VLDB 2026 Research / reviewers in the wild / expert
Marwan Fayed
dblp:92/883 · also Marwan M. Fayed
· DBLP profile ↗
18ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0002-0970-7972ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 16 · 4 first-author · 7 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Global Inference and Assessment of Large Shared IP AddressesabstractThe number of clients and users behind an IP address can differ by orders of magnitude, owing to large shared IPs such as VPNs, proxies, and Carrier-Grade NAT (CGN) gateways. However, limitations on visibility, the absence of Internet-wide data, and the dynamic nature of IP allocations make it difficult to disambiguate multi-user IPs (M-IPs) and their impact on service provision. In this paper we devise an inference technique to detect M-IPs. We train a classifier by annotating data from public sources with features extracted from a global CDN request log. To demonstrate reproducibility, we build a parallel model using public M-Lab data and achieve comparable accuracy with different features. An unanticipated result was the dominance of /24 feature importance over individual IPs. Using the CDN logs, we then evaluate implications of CGNs along multiple dimensions including user impact, relationship with IPv6 networks, and regional distributions. Our results reinforce various intuition, and potentially challenge some assumptions. Vasileios Giotsas, Loqman Salamatian, Antoine Cordelle, Nick Wood, Marwan Fayed |
SIGCOMM | 5 |
| 2025 | Guest Editorial: Special Issue on Advances in Internet Routing and Addressing
Jon Crowcroft, Jörg Ott, Miguel Rio, Noa Zilberman, Marinho P. Barcellos, Marwan Fayed |
IEEE J. Sel. Areas Commun. | 6 |
| 2024 | Topaz: Declarative and Verifiable Authoritative DNS at CDN-ScaleabstractToday, when a CDN nameserver receives a DNS query for a customer's domain, it decides which CDN IP to return based on servicelevel objectives such as managing load or maintaining performance, but also internal needs like split testing. Many of these decisions are made a priori by assignment systems that imperatively generate maps from DNS query to IP address(es). Unfortunately, imperative assignments obfuscate nameserver behavior, especially when different objectives conflict. James Larisch, Tim Alberdingk Thijm, Suleman Ahmad, Peter Wu, Tom Arnfeld, Marwan Fayed |
SIGCOMM | 6 |
| 2023 | Global, Passive Detection of Connection TamperingabstractIn-network devices around the world monitor and tamper with connections for many reasons, including intrusion prevention, combating spam or phishing, and country-level censorship. Connection tampering seeks to block access to specific domain names or keywords, and it affects billions of users worldwide with little-to-no transparency. To detect, diagnose, and measure connection-level blocking, "active" measurement techniques originate queries with domains or keywords believed to be blocked and send them from vantage points within networks of interest. Active measurement efforts have been critical to understanding how traffic tampering occurs, but they inherently are unable to capture critical parts of the picture. For instance, knowing the set of domains in a block-list (i.e., what could get blocked) is not the same as knowing what real users are actively experiencing (i.e., what is actively getting blocked). Ram Sundara Raman, Louis-Henri Merino, Kevin Bock 0001, Marwan Fayed, Dave Levin, Nick Sullivan, Luke Valenta |
SIGCOMM | 4 |
| 2023 | Evaluating practical QUIC website fingerprinting defenses for the massesabstractWebsite fingerprinting (WF) is a well-known threat to users' web privacy. New Internet standards, such as QUIC, include padding to support defenses against WF. Previous work on QUIC WF only analyzes the effectiveness of defenses when users are behind a VPN. Yet, this is not how most users browse the Internet. In this paper, we provide a comprehensive evaluation of QUIC-padding-based defenses against WF when users directly browse the web, i.e., without VPNs, HTTPS proxies, or other tunneling protocols. We confirm previous claims that network-layer padding cannot provide effective protection against powerful adversaries capable of observing all traffic traces. We show that the claims hold even against adversaries with constraints on traffic visibility and processing power. We then show that the current approach to web development, in which the use of third-party resources is the norm, impedes the effective use of padding-based defenses as it requires first and third parties to coordinate in order to thwart traffic analysis. We show that even when coordination is possible, in most cases, protection comes at a high cost. Sandra Deepthy Siby, Ludovic Barman, Christopher A. Wood, Marwan Fayed, Nick Sullivan, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | Respect the ORIGIN!: a best-case evaluation of connection coalescing in the wildabstractConnection coalescing, enabled by HTTP/2, permits a client to use an existing connection to request additional resources at the connected hostname. The potential for requests to be coalesced is hindered by the practice of domain sharding introduced by HTTP/1.1, because subresources are scattered across subdomains in an effort to improve performance with additional connections. When this happens, HTTP/2 clients invoke additional DNS queries and new connections to retrieve content that is available at the same server. ORIGIN Frame is an HTTP/2 extension that can be used by servers to inform clients about other domains that are reachable on the same connection. Despite being proposed by content delivery network (CDN) operators and standardized by the IETF in 2018, the extension has no known server implementation and is supported by only one browser. In this paper, we collect and characterize a large dataset. We use that dataset to model connection coalescing and identify a least-effort set of certificate changes that maximize opportunities for clients to coalesce. We then implemented and deployed ORIGIN Frame support at a large CDN. To evaluate and validate our modeling at scale, 5000 certificates were reissued. Passive measurements were conducted on production traffic over two weeks, during which we also actively measured on the 5000 domains. Sudheesh Singanamalla, Muhammad Talha Paracha, Suleman Ahmad, Jonathan Hoyland, Luke Valenta, Yevgen Safronov, Peter Wu, Andrew Galloni, Kurtis Heimerl, Nick Sullivan, Christopher A. Wood, Marwan Fayed |
IMC | 12 |
| 2021 | The ties that un-bind: decoupling IP from web services and sockets for robust addressing agility at CDN-scaleabstractThe couplings between IP addresses, names of content or services, and socket interfaces, are too tight. This impedes system manageability, growth, and overall provisioning. In turn, large-scale content providers are forced to use staggering numbers of addresses, ultimately leading to address exhaustion (IPv4) and inefficiency (IPv6). Marwan Fayed, Lorenz Bauer, Vasileios Giotsas, Sami Kerola, Marek Majkowski, Pavel Odintsov, Jakub Sitnicki, Taejoong Chung, Dave Levin, Alan Mislove, Christopher A. Wood, Nick Sullivan |
SIGCOMM | 1 |
| 2021 | Oblivious DNS over HTTPS (ODoH): A Practical Privacy Enhancement to DNSabstractAbstract The Internet’s Domain Name System (DNS) responds to client hostname queries with corresponding IP addresses and records. Traditional DNS is unencrypted and leaks user information to on-lookers. Recent efforts to secure DNS using DNS over TLS (DoT) and DNS over HTTPS (DoH) have been gaining traction, ostensibly protecting DNS messages from third parties. However, the small number of available public large-scale DoT and DoH resolvers has reinforced DNS privacy concerns, specifically that DNS operators could use query contents and client IP addresses to link activities with identities. Oblivious DNS over HTTPS (ODoH) safeguards against these problems. In this paper we implement and deploy interoperable instantiations of the protocol, construct a corresponding formal model and analysis, and evaluate the protocols’ performance with wide-scale measurements. Results suggest that ODoH is a practical privacy-enhancing replacement for DNS. Sudheesh Singanamalla, Suphanat Chunhapanya, Jonathan Hoyland, Marek Vavrusa, Tanya Verma, Peter Wu, Marwan Fayed, Kurtis Heimerl, Nick Sullivan, Christopher A. Wood |
Proc. Priv. Enhancing Technol. | 7 |
| 2021 | Quality of Experience in ICN: Keep Your Low- Bitrate Close and High-Bitrate CloserabstractRecent studies into streaming media delivery suggest that performance gains from ubiquitous caching in Information-Centric Networks (ICN) may be negated by Dynamic Adaptive Streaming (DAS), the de facto method for retrieving multimedia content. Bitrate adaptation mechanisms, that drive video streaming, clash with caching mechanisms in ways that affect users' Quality of Experience (QoE). Cache performance also diminishes as consumers dynamically select content encoded at different bitrates. In this article we use this evidence to draw a novel insight: in adaptive streaming over ICN, bitrates should be prioritized alongside popularity and hit rates. We build on this insight to propose RippleCache as a family of cache placement schemes that safeguard high-bitrate content at the edge and push low-bitrate content into the network core. Doing so reduces contention of cache resources, as well as congestion in the network. To validate RippleCache claims we construct two separate implementations. We design RippleClassic as a benchmark solution that optimizes content placement by maximizing a measure for ICNs shown to have high correlation with QoE. In addition, our lighter-weight RippleFinder is then re-designed with distributed execution for application in large-scale systems. RippleCache performance gains are reinforced by evaluations in NS-3 against state-of-the-art baseline approaches, using standard measures of QoE as defined by the DASH Industry Forum. Our results demonstrate that RippleClassic and RippleFinder deliver content that suffers less oscillation and rebuffering, all while achieving the highest levels of video quality; thus indicating overall improvements to QoE. Wenjie Li 0007, Sharief Oteafy, Marwan Fayed, Hossam S. Hassanein |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | Bitrate Adaptation-aware Cache Partitioning for Video Streaming over Information-Centric NetworksabstractRecent studies suggest that performance gains for content delivery over Information-centric Networks (ICNs) may be negated by Dynamic Adaptive Streaming (DAS), the de facto method for retrieval of multimedia content. The bitrate adaptation mechanism that drives video streaming appears to clash with generic ICN caching techniques in ways that affect users' Quality of Experience (QoE). Cache performance diminishes as video consumers dynamically select content encoded at different bitrates. Motivated by preliminary evidence suggesting the merits of bitrate-based cache partitioning, we introduce a scheme to dissect the cache capacity of routers along a forwarding path according to dedicated bitrates. To facilitate this partitioning, we propose a guiding principle RippleCache, which stabilizes bandwidth fluctuation while achieving high cache utilization by safeguarding high-bitrate content on the edge and pushing low-bitrate content into the network core. We further propose a cache placement scheme, RippleFinder, to realize this RippleCache principle and highlight its impact on users' QoE by cache partitioning. The performance gains are reinforced by evaluations in NS-3. Measurements show RippleFinder can significantly reduce bitrate oscillation, while ensuring high video quality, indicating overall improvement to QoE. Wenjie Li 0007, Sharief Oteafy, Marwan Fayed, Hossam S. Hassanein |
LCN | 3 |
| 2016 | TCP goes to hollywoodabstractReal-time multimedia applications use either TCP or UDP at the transport layer, yet neither of these protocols offer all of the features required. Deploying a new protocol that does offer these features is made difficult by ossification: firewalls, and other middleboxes, in the network expect TCP or UDP, and block other types of traffic. We present TCP Hollywood, a protocol that is wire-compatible with TCP, while offering an unordered, partially reliable message-oriented transport service that is well suited to multimedia applications. Analytical results show that TCP Hollywood extends the feasibility of using TCP for real-time multimedia applications, by reducing latency and increasing utility. Preliminary evaluations also show that TCP Hollywood is deployable on the public Internet, with safe failure modes. Measurements across all major UK fixed-line and cellular networks validate the possibility of deployment. Stephen McQuistin, Colin Perkins, Marwan Fayed |
NOSSDAV | 3 |
| 2015 | Network-layer fairness for adaptive video streamsabstractRecent studies observe that competing adaptive video streaming applications generate flows that lead to instability, under-utilization, and unfairness in bottleneck link sharing within the network. Additional measurements suggest there may also be a negative impact on users' perceived quality of service as a consequence. While it may be intuitive to resolve application-generated issues at the application layer, in this paper we explore the merits of a network layer solution. We are motivated by the observation that traditional network-layer metrics associated with throughput, loss, and delay are inadequate to the task. To bridge this gap we present a network-layer QoS framework for adaptive streaming video fairness that reflect the video user's quality of experience (QoE). We begin first by deriving a new measure to describe user-level fairness among competing flows, one that reflects the dynamics between the video encoding and its mapping to a screen with a given size and resolution. We then design and implement our framework in VHS (Video-Home-Shaper) to evaluate performance in the home's last access hop where this problem is known to exist. Experiments using a variety of devices, O/S platforms, and viewing screens demonstrate the merits of using video QoE as a basis for fair bandwidth sharing. Ahmed Mansy, Marwan Fayed, Mostafa H. Ammar |
Networking | 2 |
| 2014 | Virtual network migration on real infrastructure: A PlanetLab case studyabstractNetwork virtualization enables the deployment of novel network architectures and services on existing Internet infrastructure. In addition, virtual networks (VNs) can share the resources in the physical substrate. To enable efficient resource reallocation and network agility, VNs must sometimes migrate, i.e., change their placements on a substrate network. While VN placement, and to a lesser extent migration, has been studied in the past, little attention has been devoted to deploying and evaluating these functions over a real infrastructure. In this paper, we study the VN migration problem based on network virtualization in PlanetLab. We create a tool, PL-VNM, that orchestrates the VN migration on PlanetLab for a given new VN placement. The design and deployment of the tool reveal challenges and constraints. Some are particular to PlanetLab while others apply more generally to any virtualized infrastructure. Most significantly, we find that while in principle one can specify a migration schedule (sequence of migration steps) as an input to our tool, certain PlanetLab features make VN migration scheduling very difficult if not infeasible. Our work leads to recommendations about the features of a general virtualization environment and specific recommendations for PlanetLab that enable VN migration and migration scheduling. We believe that the recommended features make long-term experiments and application deployments on PlanetLab and other realistic virtualized infrastructures possible. Samantha Lo, Mostafa H. Ammar, Ellen Zegura, Marwan Fayed |
Networking | 4 |
| 2012 | Poster: towards position-based routing for mobile environmentsabstractDespite its simplicity there exists, as yet, no position-based routing that is suitable for dynamic networks: Existing schemes construct subgraphs or overlays that come at a cost that may be too high. In a network where nodes are mobile, such constructions risk becoming stale before they become stable, potentially invalidating routing decisions. David E. Cairns, Marwan Fayed |
MobiSys | 2 |
| 2012 | User-level data center tomographyabstractMeasurement and inference in data centers present a set of opportunities and challenges distinct from the Internet domain. Existing toolsets may be perturbed or be mislead by issues related to virtualization. Yet, while equally confronted by scale, data centers are relatively homogenous and symmetric. We believe these may be attributes to be exploited. However, data is required to better evaluate our hypotheses. Therefore, we introduce our efforts to gather data using a single framework from which we can launch tests of our choosing. Our observations reinforce recent claims, but indicate changes in the network. They also reveal additional obfuscations stemming from virtualization. Neil Alexander Twigg, Marwan Fayed, Colin Perkins, Dimitrios P. Pezaros, Fung Po Tso 0001 |
SIGCOMM | 2 |
| 2009 | A Mapping of Wireless Network Boundaries Using Localised Alpha-ShapesabstractIntuitively, many wireless and sensing applications benefit from knowledge of network boundaries. Many virtual coordinate constructions rely on the furthest set of nodes as beacons. Network edges may also bound routing holes in the network, regions of failure due to environmental effects, or indicate the need for additional deployment. In this paper we propose an algorithm to identify nodes and links that sit on the boundaries of the physical network. Edge nodes may then participate to map the network boundaries. Our algorithm is provably correct and exploits the relationship between alphahulls, a generalisation of the convex hull, and communication range. This relationship allows nodes on network boundaries to identify themselves without outside intervention. We then show via simulation that our algorithm identifies meaningful boundaries even in networks of low-density and non-uniform distribution. Marwan Fayed, Hussein T. Mouftah |
GLOBECOM | 1 |
| 2009 | Localised alpha-shape computations for boundary recognition in sensor networks
Marwan Fayed, Hussein T. Mouftah |
Ad Hoc Networks | 1 |
| 2007 | Position Estimation Error in Edge Detection for Wireless Sensor Networks using Local Convex ViewabstractIntuitively, identification of nodes close to the network edge is key to the successful setup, and continued operation, of many sensor network protocols and applications. In a previous study [1] we introduced local convex view (lcv) as a means to identify nodes close to the network edge by computing the convex hull of nodes within range. In this paper we evaluate lcv in the presence of position estimation error. Extensive simulations with networks of varying size and topology reveal the surprising observation that lev seems unaffected by estimation error. Motivated by this observation we enumerate a complete set of base node configurations seen by lcv. An analysis reveals that lcv is immune to two of these configurations. Further simulations show the frequency of false-positives and false-negatives imposed by a third, ambiguous, configuration to be low. The frequency of the ambiguous case is 10% in the worst case, for all networks tested. We conclude that the geometric properties underlying lcv are responsible for its resilience to error. Marwan Fayed, Hussein T. Mouftah |
GLOBECOM | 1 |