EDBT 2026 Demo / reviewers in the wild / expert
Alistair King
dblp:121/4962
· DBLP profile ↗
11ranked-venue papers
0as first author
1since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7Security and privacy · 4 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
7 papers |
Routing and switching · 39% Network measurement and analytics · 36% Internet architecture and protocols · 22% | |
| Network and information security
5 papers |
Network security · 86% Malware analysis · 14% |
Topics — the 15 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Routing and switching › inter-domain routing
BGP |
0.6 | 4 | 2019 | ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018 Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 Lost in Space: Improving Inference of IPv4 Address Space Utilization · IEEE J. Sel. Areas Commun. 2016 |
Network security › network scanning
internet-wide scanning |
0.6 | 1 | 2022 | Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope · USENIX Security Symposium 2022 |
Network security
network measurement |
0.6 | 1 | 2022 | Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope · USENIX Security Symposium 2022 |
Network security › routing security › interdomain routing security
BGP hijacking |
0.4 | 1 | 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 |
Malware analysis
botnet |
0.4 | 2 | 2015 | Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015 Analysis of a "/0" stealth scan from a botnet · Internet Measurement Conference 2012 |
Routing and switching › inter-domain routing › inter-domain routing security
BGP hijacking |
0.3 | 1 | 2018 | ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018 |
Internet architecture and protocols
network security |
0.3 | 1 | 2018 | ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018 |
Network measurement and analytics › internet measurement › routing measurement
BGP data analysis |
0.2 | 1 | 2016 | BGPStream: A Software Framework for Live and Historical BGP Data Analysis · Internet Measurement Conference 2016 |
Network measurement and analytics
passive measurement |
0.2 | 1 | 2016 | Lost in Space: Improving Inference of IPv4 Address Space Utilization · IEEE J. Sel. Areas Commun. 2016 |
Network measurement and analytics
traffic measurement |
0.2 | 1 | 2015 | Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015 |
Routing and switching › inter-domain routing
inter-domain routing security |
0.1 | 1 | 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019 |
Network measurement and analytics › internet measurement › routing measurement
BGP monitoring |
0.1 | 1 | 2018 | ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018 |
Internet of things and sensor networks › wireless sensor network › data collection protocol
collection routing |
0.1 | 1 | 2016 | BGPStream: A Software Framework for Live and Historical BGP Data Analysis · Internet Measurement Conference 2016 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 1 | 2015 | Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015 |
Network measurement and analytics › traffic analysis
darknet traffic analysis |
0.0 | 1 | 2012 | Analysis of a "/0" stealth scan from a botnet · Internet Measurement Conference 2012 |
Methods — techniques the papers use, named apart from their topics
machine learning · 0.8feature engineering · 0.8traffic correlation · 0.7network traffic analysis · 0.6honeypot logs · 0.6backscatter analysis · 0.6DNS measurement · 0.6visualization · 0.4darknet measurement · 0.3passive measurement · 0.2active measurement · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope
Raphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti, Thomas C. Schmidt, Matthias Wählisch |
USENIX Security Symposium | 3 |
| 2020 | To Filter or Not to Filter: Measuring the Benefits of Registering in the RPKI Today
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
PAM | 3 |
| 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing TableabstractBGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems. Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
Internet Measurement Conference | 3 |
| 2018 | ARTEMIS: Neutralizing BGP Hijacking Within a MinuteabstractBorder gateway protocol (BGP) prefix hijacking is a critical threat to Internet organizations and users. Despite the availability of several defense approaches (ranging from RPKI to popular third-party services), none of them solves the problem adequately in practice. In fact, they suffer from: (i) lack of detection comprehensiveness, allowing sophisticated attackers to evade detection; (ii) limited accuracy, especially in the case of third-party detection; (iii) delayed verification and mitigation of incidents, reaching up to days; and (iv) lack of privacy and of flexibility in post-hijack counteractions, on the side of network operators. In this paper, we propose ARTEMIS, a defense approach (a) based on accurate and fast detection operated by the autonomous system itself, leveraging the pervasiveness of publicly available BGP monitoring services and their recent shift towards real-time streaming and thus (b) enabling flexible and fast mitigation of hijacking events. Compared to the previous work, our approach combines characteristics desirable to network operators, such as comprehensiveness, accuracy, speed, privacy, and flexibility. Finally, we show through real-world experiments that with the ARTEMIS approach, prefix hijacking can be neutralized within a minute. Pavlos Sermpezis, Vasileios Kotronis, Petros Gigis, Xenofontas A. Dimitropoulos, Danilo Cicalese, Alistair King, Alberto Dainotti |
IEEE/ACM Trans. Netw. | 6 |
| 2017 | Millions of targets under attack: a macroscopic characterization of the DoS ecosystemabstractDenial-of-Service attacks have rapidly increased in terms of frequency and intensity, steadily becoming one of the biggest threats to Internet stability and reliability. However, a rigorous comprehensive characterization of this phenomenon, and of countermeasures to mitigate the associated risks, faces many infrastructure and analytic challenges. We make progress toward this goal, by introducing and applying a new framework to enable a macroscopic characterization of attacks, attack targets, and DDoS Protection Services (DPSs). Our analysis leverages data from four independent global Internet measurement infrastructures over the last two years: backscatter traffic to a large network telescope; logs from amplification honeypots; a DNS measurement platform covering 60% of the current namespace; and a DNS-based data set focusing on DPS adoption. Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all / 24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks. In our data, Web servers were the most prominent attack target; an average of 3% of the Web sites in .com, .net, and .org were involved with attacks, daily. Finally, we shed light on factors influencing migration to a DPS. Mattijs Jonker, Alistair King, Johannes Krupp, Christian Rossow, Anna Sperotto, Alberto Dainotti |
Internet Measurement Conference | 2 |
| 2016 | BGPStream: A Software Framework for Live and Historical BGP Data Analysis
Chiara Orsini 0001, Alistair King, Danilo Giordano, Vasileios Giotsas, Alberto Dainotti |
Internet Measurement Conference | 2 |
| 2016 | Lost in Space: Improving Inference of IPv4 Address Space UtilizationabstractOne challenge in understanding the evolution of the Internet infrastructure is the lack of systematic mechanisms for monitoring the extent to which allocated IP addresses are actually used. In this paper, we advance the science of inferring IPv4 address space utilization by proposing a novel taxonomy and analyzing and correlating results obtained through different types of measurements. We have previously studied an approach based on passive measurements that can reveal used portions of the address space unseen by active approaches. In this paper, we study such passive approaches in detail, extending our methodology to new types of vantage points and identifying traffic components that most significantly contribute to discovering used IPv4 network blocks. We then combine the results we obtained through passive measurements together with data from active measurement studies, as well as measurements from Border Gateway Protocol and additional data sets available to researchers. Through the analysis of this large collection of heterogeneous data sets, we substantially improve the state of the art in terms of: 1) understanding the challenges and opportunities in using passive and active techniques to study address utilization and 2) knowledge of the utilization of the IPv4 space. Alberto Dainotti, Karyn Benson, Alistair King, Bradley Huffaker, Eduard Glatz, Xenofontas A. Dimitropoulos, Philipp Richter, Alessandro Finamore, Alex C. Snoeren |
IEEE J. Sel. Areas Commun. | 3 |
| 2015 | Analysis of a "/0" Stealth Scan From a BotnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
IEEE/ACM Trans. Netw. | 2 |
| 2014 | Nightlights: Entropy-Based Metrics for Classifying Darkspace Traffic Patterns
Tanja Zseby, Nevil Brownlee, Alistair King, K. C. Claffy |
PAM | 3 |
| 2013 | The Day after Patch Tuesday: Effects Observable in IP Darkspace Traffic
Tanja Zseby, Alistair King, Nevil Brownlee, K. C. Claffy |
PAM | 2 |
| 2012 | Analysis of a "/0" stealth scan from a botnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial of service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February of last year. This 12-day scan originated from approximately 3 million distinct IP addresses, and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers, its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This work offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
Internet Measurement Conference | 2 |