor the acquisition of private data. Second, it requires only a few active queries, facilitating repeatability of the measurements. Finally, it offers a new source of data regarding the dense establishment of MLP at IXPs. Vasileios Giotsas, Shi Zhou, Matthew J. Luckie, K. C. Claffy |
CoNEXT | 4 |
| 2013 | A first look at IPv4 transfer marketsabstractIn February 2011 the Internet Assigned Numbers Authority (IANA) exhausted its free pool of IPv4 addresses, and the regional registries (RIRs) have started to run out of IPv4 addresses as well. As RIRs have started rationing allocations, IPv4 transfer markets have emerged as a new mechanism to acquire IPv4 addresses. Barring a few high-profile exceptions, IPv4 transfers have largely flown under the radar. In this work, we use the lists of transfers published by three RIRs to characterise the transfer market - the types of players involved, the sizes and characteristics of transferred address blocks, and the visibility of transferred address blocks in the routing table before and after the transfer. Next, we take first steps toward detecting address transfers using BGP data from the Routeviews and RIPE repositories from 2004-2013. We identify reasons why legitimate changes in prefix origin could be mistakenly inferred to be transfers, and implement a series of 10 filters that remove 86% of candidate transfers. Our results indicate that BGP-based detection of transfers is prone to false positives due to significant noise in BGP data, while some transfers remain undetectable as they involve non-BGP speakers. We describe some additional data sources and analysis techniques that may help reveal an opaque market for IPv4 address block transfers. Ioana Livadariu, Ahmed Elmokashfi, Amogh Dhamdhere, K. C. Claffy |
CoNEXT | 4 |
| 2013 | Speedtrap: internet-scale IPv6 alias resolutionabstractImpediments to resolving IPv6 router aliases have precluded understanding the emerging router-level IPv6 Internet topology. In this work, we design, implement, and validate the first Internet-scale alias resolution technique for IPv6. Our technique, speedtrap, leverages the ability to induce fragmented IPv6 responses from router interfaces in a particular temporal pattern that produces distinguishing per-router fingerprints. Our algorithm surmounts three fundamental challenges to Internet-scale IPv6 alias resolution using fragment identifier values: (1) unlike for IPv4, the identifier counters on IPv6 routers have no natural velocity, (2) the values of these counters are similar across routers, and (3) the packet size required to collect inferences is 46 times larger than required in IPv4. We demonstrate the efficacy of the technique by producing router-level Internet IPv6 topologies using measurements from CAIDA's distributed infrastructure. Our preliminary work represents a step toward understanding the Internet's IPv6 router-level topology, an important objective with respect to IPv6 network resilience, security, policy, and longitudinal evolution. Matthew J. Luckie, Robert Beverly, William Brinkmeyer, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2013 | AS relationships, customer cones, and validationabstractBusiness relationships between ASes in the Internet are typically confidential, yet knowledge of them is essential to understand many aspects of Internet structure, performance, dynamics, and evolution. We present a new algorithm to infer these relationships using BGP paths. Unlike previous approaches, our algorithm does not assume the presence (or seek to maximize the number) of valley-free paths, instead relying on three assumptions about the Internet's inter-domain structure: (1) an AS enters into a provider relationship to become globally reachable; and (2) there exists a peering clique of ASes at the top of the hierarchy, and (3) there is no cycle of p2c links. We assemble the largest source of validation data for AS-relationship inferences to date, validating 34.6% of our 126,082 c2p and p2p inferences to be 99.6% and 98.7% accurate, respectively. Using these inferred relationships, we evaluate three algorithms for inferring each AS's customer cone, defined as the set of ASes an AS can reach using customer links. We demonstrate the utility of our algorithms for studying the rise and fall of large transit providers over the last fifteen years, including recent claims about the flattening of the AS-level topology and the decreasing influence of tier-1 ASes on the global Internet. Matthew J. Luckie, Bradley Huffaker, Amogh Dhamdhere, Vasileios Giotsas, K. C. Claffy |
Internet Measurement Conference | 5 |
| 2013 | Gaining insight into AS-level outages through analysis of Internet background radiationabstractInternet Background Radiation (IBR) is unsolicited network traffic mostly generated by malicious software, e.g., worms, scans. In previous work, we extracted a signal from IBR traffic arriving at a large (/8) segment of unassigned IPv4 address space to identify large-scale disruptions of connectivity at an Autonomous System (AS) granularity, and used our technique to study episodes of government censorship and natural disasters [1]. Here we explore other IBR-derived metrics that may provide insights into the causes of macroscopic connectivity disruptions. We propose metrics indicating packet loss (e.g., due to link congestion) along a path from a specific AS to our observation point. We use three case studies to illustrate how our metrics can help identify packet loss characteristics of an outage. These metrics could be used in the diagnostic component of a semiautomated system for detecting and characterizing large-scale outages. Karyn Benson, Alberto Dainotti, K. C. Claffy, Emile Aben |
INFOCOM | 3 |
| 2013 | The Day after Patch Tuesday: Effects Observable in IP Darkspace Traffic
Tanja Zseby, Alistair King, Nevil Brownlee, K. C. Claffy |
PAM | 4 |
| 2013 | Internet-Scale IPv4 Alias Resolution With MIDARabstractA critical step in creating accurate Internet topology maps from traceroute data is mapping IP addresses to routers, a process known as alias resolution. Recent work in alias resolution inferred aliases based on similarities in IP ID time series produced by different IP addresses. We design, implement, and experiment with a new tool that builds on these insights to scale to Internet-scale topologies, i.e., millions of addresses, with greater precision and sensitivity. MIDAR, our Monotonic ID-Based Alias Resolution tool, provides an extremely precise ID comparison test based on monotonicity rather than proximity. MIDAR integrates multiple probing methods, multiple vantage points, and a novel sliding-window probe scheduling algorithm to increase scalability to millions of IP addresses. Experiments show that MIDAR's approach is effective at minimizing the false positive rate sufficiently to achieve a high positive predictive value at Internet scale. We provide sample statistics from running MIDAR on over 2 million addresses. We also validate MIDAR and RadarGun against available ground truth and show that MIDAR's results are significantly better than RadarGun's. Tools such as MIDAR can enable longitudinal study of the Internet's topological evolution. Ken Keys, Young Hyun, Matthew J. Luckie, K. C. Claffy |
IEEE/ACM Trans. Netw. | 4 |
| 2012 | Analysis of a "/0" stealth scan from a botnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial of service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February of last year. This 12-day scan originated from approximately 3 million distinct IP addresses, and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers, its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This work offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
Internet Measurement Conference | 3 |
| 2012 | Measuring the deployment of IPv6: topology, routing and performanceabstractWe use historical BGP data and recent active measurements to analyze trends in the growth, structure, dynamics and performance of the evolving IPv6 Internet, and compare them to the evolution of IPv4. We find that the IPv6 network is maturing, albeit slowly. While most core Internet transit providers have deployed IPv6, edge networks are lagging. Early IPv6 network deployment was stronger in Europe and the Asia-Pacific region, than in North America. Current IPv6 network deployment still shows the same pattern. The IPv6 topology is characterized by a single dominant player -- Hurricane Electric -- which appears in a large fraction of IPv6 AS paths, and is more dominant in IPv6 than the most dominant player in IPv4. Routing dynamics in the IPv6 topology are largely similar to those in IPv4, and churn in both networks grows at the same rate as the underlying topologies. Our measurements suggest that performance over IPv6 paths is comparable to that over IPv4 paths if the AS-level paths are the same, but can be much worse than IPv4 if the AS-level paths differ. Amogh Dhamdhere, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Ahmed Elmokashfi, Emile Aben |
Internet Measurement Conference | 4 |
| 2012 | Measuring the Evolution of Internet Peering Agreements
Amogh Dhamdhere, Himalatha Cherukuru, Constantinos Dovrolis, K. C. Claffy |
Networking (2) | 4 |
| 2011 | Analysis of country-wide internet outages caused by censorshipabstractIn the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data; unsolicited data plane traffic to unassigned address space; active macroscopic traceroute measurements; RIR delegation files; and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin ASes using publicly available BGP data repositories in the U.S. and Europe. We then analyzed observable activity related to these sets of prefixes and ASes throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions. Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè |
Internet Measurement Conference | 4 |
| 2010 | Estimating routing symmetry on single links by passive flow measurementsabstractThe assumption of routing symmetry is often embedded into traffic analysis and classification tools. This paper uses passively captured network data to estimate the amount of traffic actually routed symmetrically on a specific link. We propose a Flow-Based Symmetry Estimator (FSE) -- a set of metrics to assess symmetry in terms of flows, packets and bytes, which disregards inherently asymmetrical traffic such as UDP, ICMP and TCP background radiation. This normalized metric allows fair comparison of symmetry across different links. We evaluate our method on a large heterogeneous dataset, and confirm anecdotal reports that routing symmetry typically does not hold for non-edge Internet links, and decreases as one moves toward core backbone links, due to routing policy complexity. Our proposed metric for traffic asymmetry induced by routing policies will help the community improve traffic characterization techniques and formats, but also support quantitative formalization of routing policy effects on links in the wild. Wolfgang John, Maurizio Dusi, K. C. Claffy |
IWCMC | 3 |
| 2010 | Toward Topology Dualism: Improving the Accuracy of AS Annotations for Routers
Bradley Huffaker, Amogh Dhamdhere, Marina Fomenkov, K. C. Claffy |
PAM | 4 |
| 2009 | Understanding the efficacy of deployed internet source address validation filteringabstractIP source address forgery, or “spoofing, ” is a long-recognized consequence of the Internet’s lack of packet-level authenticity. Despite historical precedent and filtering and tracing efforts, attackers continue to utilize spoofing for anonymity, indirection, and amplification. Using a distributed infrastructure and approximately 12,000 active measurement clients, we collect data on the prevalence and efficacy of current bestpractice source address validation techniques. Of clients able to test their provider’s source-address filtering rules, we find 31 % able to successfully spoof an arbitrary, routable source address, while 77 % of clients otherwise unable to spoof can forge an address within their own /24 subnetwork. We uncover significant differences in filtering depending upon network geographic region, type, and size. Our new tracefilter tool for filter location inference finds 80 % of filters implemented a single IP hop from sources, with over 95 % of blocked packets observably filtered within the source’s autonomous system. Finally, we provide initial longitudinal results on the evolution of spoofing revealing no mitigation improvement over four years of measurement. Our analysis provides an empirical basis for evaluating incentive and coordination issues surrounding existing and future Internet packet authentication strategies. Robert Beverly, Arthur W. Berger, Young Hyun, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2008 | Internet traffic classification demystified: myths, caveats, and the best practicesabstractRecent research on Internet traffic classification algorithms has yield a flurry of proposed approaches for distinguishing types of traffic, but no systematic comparison of the various algorithms. This fragmented approach to traffic classification research leaves the operational community with no basis for consensus on what approach to use when, and how to interpret results. In this work we critically revisit traffic classification by conducting a thorough evaluation of three classification approaches, based on transport layer ports, host behavior, and flow features. A strength of our work is the broad range of data against which we test the three classification approaches: seven traces with payload collected in Japan, Korea, and the US. The diverse geographic locations, link characteristics and application traffic mix in these data allowed us to evaluate the approaches under a wide variety of conditions. We analyze the advantages and limitations of each approach, evaluate methods to overcome the limitations, and extract insights and recommendations for both the study and practical application of traffic classification. We make our software, classifiers, and data available for researchers interested in validating or extending this work. Hyunchul Kim, K. C. Claffy, Marina Fomenkov, Dhiman Barman, Michalis Faloutsos, KiYoung Lee |
CoNEXT | 2 |
| 2007 | Increasing the Coverage of a Cooperative Internet Topology Discovery Algorithm
Benoit Donnet, Bradley Huffaker, Timur Friedman, K. C. Claffy |
Networking | 4 |
| 2007 | Two Days in the Life of the DNS Anycast Root Servers
Bradley Huffaker, Marina Fomenkov, Nevil Brownlee, K. C. Claffy |
PAM | 5 |
| 2005 | Remote Physical Device FingerprintingabstractWe introduce the area of remote physical device fingerprinting, or fingerprinting a physical device, as opposed to an operating system or class of devices, remotely, and without the fingerprinted device's known cooperation. We accomplish this goal by exploiting small, microscopic deviations in device hardware: clock skews. Our techniques do not require any modification to the fingerprinted devices. Our techniques report consistent measurements when the measurer is thousands of miles, multiple hops, and tens of milliseconds away from the fingerprinted device, and when the fingerprinted device is connected to the Internet from different locations and via different access technologies. Further one can apply our passive and semi-passive techniques when the fingerprinted device is behind a NAT or firewall, and also when the device's system time is maintained via NTP or SNTP. One can use our techniques to obtain information about whether two devices an the Internet, possibly shifted in time or IP addresses, are actually the same physical device. Example applications include: computer forensics; tracking, with some probability, a physical device as it connects to the Internet from different public access points; counting the number of devices behind a NAT even when the devices use constant or random IP ID; remotely probing a block of addresses to determine if the addresses correspond to virtual hosts, e.g., as part of a virtual honeynet; and unanonymizing anonymized network traces. Tadayoshi Kohno, Andre Broido, K. C. Claffy |
S&P | 3 |
| 2005 | Remote Physical Device FingerprintinabstractWe introduce the area of remote physical device fingerprinting, or fingerprinting a physical device, as opposed to an operating system or class of devices, remotely, and without the fingerprinted device's known cooperation. We accomplish this goal by exploiting small, microscopic deviations in device hardware: clock skews. Our techniques do not require any modification to the fingerprinted devices. Our techniques report consistent measurements when the measurer is thousands of miles, multiple hops, and tens of milliseconds away from the fingerprinted device and when the fingerprinted device is connected to the Internet from different locations and via different access technologies. Further, one can apply our passive and semipassive techniques when the fingerprinted device is behind a NAT or firewall, and. also when the device's system time is maintained via NTP or SNTP. One can use our techniques to obtain information about whether two devices on the Internet, possibly shifted in time or IP addresses, are actually the same physical device. Example applications include: computer forensics; tracking, with some probability, a physical device as it connects to the Internet from different public access points; counting the number of devices behind a NAT even when the devices use constant or random IP IDs; remotely probing a block of addresses to determine if the addresses correspond to virtual hosts, e.g., as part of a virtual honeynet; and unanonymizing anonymized network traces. Tadayoshi Kohno, Andre Broido, K. C. Claffy |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2005 | Guest Editorial Introduction to the Special Issue on Adaptive Learning Systems in Communication Networks
Alexander G. Parlos, Chuanyi Ji, Thomas Parisini, Marco Baglietto, Amir F. Atiya, K. C. Claffy |
IEEE Trans. Neural Networks | 6 |
| 2004 | Is P2P dying or just hiding? [P2P traffic measurement]abstractRecent reports in the popular media suggest a significant decrease in peer-to-peer (P2P) file-sharing traffic, attributed to the public's response to legal threats. Have we reached the end of the P2P revolution? In pursuit of legitimate data to verify this hypothesis, in this paper, we embark on a more accurate measurement effort of P2P traffic at the link level. In contrast to previous efforts, we introduce two novel elements in our methodology. First, we measure traffic of all known popular P2P protocols. Second, we go beyond the "known port" limitation by reverse engineering the protocols and identifying characteristic strings in the payload. We find that, if measured accurately, P2P traffic has never declined; indeed we have never seen the proportion of P2P traffic decrease over time (any change is an increase) in any of our data sources. Thomas Karagiannis, Andre Broido, Nevil Brownlee, K. C. Claffy, Michalis Faloutsos |
GLOBECOM | 4 |
| 2004 | Transport layer identification of P2P trafficabstractSince the emergence of peer-to-peer (P2P) networking in the late '90s, P2P applications have multiplied, evolved and established themselves as the leading `growth app' of Internet traffic workload. In contrast to first-generation P2P networks which used well-defined port numbers, current P2P applications have the ability to disguise their existence through the use of arbitrary ports. As a result, reliable estimates of P2P traffic require examination of packet payload, a methodological landmine from legal, privacy, technical, logistic, and fiscal perspectives. Indeed, access to user payload is often rendered impossible by one of these factors, inhibiting trustworthy estimation of P2P traffic growth and dynamics. In this paper, we develop a systematic methodology to identify P2P flows at the transport layer, i.e., based on connection patterns of P2P networks, and without relying on packet payload. We believe our approach is the first method for characterizing P2P traffic using only knowledge of network dynamics rather than any user payload. To evaluate our methodology, we also develop a payload technique for P2P traffic identification, by reverse engineering and analyzing the nine most popular P2P protocols, and demonstrate its efficacy with the discovery of P2P protocols in our traces that were previously unknown to us. Finally, our results indicate that P2P traffic continues to grow unabatedly, contrary to reports in the popular media. Thomas Karagiannis, Andre Broido, Michalis Faloutsos, K. C. Claffy |
Internet Measurement Conference | 4 |
| 2003 | Spectroscopy of DNS update trafficabstractWe study attempts to dynamically update DNS records for private (RFC1918) addresses, by analyzing the frequency spectrum of updates observed at an authoritative nameserver for these addresses. Using a discrete autocorrelation algorithm we found that updates series have periods of 60 or 75 minutes, which we identified as default settings of out-of-the-box Microsoft Windows 2000 and XP DNS software. Andre Broido, Evi Nemeth, K. C. Claffy |
SIGMETRICS | 3 |
| 2002 | Code-Red: a case study on the spread and victims of an internet wormabstractOn July 19, 2001, more than 359,000 computers connected to the Internet were infected with the Code-Red (CRv2) worm in less than 14 hours. The cost of this epidemic, including subsequent strains of Code-Red, is estimated to be in excess of $2.6 billion. Despite the global damage caused by this attack, there have been few serious attempts to characterize the spread of the worm, partly due to the challenge of collecting global information about worms. Using a technique that enables global detection of worm spread, we collected and analyzed data over a period of 45 days beginning July 2nd, 2001 to determine the characteristics of the spread of Code-Red throughout the Internet.In this paper, we describe the methodology we use to trace the spread of Code-Red, and then describe the results of our trace analyses. We first detail the spread of the Code-Red and CodeRedII worms in terms of infection and deactivation rates. Even without being optimized for spread of infection, Code-Red infection rates peaked at over 2,000 hosts per minute. We then examine the properties of the infected host population, including geographic location, weekly and diurnal time effects, top-level domains, and ISPs. We demonstrate that the worm was an international event, infection activity exhibited time-of-day effects, and found that, although most attention focused on large corporations, the Code-Red worm primarily preyed upon home and small business users. We also qualified the effects of DHCP on measurements of infected hosts and determined that IP addresses are not an accurate measure of the spread of a worm on timescales longer than 24 hours. Finally, the experience of the Code-Red worm demonstrates that wide-spread vulnerabilities in Internet hosts can be exploited quickly and dramatically, and that techniques other than host patching are required to mitigate Internet worms. David Moore 0001, Colleen Shannon, K. C. Claffy |
Internet Measurement Workshop | 3 |
| 2002 | Internet stream size distributionsabstractWe present and discuss stream size and lifetime distributions for web and non-web TCP traffic on a campus OC12 link at UC San Diego. The distributions are stable over long periods, and show that on this link only 3% of the streams last longer than one minute, and that only about 0.5% of them are bigger than 100 kBytes. Although there are large streams (elephants) on this link, the bulk of its traffic is composed of many small streams (mice). Nevil Brownlee, K. C. Claffy |
SIGMETRICS | 2 |
| 2002 | Beyond folklore: observations on fragmented trafficabstractFragmented IP traffic is a poorly understood component of the overall mix of traffic on the Internet. Many assertions about the nature and extent of fragmented traffic are anecdotal rather than empirical. In this paper we examine the causes and attributes of measured fragment traffic, in particular, the effects of NFS, streaming media, networked video games, tunneled traffic, and the prevalence of packet fragmentation due to improperly configured machines. To understand the prevalence, causes, and effects of fragmented IP traffic, we have collected and analyzed seven multiday traces from four sources. These sources include a university commodity access link, two highly aggregated commercial exchange points, and a local NAP. Although there is no practical method of ascertaining whether any data provide a representative sample of all Internet traffic, we include data sources that cover several different types of WAN with traffic from commercial entities, educational and research institutions, and large government facilities. The dominant causes of fragmentation are streaming media and tunneled traffic. Although rumored to be the main impetus for IP packet fragmentation, NFS is not among the top ten causes. Colleen Shannon, David Moore 0001, K. C. Claffy |
IEEE/ACM Trans. Netw. | 3 |
| 2001 | DNS measurements at a root serverabstractThe Domain Name System (DNS) prescribes domain names to be used in network transactions (email, web requests, etc.) instead of IP addresses. The root of the DNS distributed database is managed by 13 root nameservers. We passively measure the performance of one of them: F.root-servers.net. These measurements show an astounding number of bogus queries: from 60-85% of observed queries were repeated from the same host within the measurement interval. Over 14% of a root server's query load is due to queries that violate the DNS specification. Denial of service attacks using root servers are common and occurred throughout our measurement period (7-24 Jan 2001). Though not targeted at the root servers, DOS attacks often use root servers as reflectors toward a victim network. We contrast our observations with those found in an earlier study of DNS root server performance by Danzig et. al., (1992). Nevil Brownlee, K. C. Claffy, Evi Nemeth |
GLOBECOM | 2 |
| 2001 | DNS Root/g TLD Server Measurements
Nevil Brownlee, K. C. Claffy, Evi Nemeth |
LISA | 2 |
| 2001 | Internet Measurement: Myths About Internet Data
K. C. Claffy |
LISA | 1 |
| 2001 | Macroscopic Internet Topology and Performance Measurements from the DNS Root Name Servers
Marina Fomenkov, K. C. Claffy, Bradley Huffaker, David Moore 0001 |
LISA | 2 |
| 2001 | The CoralReef Software Suite as a Tool for System and Network Administrators
David Moore 0001, Ken Keys, Ryan Koga, Edouard Lagache, K. C. Claffy |
LISA | 5 |
| 1998 | Visualization of the Growth and Topology of the NLANR Caching Hierarchy
Bradley Huffaker, Jaeyeon Jung, Evi Nemeth, Duane Wessels, K. C. Claffy |
Comput. Networks | 5 |
| 1998 | ICP and the Squid web cacheabstractWe describe the structure and functionality of the Internet cache protocol (ICP) and its implementation in the Squid web caching software. ICP is a lightweight message format used for communication among Web caches. Caches exchange ICP queries and replies to gather information to use in selecting the most appropriate location from which to retrieve an object. We present background on the history of ICP, and discuss issues in ICP deployment, efficiency, security, and interaction with other aspects of Web traffic behavior. We catalog successes, failures, and lessons learned from using ICP to deploy a global Web cache hierarchy. Duane Wessels, K. C. Claffy |
IEEE J. Sel. Areas Commun. | 2 |
| 1997 | What's next for Internet data analysis? Status and challenges facing the communityabstractMost large providers currently collect basic statistics on the performance of their own infrastructure, typically including measurements of utilization and availability and possibly rudimentary assessments of delay and throughput. In today's commercial Internet, the only baseline against which organizations can calibrate their networks is past performance data. No data or even standard formats are available against which to compare performance with other networks or against an industry norm, nor are there reliable data with which customers can assess the performance of providers. Data characterization and traffic flow analysis also are virtually nonexistent at this time, yet they remain essential for understanding the internal dynamics of the Internet infrastructure. Path performance measurement tools enable users and operators to better evaluate and compare providers and to monitor service quality. Traffic flow characterization tools focus on the behavior and inner workings of these wide-area networks. This paper has two goals. We first provide background on the current Internet architecture and describe how measurements are a key element in the development of a robust and financially successful commercial Internet. We then discuss the current state of Internet metrics analysis and activities within various forums, particularly the Cooperative Association for Internet Data Analysis and the National Laboratory for Applied Network Research, to encourage the development and deployment of Internet performance monitoring and workload characterization tools. K. C. Claffy, Tracie Monk |
Proc. IEEE | 1 |
| 1996 | OC3MON: Flexible, Affordable, High Performance Staistics Collection
Joel Apisdorf, K. C. Claffy, Kevin Thompson 0002, Rick Wilder |
LISA | 2 |
| 1995 | Web Traffic Characterization: An Assesment of the Impact of Caching Documents from NCSA's Web Server
Hans-Werner Braun, K. C. Claffy |
Comput. Networks ISDN Syst. | 2 |
| 1995 | A Parameterizable Methodology for Internet Traffic Flow ProfilingabstractWe present a parameterizable methodology for profiling Internet traffic flows at a variety of granularities. Our methodology differs from many previous studies that have concentrated on end-point definitions of flows in terms of state derived from observing the explicit opening and closing of TCP connections. Instead, our model defines flows based on traffic satisfying various temporal and spatial locality conditions, as observed at internal points of the network. This approach to flow characterization helps address some central problems in networking based on the Internet model. Among them are route caching, resource reservation at multiple service levels, usage based accounting, and the integration of IP traffic over an ATM fabric. We first define the parameter space and then concentrate on metrics characterizing both individual flows as well as the aggregate flow profile. We consider various granularities of the definition of a flow, such as by destination network, host-pair, or host and port quadruple. We include some measurements based on case studies we undertook, which yield significant insights into some aspects of Internet traffic, including demonstrating (i) the brevity of a significant fraction of IP flows at a variety of traffic aggregation granularities, (ii) that the number of host-pair IP flows is not significantly larger than the number of destination network flows, and (iii) that schemes for caching traffic information could significantly benefit from using application information.> K. C. Claffy, Hans-Werner Braun, George C. Polyzos |
IEEE J. Sel. Areas Commun. | 1 |
| 1993 | Traffic Characteristics of the T1 NSFNET BackboneabstractThe results of a measurement study of the T1 NSFNET backbone are presented. The measurement environment and the approach to data collection are discussed. Measurements results are then presented for: long-term growth in traffic volume, including attribution to domains and protocols; trends in average packet size on the network, over both long- and medium-term intervals; most popular sources, destinations, and site pairs; traffic locality; international distribution of traffic; mean utilization statistics of the overall backbone as well as of specific links of interest: and delay statistics.> K. C. Claffy, George C. Polyzos, Hans-Werner Braun |
INFOCOM | 1 |
| 1993 | Application of Sampling Methodologies to Network Traffic CharacterizationabstractThe relative performance of different data collection methods in the assessment of various traffic parameters is significant when the amount of data generated by a complete trace of a traffic interval is computationally overwhelming, and even capturing summary statistics for all traffic is impractical. This paper presents a study of the performance of various methods of sampling in answering questions related to wide area network traffic characterization. Using a packet trace from a network environment that aggregates traffic from a large number of sources, we simulate various sampling approaches, including time-driven and event-driven methods, with both random and deterministic selection patterns, at a variety of granularities. Using several metrics which indicate the similarity between two distributions, we then compare the sampled traces to the parent population. Our results revealed that the time-triggered techniques did not perform as well as the packet-triggered ones. Furthermore, the performance differences within each class (packet-based or time-based techniques) are small. K. C. Claffy, George C. Polyzos, Hans-Werner Braun |
SIGCOMM | 1 |
| 1992 | Design, Implementation, and Evaluation of Virtual Internet ProtocolabstractThe design and implementation of the Virtual Internet Protocol (VIP) are described. The VIP was implemented by modifying an operating system kernel based on 4.3BSD. The overhead of VIP is compared to that of IP. Measured results indicate that VIP can achieve host migration transparency in the Internet with negligible overhead.> Fumio Teraoka, K. C. Claffy, Mario Tokoro |
ICDCS | 2 |