Aaron Schulman

dblp:77/3626 · DBLP profile ↗
← Back
35ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0002-9280-8925ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 21 · 2 first-author · 6 since 2021Security and privacy · 13 · 2 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Different Policies for Different NodeBs: Comparing Downlink Schedulers in Cellular Base Stations
Zesen Zhang, Jon Larrea, Jarrett Huddleston, Haoran Wan, Ricky K. P. Mok, Bradley Huffaker, K. C. Claffy, Kyle Jamieson, Alexander Marder, Aaron Schulman
PAM10
2026 Lost in Translation: Text Message Spoofing via Email
Sumanth Rao, Ye Shu, Stefan Savage, Aaron Schulman, Geoffrey M. Voelker, Enze Liu 0001
SP4
2025 Don't Look Up: There Are Sensitive Internal Links in the Clear on GEO Satellites
abstract
Geosynchronous (GEO) satellite links provide IP backhaul to remote critical infrastructure for utilities, telecom, government, military, and commercial users. To date, academic studies of GEO infrastructure have focused on a handful of satellites and specific use cases. We perform the first broad scan of IP traffic on 39 GEO satellites across 25 distinct longitudes with 411 transponders using consumer-grade equipment. We overcome the poor signal quality plaguing prior work and build the first general parser that can handle the diverse protocols in use by heterogeneous endpoints. We found 50% of GEO links contained cleartext IP traffic; while link-layer encryption has been standard practice in satellite TV for decades, IP links typically lacked encryption at both the link and network layers. This gives us a unique view into the internal network security practices of these organizations. We observed unencrypted cellular backhaul traffic from several providers including cleartext call and text contents, job scheduling and industrial control systems for utility infrastructure, military asset tracking, inventory management for global retail stores, and in-flight wifi.
Wenyi Morty Zhang, Annie Dai, Keegan Ryan, Dave Levin, Nadia Heninger, Aaron Schulman
CCS6
2024 Practical Obfuscation of BLE Physical-Layer Fingerprints on Mobile Devices
abstract
Mobile devices continuously beacon Bluetooth Low Energy (BLE) advertisement packets. This has created the threat of attackers identifying and tracking a device by sniffing its BLE signals. To mitigate this threat, MAC address randomization has been deployed at the link-layer in most BLE transmitters. However, attackers can bypass MAC address randomization using lower-level physical-layer fingerprints resulting from manufacturing imperfections of radios. In this work, we demonstrate a practical and effective method of obfuscating physical-layer hardware imperfection fingerprints. Through theoretical analysis, simulations, and field evaluations, we design and evaluate our approach to hardware imperfection obfuscation. By analyzing data from thousands of BLE devices, we demonstrate obfuscation significantly reduces the accuracy of identifying a target device. This makes an attack impractical, even if a target is continuously observed for 24 hours. Furthermore, we demonstrate the practicality of this defense by implementing it by making firmware changes to commodity BLE chipsets.
Hadi Givehchian, Nishant Bhaskar, Alexander Redding, Aaron Schulman, Dinesh Bharadia
SP5
2023 Rosebud: Making FPGA-Accelerated Middlebox Development More Pleasant
abstract
We introduce an approach to designing FPGA-accelerated middleboxes that simplifies development, debugging, and performance tuning by decoupling the tasks of hardware-accelerator implementation and software-application programming. Rosebud is a framework that links hardware accelerators to a high-performance packet processing pipeline through a standardized hardware/software interface. This separation of concerns allows hardware developers to focus on optimizing custom accelerators while freeing software programmers to reuse, configure, and debug accelerators in a fashion akin to software libraries. We show the benefits of the Rosebud framework by building a firewall based on a large blacklist and porting the Pigasus IDS pattern-matching accelerator in less than a month. Our experiments demonstrate that Rosebud delivers high performance, serving ∼200 ‍Gbps of traffic while adding only 0.7–7 microseconds of latency.
Moein Khazraee, Alex Forencich, George Papen, Alex C. Snoeren, Aaron Schulman
ASPLOS (3)5
2023 Crescendo: Towards Wideband, Real-time, High-Fidelity Spectrum Sensing Systems
abstract
Spectrum sensing systems provide real-time feedback essential for spectrum sharing. However, the growth of spectrum sharing is limited by the capabilities of these spectrum sensors. Sharing a new frequency band is only possible if sensors can detect activity in that band with sufficient time granularity and signal fidelity to meet spectrum sharing policy requirements. In this work, we introduce Crescendo, a system design that shows we can achieve wideband, real-time, high-fidelity spectrum sensing using sweeping spectrum sensors. We first provide an analysis that demonstrates there are operating points of sweeping sensors that can sense multiple popular protocols. Then we demonstrate these sensors can be built in practice with an adaptive gain super-heterodyne RF frontend with high-fidelity LO generation, and evaluate a prototype built with COTS components. In our benchmarks, Crescendo outperforms prior wideband spectrum sensors, achieving a 30 dB increase in dynamic range and 10 dB increase in SNR.
Raghav Subbaraman, Kevin Mills, Aaron Schulman, Dinesh Bharadia
MobiCom3
2023 Access Denied: Assessing Physical Risks to Internet Access Networks
Alexander Marder, Zesen Zhang, Ricky K. P. Mok, Ramakrishna Padmanabhan, Bradley Huffaker, Matthew J. Luckie, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Aaron Schulman
USENIX Security Symposium10
2022 ZLeaks: Passive Inference Attacks on Zigbee Based Smart Homes
Narmeen Shafqat, Daniel J. Dubois, David R. Choffnes, Aaron Schulman, Dinesh Bharadia, Aanjhan Ranganathan
ACNS4
2022 Measuring UID smuggling in the wild
abstract
This work presents a systematic study of UID smuggling, an emerging tracking technique that is designed to evade browsers' privacy protections. Browsers are increasingly attempting to prevent cross-site tracking by partitioning the storage where trackers store user identifiers (UIDs). UID smuggling allows trackers to synchronize UIDs across sites by inserting UIDs into users' navigation requests. Trackers can thus regain the ability to aggregate users' activities and behaviors across sites, in defiance of browser protections.
Audrey Randall, Peter Snyder, Alisha Ukani, Alex C. Snoeren, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman
IMC7
2022 Observing wideband RF spectrum with low-cost, resource limited SDRs
abstract
Software Defined Radios (SDRs) combine a universal radio frontend with flexible processing. The radio frontend can be tuned to capture various wireless signals, while software processing allows quick and scalable deployment for diverse applications. SDRs seem like a good fit for the ever-evolving needs of today's spectrum usage: SDRs can be deployed today, then managed and upgraded with software to support the needs of tomorrow. However, the prevailing architecture of SDRs prevent real-time observation of wideband RF signals due to backhaul and processing resource constraints.
Raghav Subbaraman, Nishant Bhaskar, Sam Crow, Moein Khazraee, Aaron Schulman, Dinesh Bharadia
MobiSys5
2022 Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices
abstract
Mobile devices increasingly function as wireless tracking beacons. Using the Bluetooth Low Energy (BLE) protocol, mobile devices such as smartphones and smartwatches continuously transmit beacons to inform passive listeners about device locations for applications such as digital contact tracing for COVID-19, and even finding lost devices. These applications use cryptographic anonymity that limit an adversary’s ability to use these beacons to stalk a user. However, attackers can bypass these defenses by fingerprinting the unique physical-layer imperfections in the transmissions of specific devices.We empirically demonstrate that there are several key challenges that can limit an attacker’s ability to find a stable physical layer identifier to uniquely identify mobile devices using BLE, including variations in the hardware design of BLE chipsets, transmission power levels, differences in thermal conditions, and limitations of inexpensive radios that can be widely deployed to capture raw physical-layer signals. We evaluated how much each of these factors limits accurate fingerprinting in a large-scale field study of hundreds of uncontrolled BLE devices, revealing that physical-layer identification is a viable, although sometimes unreliable, way for an attacker to track mobile devices.
Hadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto, Christian Dameff, Dinesh Bharadia, Aaron Schulman
SP7
2021 Federated infrastructure: usage, patterns, and insights from "the people's network"
abstract
In this paper, we provide the first broad measurement study of the operation, adoption, performance, and efficacy of Helium. The Helium network aims to provide low-power, wide-area network wireless coverage for Internet of Things-class devices. In contrast to traditional infrastructure, "hotspots" (base stations) are owned and operated by individuals who are paid by the network for providing coverage and are paid directly by users for ferrying data.
Dhananjay Jagtap, Alex Yen, Huanlei Wu, Aaron Schulman, Pat Pannuto
Internet Measurement Conference4
2021 Home is where the hijacking is: understanding DNS interception by residential routers
abstract
DNS interception --- when a user's DNS queries to a target resolver are intercepted en route and forwarded to a different resolver --- is a phenomenon of concern to both researchers and Internet users because of its implications for security and privacy. While the prevalence of DNS interception has received some attention, less is known about where in the network interception takes place. We introduce methods to identify where DNS interception occurs and who the interceptors may be. We identify when interception is performed before the query exits the ISP, and even when it is performed by the Customer Premises Equipment (CPE) in the user's own home. We believe that these techniques are vital in the light of the ongoing debate concerning the value of privacy-enhancing DNS transport.
Audrey Randall, Enze Liu 0001, Ramakrishna Padmanabhan, Gautam Akiwate, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman
Internet Measurement Conference7
2021 Inferring regional access network topologies: methods and applications
abstract
Using a toolbox of Internet cartography methods, and new ways of applying them, we have undertaken a comprehensive active measurement-driven study of the topology of U.S. regional access ISPs. We used state-of-the-art approaches in various combinations to accommodate the geographic scope, scale, and architectural richness of U.S. regional access ISPs. In addition to vantage points from research platforms, we used public WiFi hotspots and public transit of mobile devices to acquire the visibility needed to thoroughly map access networks across regions. We observed many different approaches to aggregation and redundancy, across links, nodes, buildings, and at different levels of the hierarchy. One result is substantial disparity in latency from some Edge COs to their backbone COs, with implications for end users of cloud services. Our methods and results can inform future analysis of critical infrastructure, including resilience to disasters, persistence of the digital divide, and challenges for the future of 5G and edge computing.
Zesen Zhang, Alexander Marder, Ricky K. P. Mok, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy, Aaron Schulman
Internet Measurement Conference7
2020 Trufflehunter: Cache Snooping Rare Domains at Large Public DNS Resolvers
abstract
This paper presents and evaluates Trufflehunter, a DNS cache snooping tool for estimating the prevalence of rare and sensitive Internet applications. Unlike previous efforts that have focused on small, misconfigured open DNS resolvers, Trufflehunter models the complex behavior of large multi-layer distributed caching infrastructures (e.g., such as Google Public DNS). In particular, using controlled experiments, we have inferred the caching strategies of the four most popular public DNS resolvers (Google Public DNS, Cloudflare Quad1, OpenDNS and Quad9). The large footprint of such resolvers presents an opportunity to observe rare domain usage, while preserving the privacy of the users accessing them. Using a controlled testbed, we evaluate how accurately Trufflehunter can estimate domain name usage across the U.S. Applying this technique in the wild, we provide a lower-bound estimate of the popularity of several rare and sensitive applications (most notably smartphone stalkerware) which are otherwise challenging to survey.
Audrey Randall, Enze Liu 0001, Gautam Akiwate, Ramakrishna Padmanabhan, Geoffrey M. Voelker, Stefan Savage, Aaron Schulman
Internet Measurement Conference7
2019 Measuring Security Practices and How They Impact Security
abstract
Security is a discipline that places significant expectations on lay users. Thus, there are a wide array of technologies and behaviors that we exhort end users to adopt and thereby reduce their security risk. However, the adoption of these "best practices" --- ranging from the use of antivirus products to actively keeping software updated --- is not well understood, nor is their practical impact on security risk well-established. This paper explores both of these issues via a large-scale empirical measurement study covering approximately 15,000 computers over six months. We use passive monitoring to infer and characterize the prevalence of various security practices in situ as well as a range of other potentially security-relevant behaviors. We then explore the extent to which differences in key security behaviors impact real-world outcomes (i.e., that a device shows clear evidence of having been compromised).
Louis F. DeKoven, Audrey Randall, Ariana Mirian, Gautam Akiwate, Ansel Blume, Lawrence K. Saul, Aaron Schulman, Geoffrey M. Voelker, Stefan Savage
Internet Measurement Conference7
2019 Detecting if LTE is the Bottleneck with BurstTracker
abstract
We present BurstTracker, the first tool that developers can use to detect if the LTE downlink is the bottleneck for their applications. BurstTracker is driven by our discovery that the proprietary LTE downlink schedulers running on LTE base stations allocate resources to users in a way that reveals if a user's downlink queue runs empty during a download. We demonstrate that BurstTracker works across Tier-1 cellular providers and across a variety of network conditions. We also present a case study that shows how application developers can use this tool in practice. Surprisingly, with BurstTracker, we find that the LTE downlink may not be the bottleneck for video streaming on several Tier-1 providers, even during peak hours at busy locations. Rather, transparent TCP middleboxes deployed by these providers lead to downlink underutilization, because they force Slow-Start Restart. With a simple workaround, we improve video streaming bitrate on busy LTE links by 35%.
Arjun Balasingam, Manu Bansal, Rakesh Misra, Kanthi Nagaraj, Rahul Tandra, Sachin Katti, Aaron Schulman
MobiCom7
2019 SparSDR: Sparsity-proportional Backhaul and Compute for SDRs
abstract
We present SparSDR, a resource-efficient architecture for softwaredefined radios whose backhaul bandwidth and compute power requirements scale in inverse proportion to the sparsity (in time and frequency) of the signals received. SparSDR requires dramatically fewer resources than existing approaches to process many popular protocols while retaining both flexibility and fidelity. We demonstrate that our approach has negligible impact on signal quality, receiver sensitivity, and processing latency. The SparSDR architecture makes it possible to capture signals across bandwidths far wider than the capacity of a radio's backhaul through the addition of lightweight frontend processing and corresponding backend reconstruction to restore the signals to their original sample rate. We employ SparSDR to develop two wideband applications running on a USRP N210 and a Raspberry Pi 3+: an IoT sniffer that scans 100 MHz of bandwidth and decodes received BLE packets, and a wideband Cloud SDR receiver that requires only residential-class Internet uplink capacity. We show that our SparSDR implementation fits in the constrained resources of popular low-cost SDR platforms, such as the AD Pluto.
Moein Khazraee, Yeswanth Guddeti, Sam Crow, Alex C. Snoeren, Kirill Levchenko, Dinesh Bharadia, Aaron Schulman
MobiSys7
2019 SweepSense: Sensing 5 GHz in 5 Milliseconds with Low-cost Radios
Yeswanth Guddeti, Raghav Subbaraman, Moein Khazraee, Aaron Schulman, Dinesh Bharadia
NSDI4
2019 How to Find Correlated Internet Failures
Ramakrishna Padmanabhan, Aaron Schulman, Alberto Dainotti, Dave Levin, Neil Spring
PAM2
2019 Residential links under the weather
abstract
Weather is a leading threat to the stability of our vital infrastructure. Last-mile Internet is no exception. Yet, unlike other vital infrastructure, weather's effect on last-mile Internet outages is not well understood. This work is the first attempt to quantify the effect of weather on residential outages.
Ramakrishna Padmanabhan, Aaron Schulman, Dave Levin, Neil Spring
SIGCOMM2
2019 Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump Skimmers
Nishant Bhaskar, Maxwell Bland, Kirill Levchenko, Aaron Schulman
USENIX Security Symposium4
2017 Poster: Broadcast LTE Data Reveals Application Type
abstract
The rapid growth in mobile connectivity is enabling phones to support a wide range of societally-important applications. In this work, we show that broad classes of popular mobile applications have distinct radio resource allocation signatures. Using this insight, we design a mobile application classifier, and demonstrate that (1) an application can infer its own type solely from its resource allocation patterns, and (2) anyone can accurately infer the type of application being served by each session on a particular cell tower. We present our findings by showing the breakdown of applications being served by an LTE base station belonging to a Tier 1 US provider in downtown Palo Alto. Our work encourages an open discussion about LTE standards, and whether they might need to be enhanced to mask features that can be exploited to infer application type from signals broadcast over the air.
Arjun Balasingam, Manu Bansal, Rakesh Misra, Rahul Tandra, Aaron Schulman, Sachin Katti
MobiCom5
2015 An End-to-End Measurement of Certificate Revocation in the Web's PKI
abstract
Critical to the security of any public key infrastructure (PKI) is the ability to revoke previously issued certificates. While the overall SSL ecosystem is well-studied, the frequency with which certificates are revoked and the circumstances under which clients (e.g., browsers) check whether certificates are revoked are still not well-understood.
Yabing Liu, Will Tome, Liang Zhang 0022, David R. Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Aaron Schulman, Christo Wilson
Internet Measurement Conference8
2015 Timeouts: Beware Surprisingly High Delay
abstract
Active probing techniques, such as ping, have been used to detect outages. When a previously responsive end host fails to respond to a probe, studies sometimes attempt to confirm the outage by retrying the ping or attempt to identify the location of the outage by using other tools such as traceroute. The latent problem, however, is, how long should one wait for a response to the ping? Too short a timeout risks confusing congestion or other delay with an outage. Too long a timeout may slow the process and prevent observing and diagnosing short-duration events, depending on the experiment's design.
Ramakrishna Padmanabhan, Patrick Owen, Aaron Schulman, Neil Spring
Internet Measurement Conference3
2015 Atomix: A Framework for Deploying Signal Processing Applications on Wireless Infrastructure
Manu Bansal, Aaron Schulman, Sachin Katti
NSDI2
2015 PowerSpy: Location Tracking Using Mobile Device Power Analysis
Yan Michalevsky, Aaron Schulman, Gunaa Arumugam Veerapandian, Dan Boneh, Gabi Nakibly
USENIX Security Symposium2
2014 RevCast: Fast, Private Certificate Revocation over FM Radio
abstract
The ability to revoke certificates is a fundamental feature of a public key infrastructure. However, certificate revocation systems are generally regarded as ineffective and potentially insecure: Some browsers bundle revocation updates with more general software updates, and may go hours, days, or indefinitely between updates; moreover, some operating systems make it difficult for users to demand recent revocation data. This paper argues that this sad state of affairs is an inexorable consequence of relying on unicast communication to distribute revocation information. We present RevCast, a broadcast system that disseminates revocation data in a timely and private manner. RevCast is not emulated broadcast over traditional Internet links, but rather a separate metropolitan-area wireless broadcast link; specifically, we have designed RevCast to operate over existing FM radio, although the principles apply to alternative implementations. We present the design, implementation, and initial deployment of RevCast on a 3 kW commercial radio station using the FM RDS protocol. With the use of two types of receivers (an RDS-to-LAN bridge that we have prototyped and an RDS-enabled smartphone), we show that, even at a low bitrate, RevCast is able to deliver complete and timely revocation information, anonymously, even for receivers who do not receive all packets all the time.
Aaron Schulman, Dave Levin, Neil Spring
CCS1
2014 Analysis of SSL certificate reissues and revocations in the wake of heartbleed
abstract
Central to the secure operation of a public key infrastructure (PKI) is the ability to revoke certificates. While much of users' security rests on this process taking place quickly, in practice, revocation typically requires a human to decide to reissue a new certificate and revoke the old one. Thus, having a proper understanding of how often systems administrators reissue and revoke certificates is crucial to understanding the integrity of a PKI. Unfortunately, this is typically difficult to measure: while it is relatively easy to determine when a certificate is revoked, it is difficult to determine whether and when an administrator should have revoked.
Liang Zhang 0022, David R. Choffnes, Dave Levin, Tudor Dumitras, Alan Mislove, Aaron Schulman, Christo Wilson
Internet Measurement Conference6
2011 Pingin' in the rain
abstract
Residential Internet connections are susceptible to weather-caused outages: Lightning and wind cause local power failures, direct lightning strikes destroy equipment, and water in the atmosphere degrades satellite links. Outages caused by severe events such as fires and undersea cable cuts are often reported upon by operators and studied by researchers. In contrast, outages cause by ordinary weather are typically limited in scope, and because of their small scale, there has not been comparable effort to understand how weather affects everyday last-mile Internet connectivity. We design and deploy a measurement tool called ThunderPing that measures the connectivity of residential Inter- net hosts before, during, and after forecast periods of severe weather. ThunderPing uses weather alerts from the US National Weather Service to choose a set of residential host addresses to ping from several vantage points on the Internet. We then process this ping data to determine when hosts lose connectivity, completely or partially, and categorize whether these failures occur during periods of severe weather or when the skies are clear. In our preliminary results, we find that compared to clear weather, failures are four times as likely during thunderstorms and two times as likely during rain. We also find that the duration of weather induced outages is relatively small for a satellite provider we focused on.
Aaron Schulman, Neil Spring
Internet Measurement Conference1
2010 Bartendr: a practical approach to energy-aware cellular data scheduling
abstract
Cellular radios consume more power and suffer reduced data rate when the signal is weak. According to our measurements, the communication energy per bit can be as much as 6x higher when the signal is weak than when it is strong. To realize energy savings, applications must preferentially communicate when the signal is strong, either by deferring non-urgent communication or by advancing anticipated communication to coincide with periods of strong signal. Allowing applications to perform such scheduling requires predicting signal strength, so that opportunities for energy-efficient communication can be anticipated. Furthermore, such prediction must be performed at little energy cost.
Aaron Schulman, Vishnu Navda, Ramachandran Ramjee, Neil Spring, Pralhad Deshpande, Calvin Grunewald, Kamal Jain, Venkat N. Padmanabhan
MobiCom1
2010 Maranello: Practical Partial Packet Recovery for 802.11
Bo Han 0001, Aaron Schulman, Francesco Gringoli, Neil Spring, Bobby Bhattacharjee, Lorenzo Nava, Lusheng Ji, Seungjoon Lee, Robert R. Miller
NSDI2
2010 Stratus: energy-efficient mobile communication using cloud support
abstract
Cellular radio communication is a significant contributor to battery energy drain on smartphones, in some cases inflating the energy cost by a factor of 5 or more compared to the energy cost of the base device. Stratus is a system to reduce this energy consumption by leveraging cloud resources to make data communication on smartphones more efficient. Using a cloud-based proxy, Stratus employs optimizations that adapt an application's incoming and outgoing traffic to better match the energy characteristics of the radio interface. The optimizations include (a) aggregation to bunch up sporadic transmissions, (b) asymmetric dictionary-based compression to reduce the number of bits transmitted over the air, and (c) opportunistic scheduling to avoid communication during periods of poor signal reception. These optimizations can be used individually, or in combination, subject to an application's delay tolerance. For example, using our Stratus prototype, the aggregation and compression optimizations together achieve up to 50% energy savings for web browsing, while the aggregation and scheduling optimizations together achieve up to 35% energy savings for a media streaming application.
Bhavish Agarwal, Pushkar V. Chitnis, Amit Dey, Kamal Jain, Vishnu Navda, Venkat N. Padmanabhan, Ramachandran Ramjee, Aaron Schulman, Neil Spring
SIGCOMM8
2008 On the Fidelity of 802.11 Packet Traces
Aaron Schulman, Dave Levin, Neil Spring
PAM1
2008 Visualizing Real-Time Network Resource Usage
Ryan Blue, Cody Dunne, Adam Fuchs, Kyle King, Aaron Schulman
VizSEC5