EDBT 2026 Demo / reviewers in the wild / expert
Matthew J. Luckie
dblp:12/4563 · also Matthew Luckie
· DBLP profile ↗
44ranked-venue papers
17as first author
12since 2021 · last 2026
0000-0002-3872-4624ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 31 · 14 first-author · 7 since 2021Security and privacy · 13 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Aliens Among Us: Observing Private or Reserved IPs on the Public Internet
Radu Anghel, Carlos Gañán, Qasim Lone, Matthew J. Luckie, Yury Zhauniarovich |
NDSS | 4 |
| 2025 | LACeS: An Open, Fast, Responsible and Efficient Longitudinal Anycast Census Systemabstract[1.5.4] - 2026-08-10 Changed Fixed --accuracy quadratic cost - candidate_diameter was computed by comparing every pair of surviving candidates. This was expensive for large MIS discs. We now approximate the distance for large MIS discs using a farthest-point sweep. Documentation Added a section on the accuracy trade-off between disc intersection and single-disc (iGreedy) geolocation. Full Changelog: https://github.com/rhendriks/MiGreedy/compare/v1.5.3...v1.5.4 Remi Hendriks, Matthew J. Luckie, Mattijs Jonker, Raffaele Sommese, Roland van Rijswijk-Deij |
IMC | 2 |
| 2025 | Replication: Characterizing MPLS Tunnels over Internet PathsabstractTraceroute is a critical tool in the Internet measurement toolbox, but its output can be misleading. One problem for traceroute analysis is that certain types of Multiprotocol Label Switching (MPLS) tunnels hide routers from traceroute output. Worse still, there is no simple way to detect or reveal missing routers. Any analysis that expects comprehensive topology discovery—including identifying performance bottlenecks, analyzing traffic engineering approaches, and evaluating traffic sovereignty—needs to account for MPLS. In this paper, we replicate previous work by Vanaubel et al. [18, 21] to characterize and provide a snapshot of the current deployment of MPLS tunnels. We also release a sustainable and easily deployed tool for MPLS detection, called PyTNT. Using PyTNT, we find that the problematic types of MPLS tunnels remain prevalent, though we inferred a general decrease in MPLS usage across the Internet. We also inferred that public clouds accounted for 3 of the top 10 networks with the most routers observed to be in MPLS tunnels. Finally, we observed more MPLS routers in Europe than any in other continent, and more MPLS routers in the U.S. than any other country. Jarrett Huddleston, Matthew J. Luckie, Alexander Marder |
IMC | 2 |
| 2025 | R&E Routing Policy: Inference and ImplicationabstractBGP hides information that is crucial for building accurate routing models. In this paper, we combine BGP and active probing to infer relative route preference policies of research and education R&E connected ASes. We inferred that systems in ≈88% of <12K prefixes that 2,578 ASes announced in the R&E ecosystem were insensitive to AS path length when selecting provider routes -- only ≈8-9% appeared to assign the same local preference to available R&E and commodity routes. We validate our method, and discuss broader application of the method to infer relative route preference, a crucial step in being able to accurately model routing policies. Matthew J. Luckie, Steven Wallace, Karl Newell, Jeff Bartig, Sadi Koçak, Niels den Otter, Kaj Koole, James Deaton, K. C. Claffy |
IMC | 1 |
| 2025 | An Integrated Active Measurement Programming Environment
Matthew J. Luckie, Shivani Hariprasad, Raffaele Sommese, Brendon Jones, Ken Keys, Ricky K. P. Mok, K. C. Claffy |
PAM | 1 |
| 2023 | Coarse-grained Inference of BGP Community IntentabstractBGP communities allow operators to influence routing decisions made by other networks (action communities) and to annotate their network's routing information with metadata such as where each route was learned or the relationship the network has with their neighbor (information communities). BGP communities also help researchers understand complex Internet routing behaviors. However, there is no standard convention for how operators assign community values, and significant efforts to scalably infer community meanings have ignored this high-level classification. We discovered that doing so comes at significant cost in accuracy, of both inference and validation. To advance this narrow but powerful direction in Internet infrastructure research, we design and validate an algorithm to execute this first fundamental step: inferring whether a BGP community is action or information. We applied our method to 78,480 community values observed in public BGP data for May 2023. Validating our inferences (24,376 action and 54,104 informational communities) against available ground truth (6,259 communities) we find that our method classified 96.5% correctly. We found that the precision of a state-of-the-art location community inference method increased from 68.2% to 94.8% with our classifications. We publicly share our code, dictionaries, inferences, and datasets to enable the community to benefit from them. Thomas Krenc, Matthew J. Luckie, Alexander Marder, K. C. Claffy |
IMC | 2 |
| 2023 | Access Denied: Assessing Physical Risks to Internet Access Networks
Alexander Marder, Zesen Zhang, Ricky K. P. Mok, Ramakrishna Padmanabhan, Bradley Huffaker, Matthew J. Luckie, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Aaron Schulman |
USENIX Security Symposium | 6 |
| 2022 | Stop, DROP, and ROA: effectiveness of defenses through the lens of DROPabstractWe analyze the properties of 712 prefixes that appeared in Spamhaus' Don't Route Or Peer (DROP) list over a nearly three-year period from June 2019 to March 2022. We show that attackers are subverting multiple defenses against malicious use of address space, including creating fraudulent Internet Routing Registry records for prefixes shortly before using them. Other attackers disguised their activities by announcing routes with spoofed origin ASes consistent with historic route announcements, and in one case, with the ASN in a Route Origin Authorization. We quantify the substantial and actively-exploited attack surface in unrouted address space, which warrants reconsideration of RPKI eligibility restrictions by RIRs, and reconsideration of AS0 policies by both operators and RIRs. Leo Oliver, Gautam Akiwate, Matthew J. Luckie, Ben Du, K. C. Claffy |
IMC | 3 |
| 2022 | On the Latency Impact of Remote Peering
Fabrício M. Mazzola, Pedro de B. Marcos, Ignacio Castro, Matthew J. Luckie, Marinho P. Barcellos |
PAM | 4 |
| 2022 | Deployment of Source Address Validation by Network Operators: A Randomized Control TrialabstractIP spoofing, sending IP packets with a false source IP address, continues to be a primary attack vector for large-scale Denial of Service attacks. To combat spoofing, various interventions have been tried to increase the adoption of source address validation (SAV) among network operators. How can SAV deployment be increased? In this work, we conduct the first randomized control trial to measure the effectiveness of various notification mechanisms on SAV deployment. We include new treatments using nudges and channels, previously untested in notification experiments. Our design reveals a painful reality that contrasts with earlier observational studies: none of the notification treatments significantly improved SAV deployment compared to the control group. We explore the reasons for these findings and report on a survey among operators to identify ways forward. A portion of the operators indicate that they do plan to deploy SAV and ask for better notification mechanisms, training, and support materials for SAV implementation. Qasim Lone, Alisa Frik, Matthew J. Luckie, Maciej Korczynski, Michel van Eeten, Carlos Gañán |
SP | 3 |
| 2021 | Learning to extract geographic information from internet router hostnamesabstractGeolocating Internet routers is a long-standing and notoriously difficult challenge, and current solutions lack the accuracy and adaptability to yield reliable results. We revisit this problem, designing a solution capable of accurately and comprehensively extracting geographic information that network operators embed into router interface hostnames. We train our system using dictionaries that map geographic codes to known locations, and constrain inferences with delay measurements conducted from a distributed set of vantage points. While most operators use known geographic codes, some devise their own mnemonic codes for locations, which our system also extracts and interprets. Matthew J. Luckie, Bradley Huffaker, Alexander Marder, Zachary S. Bischof, Marianne Fletcher, K. C. Claffy |
CoNEXT | 1 |
| 2021 | Inferring regional access network topologies: methods and applicationsabstractUsing a toolbox of Internet cartography methods, and new ways of applying them, we have undertaken a comprehensive active measurement-driven study of the topology of U.S. regional access ISPs. We used state-of-the-art approaches in various combinations to accommodate the geographic scope, scale, and architectural richness of U.S. regional access ISPs. In addition to vantage points from research platforms, we used public WiFi hotspots and public transit of mobile devices to acquire the visibility needed to thoroughly map access networks across regions. We observed many different approaches to aggregation and redundancy, across links, nodes, buildings, and at different levels of the hierarchy. One result is substantial disparity in latency from some Edge COs to their backbone COs, with implications for end users of cloud services. Our methods and results can inform future analysis of critical infrastructure, including resilience to disasters, persistence of the digital divide, and challenges for the future of 5G and edge computing. Zesen Zhang, Alexander Marder, Ricky K. P. Mok, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy, Aaron Schulman |
Internet Measurement Conference | 5 |
| 2020 | Learning to Extract and Use ASNs in HostnamesabstractWe present the design, implementation, evaluation, and validation of a system that learns regular expressions (regexes) to extract Autonomous System Numbers (ASNs) from hostnames associated with router interfaces. We train our system with ASNs inferred by Router-ToAsAssignment and bdrmapIT using topological constraints from traceroute paths, as well as ASNs recorded by operators in PeeringDB, to learn regexes for 206 different suffixes. Because these methods for inferring router ownership can infer the wrong ASN, we modify bdrmapIT to integrate this new capability to extract ASNs from hostnames. Evaluating against ground truth, our modification correctly distinguished stale from correct hostnames for 92.5% of hostnames with an ASN different from bdrmapIT's initial inference. This modification allowed bdrmapIT to increase the agreement between extracted and inferred ASNs for these routers in the January 2020 ITDK from 87.4% to 97.1% and reduce the error rate from 1/7.9 to 1/34.5. This work opens a broader horizon of opportunity for evidence-based router ownership inference. Matthew J. Luckie, Alexander Marder, Marianne Fletcher, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2020 | Spoofed traffic inference at IXPs: Challenges, methods and analysis
Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
Comput. Networks | 2 |
| 2019 | Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetabstractThe Spoofer project has collected data on the deployment and characteristics of IP source address validation on the Internet since 2005. Data from the project comes from participants who install an active probing client that runs in the background. The client automatically runs tests both periodically and when it detects a new network attachment point. We analyze the rich dataset of Spoofer tests in multiple dimensions: across time, networks, autonomous systems, countries, and by Internet protocol version. In our data for the year ending August 2019, at least a quarter of tested ASes did not filter packets with spoofed source addresses leaving their networks. We show that routers performing Network Address Translation do not always filter spoofed packets, as 6.4% of IPv4/24 tested in the year ending August 2019 did not filter. Worse, at least two thirds of tested ASes did not filter packets entering their networks with source addresses claiming to be from within their network that arrived from outside their network. We explore several approaches to encouraging remediation and the challenges of evaluating their impact. While we have been able to remediate 352 IPv4/24, we have found an order of magnitude more IPv4/24 that remains unremediated, despite myriad remediation strategies, with 21% unremediated for more than six months. Our analysis provides the most complete and confident picture of the Internet's susceptibility to date of this long-standing vulnerability. Although there is no simple solution to address the remaining long-tail of unremediated networks, we conclude with a discussion of possible non-technical interventions, and demonstrate how the platform can support evaluation of the impact of such interventions over time. Matthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys, Joshua A. Kroll, K. C. Claffy |
CCS | 1 |
| 2019 | Challenges in inferring spoofed traffic at IXPsabstractAscertaining that a network will forward spoofed traffic usually requires an active probing vantage point in that network, effectively preventing a comprehensive view of this global Internet vulnerability. Recently, researchers have proposed using Internet Exchange Points (IXPs) as observatories to detect spoofed packets, by leveraging Autonomous System (AS) topology knowledge extracted from Border Gateway Protocol (BGP) data to infer which source addresses should legitimately appear across parts of the IXP switch fabric. We demonstrate that the existing literature does not capture several fundamental challenges to this approach, including noise in BGP data sources, heuristic AS relationship inference, and idiosyncrasies in IXP interconnectivity fabrics. We propose a novel method to navigate these challenges, leveraging customer cone semantics of AS relationships to guide precise classification of inter-domain traffic as in-cone, out-of-cone (spoofed), unverifiable, bogon, and unassigned. We apply our method to a mid-size IXP with approximately 200 members, and find an upper bound volume of out-of-cone traffic to be more than an order of magnitude less than the previous method inferred on the same data. Our work illustrates the subtleties of scientific assessments of operational Internet infrastructure, and the need for a community focus on reproducing and repeating previous methods. Lucas F. Müller, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Marinho P. Barcellos |
CoNEXT | 2 |
| 2019 | Learning Regexes to Extract Router Names from HostnamesabstractWe present the design, implementation, evaluation, and validation of a system that automatically learns to extract router names (router identifiers) from hostnames stored by network operators in different DNS zones, which we represent by regular expressions (regexes). Our supervised-learning approach evaluates automatically generated candidate regexes against sets of hostnames for IP addresses that other alias resolution techniques previously inferred to identify interfaces on the same router. Conceptually, if three conditions hold: (1) a regex extracts the same value from a set of hostnames associated with IP addresses on the same router; (2) the value is unique to that router; and (3) the regex extracts names for multiple routers in the suffix, then we conclude the regex accurately represents the naming convention for the suffix. Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2019 | Tracking the deployment of IPv6: Topology, routing and performance
Siyuan Jia, Matthew J. Luckie, Bradley Huffaker, Ahmed Elmokashfi, Emile Aben, K. C. Claffy, Amogh Dhamdhere |
Comput. Networks | 2 |
| 2018 | Pushing the Boundaries with bdrmapIT: Mapping Router Ownership at Internet Scale
Alexander Marder, Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, K. C. Claffy, Jonathan M. Smith |
Internet Measurement Conference | 2 |
| 2018 | Inferring persistent interdomain congestionabstractThere is significant interest in the technical and policy communities regarding the extent, scope, and consumer harm of persistent interdomain congestion. We provide empirical grounding for discussions of interdomain congestion by developing a system and method to measure congestion on thousands of interdomain links without direct access to them. We implement a system based on the Time Series Latency Probes (TSLP) technique that identifies links with evidence of recurring congestion suggestive of an under-provisioned link. We deploy our system at 86 vantage points worldwide and show that congestion inferred using our lightweight TSLP method correlates with other metrics of interconnection performance impairment. We use our method to study interdomain links of eight large U.S. broadband access providers from March 2016 to December 2017, and validate our inferences against ground-truth traffic statistics from two of the providers. For the period of time over which we gathered measurements, we did not find evidence of widespread endemic congestion on interdomain links between access ISPs and directly connected transit and content providers, although some such links exhibited recurring congestion patterns. We describe limitations, open challenges, and a path toward the use of this method for large-scale third-party monitoring of the Internet interconnection ecosystem. Amogh Dhamdhere, David D. Clark, Alexander Gamero-Garrido, Matthew J. Luckie, Ricky K. P. Mok, Gautam Akiwate, Kabir Gogia, Vaibhav Bajpai, Alex C. Snoeren, K. C. Claffy |
SIGCOMM | 4 |
| 2017 | The record route option is an option!abstractThe IPv4 Record Route (RR) Option instructs routers to record their IP addresses in a packet. RR is subject to a nine hop limit and, traditionally, inconsistent support from routers. Recent changes in interdomain connectivity---the so-called "flattening Internet"---and new best practices for how routers should handle RR packets suggest that now is a good time to reassess the potential of the RR Option. Brian J. Goodchild, Yi-Ching Chiu, Rob Hansen, Haonan Lu, Matt Calder, Matthew J. Luckie, Wyatt Lloyd, David R. Choffnes, Ethan Katz-Bassett |
Internet Measurement Conference | 6 |
| 2017 | Using Loops Observed in Traceroute to Infer the Ability to Spoof
Qasim Lone, Matthew J. Luckie, Maciej Korczynski, Michel van Eeten |
PAM | 2 |
| 2017 | The Impact of Router Outages on the AS-level InternetabstractWe propose and evaluate a new metric for understanding the dependence of the AS-level Internet on individual routers. Whereas prior work uses large volumes of reachability probes to infer outages, we design an efficient active probing technique that directly and unambiguously reveals router restarts. We use our technique to survey 149,560 routers across the Internet for 2.5 years. 59,175 of the surveyed routers (40%) experience at least one reboot, and we quantify the resulting impact of each router outage on global IPv4 and IPv6 BGP reachability. Matthew J. Luckie, Robert Beverly |
SIGCOMM | 1 |
| 2016 | bdrmap: Inference of Borders Between IP Networks
Matthew J. Luckie, Amogh Dhamdhere, Bradley Huffaker, David D. Clark, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2016 | Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security Policy
Jakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. Bailey |
NDSS | 2 |
| 2015 | A server-to-server view of the internetabstractWhile the performance characteristics of access networks and end-user-to-server paths are well-studied, measuring the performance of the Internet's core remains, largely, an uncharted territory. With more content being moved closer to the end-user, server-to-server paths have increased in length and have a significant role in dictating the quality of services offered by content and service providers. In this paper, we present a large-scale study of the effects of routing changes and congestion on the end-to-end latencies of server-to-server paths in the core of the Internet. Balakrishnan Chandrasekaran 0002, Georgios Smaragdakis, Arthur W. Berger, Matthew J. Luckie, Keung-Chi Ng |
CoNEXT | 4 |
| 2015 | Mapping peering interconnections to a facilityabstractAnnotating Internet interconnections with robust physical coordinates at the level of a building facilitates network management including interdomain troubleshooting, but also has practical value for helping to locate points of attacks, congestion, or instability on the Internet. But, like most other aspects of Internet interconnection, its geophysical locus is generally not public; the facility used for a given link must be inferred to construct a macroscopic map of peering. We develop a methodology, called constrained facility search, to infer the physical interconnection facility where an interconnection occurs among all possible candidates. We rely on publicly available data about the presence of networks at different facilities, and execute traceroute measurements from more than 8,500 available measurement servers scattered around the world to identify the technical approach used to establish an interconnection. A key insight of our method is that inference of the technical approach for an interconnection sufficiently constrains the number of candidate facilities such that it is often possible to identify the specific facility where a given interconnection occurs. Validation via private communication with operators confirms the accuracy of our method, which outperforms heuristics based on naming schemes and IP geolocation. Our study also reveals the multiple roles that routers play at interconnection facilities; in many cases the same router implements both private interconnections and public peerings, in some cases via multiple Internet exchange points. Our study also sheds light on peering engineering strategies used by different types of networks around the globe. Vasileios Giotsas, Georgios Smaragdakis, Bradley Huffaker, Matthew J. Luckie, K. C. Claffy |
CoNEXT | 4 |
| 2015 | Resilience of Deployed TCP to Blind AttacksabstractAs part of TCP's steady evolution, recent standards have recommended mechanisms to protect against weaknesses in TCP. But adoption, configuration, and deployment of TCP improvements can be slow. In this work, we consider the resilience of deployed TCP implementations to blind in-window attacks, where an off-path adversary disrupts an established connection by sending a packet that the victim believes came from its peer, causing data corruption or connection reset. We tested operating systems (and middleboxes deployed in front) of webservers in the wild in September 2015 and found 22% of connections vulnerable to in-window SYN and reset packets, 30% vulnerable to in-window data packets, and 38.4% vulnerable to at least one of three in-window attacks we tested. We also tested out-of-window packets and found that while few deployed systems were vulnerable to reset and SYN packets, 5.4% of connections accepted in-window data with an invalid acknowledgment number. In addition to evaluating commodity TCP stacks, we found vulnerabilities in 12 of 14 of the routers and switches we characterized -- critical network infrastructure where the potential impact of any TCP vulnerabilities is particularly acute. This surprisingly high level of extant vulnerabilities in the most mature Internet transport protocol in use today is a perfect illustration of the Internet's fragility. Embedded in historical context, it also provides a strong case for more systematic, scientific, and longitudinal measurement and quantitative analysis of fundamental properties of critical Internet infrastructure, as well as for the importance of better mechanisms to get best security practices deployed. Matthew J. Luckie, Robert Beverly, Tiange Wu, Mark Allman, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2015 | Measuring and Characterizing IPv6 Router Availability
Robert Beverly, Matthew J. Luckie, Lorenza Mosley, K. C. Claffy |
PAM | 2 |
| 2015 | IPv6 AS Relationships, Cliques, and Congruence
Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
PAM | 2 |
| 2014 | Inferring Complex AS RelationshipsabstractThe traditional approach of modeling relationships between ASes abstracts relationship types into three broad categories: transit, peering, and sibling. More complicated configurations exist, and understanding them may advance our knowledge of Internet economics and improve models of routing. We use BGP, traceroute, and geolocation data to extend CAIDA's AS relationship inference algorithm to infer two types of complex relationships: hybrid relationships, where two ASes have different relationships at different interconnection points, and partial transit relationships, which restrict the scope of a customer relationship to the provider's peers and customers. Using this new algorithm, we find 4.5% of the 90,272 provider-customer relationships observed in March 2014 were complex, including 1,071 hybrid relationships and 2,955 partial-transit relationships. Because most peering relationships are invisible, we believe these numbers are lower bounds. We used feedback from operators, and relationships encoded in BGP communities and RPSL, to validate 20% and 6.9% of our partial transit and hybrid inferences, respectively, and found our inferences have 92.9% and 97.0% positive predictive values. Hybrid relationships are not only established betweenlarge transit providers; in 57% of the inferred hybrid transit/peering relationships the customer had a customer cone of fewer than 5 ASes. Vasileios Giotsas, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 2 |
| 2014 | Challenges in Inferring Internet Interdomain CongestionabstractWe introduce and demonstrate the utility of a method to localize and quantify inter-domain congestion in the Internet. Our Time Sequence Latency Probes (TSLP) method depends on two facts: Internet traffic patterns are typically diurnal, and queues increase packet delay through a router during periods of adjacent link congestion. Repeated round trip delay measurements from a single test point to the two edges of a congested link will show sustained increased latency to the far (but not to the near) side of the link, a delay pattern that differs from the typical diurnal pattern of an uncongested link. We describe our technique and its surprising potential,carefully analyze the biggest challenge with the methodology (interdomain router-level topology inference), describe other less severe challenges, and present initial results that are sufficiently promising to motivate further attention to overcoming the challenges. Matthew J. Luckie, Amogh Dhamdhere, David D. Clark, Bradley Huffaker, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2014 | A Second Look at Detecting Third-Party Addresses in Traceroute Traces with the IP Timestamp Option
Matthew J. Luckie, K. C. Claffy |
PAM | 1 |
| 2013 | Inferring multilateral peeringabstractThe AS topology incompleteness problem is derived from difficulties in the discovery of p2p links, and is amplified by the increasing popularity of Internet eXchange Points (IXPs) to support peering interconnection. We describe, implement, and validate a method for discovering currently invisible IXP peering links by mining BGP communities used by IXP route servers to implement multilateral peering (MLP), including communities that signal the intent to restrict announcements to a subset of participants at a given IXP. Using route server data juxtaposed with a mapping of BGP community values, we can infer 206K p2p links from 13 large European IXPs, four times more p2p links than what is directly observable in public BGP data. The advantages of the proposed technique are threefold. First, it utilizes existing BGP data sources and does not require the deployment of additional vantage points nor the acquisition of private data. Second, it requires only a few active queries, facilitating repeatability of the measurements. Finally, it offers a new source of data regarding the dense establishment of MLP at IXPs. Vasileios Giotsas, Shi Zhou, Matthew J. Luckie, K. C. Claffy |
CoNEXT | 3 |
| 2013 | Speedtrap: internet-scale IPv6 alias resolutionabstractImpediments to resolving IPv6 router aliases have precluded understanding the emerging router-level IPv6 Internet topology. In this work, we design, implement, and validate the first Internet-scale alias resolution technique for IPv6. Our technique, speedtrap, leverages the ability to induce fragmented IPv6 responses from router interfaces in a particular temporal pattern that produces distinguishing per-router fingerprints. Our algorithm surmounts three fundamental challenges to Internet-scale IPv6 alias resolution using fragment identifier values: (1) unlike for IPv4, the identifier counters on IPv6 routers have no natural velocity, (2) the values of these counters are similar across routers, and (3) the packet size required to collect inferences is 46 times larger than required in IPv4. We demonstrate the efficacy of the technique by producing router-level Internet IPv6 topologies using measurements from CAIDA's distributed infrastructure. Our preliminary work represents a step toward understanding the Internet's IPv6 router-level topology, an important objective with respect to IPv6 network resilience, security, policy, and longitudinal evolution. Matthew J. Luckie, Robert Beverly, William Brinkmeyer, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2013 | AS relationships, customer cones, and validationabstractBusiness relationships between ASes in the Internet are typically confidential, yet knowledge of them is essential to understand many aspects of Internet structure, performance, dynamics, and evolution. We present a new algorithm to infer these relationships using BGP paths. Unlike previous approaches, our algorithm does not assume the presence (or seek to maximize the number) of valley-free paths, instead relying on three assumptions about the Internet's inter-domain structure: (1) an AS enters into a provider relationship to become globally reachable; and (2) there exists a peering clique of ASes at the top of the hierarchy, and (3) there is no cycle of p2c links. We assemble the largest source of validation data for AS-relationship inferences to date, validating 34.6% of our 126,082 c2p and p2p inferences to be 99.6% and 98.7% accurate, respectively. Using these inferred relationships, we evaluate three algorithms for inferring each AS's customer cone, defined as the set of ASes an AS can reach using customer links. We demonstrate the utility of our algorithms for studying the rise and fall of large transit providers over the last fifteen years, including recent claims about the flattening of the AS-level topology and the decreasing influence of tier-1 ASes on the global Internet. Matthew J. Luckie, Bradley Huffaker, Amogh Dhamdhere, Vasileios Giotsas, K. C. Claffy |
Internet Measurement Conference | 1 |
| 2013 | IPv6 Alias Resolution via Induced Fragmentation
Robert Beverly, William Brinkmeyer, Matthew J. Luckie, Justin P. Rohrer |
PAM | 3 |
| 2013 | Internet-Scale IPv4 Alias Resolution With MIDARabstractA critical step in creating accurate Internet topology maps from traceroute data is mapping IP addresses to routers, a process known as alias resolution. Recent work in alias resolution inferred aliases based on similarities in IP ID time series produced by different IP addresses. We design, implement, and experiment with a new tool that builds on these insights to scale to Internet-scale topologies, i.e., millions of addresses, with greater precision and sensitivity. MIDAR, our Monotonic ID-Based Alias Resolution tool, provides an extremely precise ID comparison test based on monotonicity rather than proximity. MIDAR integrates multiple probing methods, multiple vantage points, and a novel sliding-window probe scheduling algorithm to increase scalability to millions of IP addresses. Experiments show that MIDAR's approach is effective at minimizing the false positive rate sufficiently to achieve a high positive predictive value at Internet scale. We provide sample statistics from running MIDAR on over 2 million addresses. We also validate MIDAR and RadarGun against available ground truth and show that MIDAR's results are significantly better than RadarGun's. Tools such as MIDAR can enable longitudinal study of the Internet's topological evolution. Ken Keys, Young Hyun, Matthew J. Luckie, K. C. Claffy |
IEEE/ACM Trans. Netw. | 3 |
| 2012 | Measuring the deployment of IPv6: topology, routing and performanceabstractWe use historical BGP data and recent active measurements to analyze trends in the growth, structure, dynamics and performance of the evolving IPv6 Internet, and compare them to the evolution of IPv4. We find that the IPv6 network is maturing, albeit slowly. While most core Internet transit providers have deployed IPv6, edge networks are lagging. Early IPv6 network deployment was stronger in Europe and the Asia-Pacific region, than in North America. Current IPv6 network deployment still shows the same pattern. The IPv6 topology is characterized by a single dominant player -- Hurricane Electric -- which appears in a large fraction of IPv6 AS paths, and is more dominant in IPv6 than the most dominant player in IPv4. Routing dynamics in the IPv6 topology are largely similar to those in IPv4, and churn in both networks grows at the same rate as the underlying topologies. Our measurements suggest that performance over IPv6 paths is comparable to that over IPv4 paths if the AS-level paths are the same, but can be much worse than IPv4 if the AS-level paths differ. Amogh Dhamdhere, Matthew J. Luckie, Bradley Huffaker, K. C. Claffy, Ahmed Elmokashfi, Emile Aben |
Internet Measurement Conference | 2 |
| 2010 | Scamper: a scalable and extensible packet prober for active measurement of the internetabstractPath MTU Discovery (PMTUD) is widely believed to be unreliable because of firewalls that discard ICMP “Packet Too Big”messages. This paper measures PMTUD behaviour for 50,000 popular websites and finds the failure rate in IPv4 is much less than previous studies. We measure the overall failure rate between 5% and 18%, depending on the MTU of the constraining link. We explore methods webserver operators are using to reduce their dependence on PMTUD, and find 11% limit themselves to sending packets no larger than 1380 bytes. We identify a number of common behaviours that seem to be software bugs rather than filtering by firewalls. If these are corrected PMTUD failures could be reduced by 63%. We further find the IPv6 failure rate is less than the IPv4 rate even with more scope for failure in IPv6. Matthew J. Luckie |
Internet Measurement Conference | 1 |
| 2010 | Measuring path MTU discovery behaviourabstractPath MTU Discovery (PMTUD) is widely believed to be unreliable because of firewalls that discard ICMP "Packet Too Big" messages. This paper measures PMTUD behaviour for 50,000 popular websites and finds the failure rate in IPv4 is much less than previous studies. We measure the overall failure rate between 5% and 18%, depending on the MTU of the constraining link. We explore methods webserver operators are using to reduce their dependence on PMTUD, and find 11% limit themselves to sending packets no larger than 1380 bytes. We identify a number of common behaviours that seem to be software bugs rather than filtering by firewalls. If these are corrected PMTUD failures could be reduced by 63%. We further find the IPv6 failure rate is less than the IPv4 rate even with more scope for failure in IPv6. Matthew J. Luckie, Ben Stasiewicz |
Internet Measurement Conference | 1 |
| 2008 | Traceroute probe method and forward IP path inferenceabstractSeveral traceroute probe methods exist, each designed to perform better in a scenario where another fails. This paper examines the effects that the choice of probe method has on the inferred forward IP path by comparing the paths inferred with UDP, ICMP, and TCP-based traceroute methods to (1) a list of routable IP addresses, (2) a list of known routers, and (3) a list of well-known websites. We further compare methods by examining seven months of macroscopic Internet topology data collected by CAIDA's Archipelago infrastructure. Matthew J. Luckie, Young Hyun, Bradley Huffaker |
Internet Measurement Conference | 1 |
| 2007 | Analysis of ICMP Quotations
David Malone, Matthew J. Luckie |
PAM | 2 |
| 2005 | Inferring and Debugging Path MTU Discovery Failures
Matthew J. Luckie, Kenjiro Cho, Bill Owens |
Internet Measurement Conference | 1 |