Alistair King

dblp:121/4962 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7Security and privacy · 4 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
7 papers
Routing and switching · 39% Network measurement and analytics · 36% Internet architecture and protocols · 22%
Network and information security
5 papers
Network security · 86% Malware analysis · 14%

Topics — the 15 heaviest of 18, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Routing and switching › inter-domain routing
BGP
0.642019
ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018
Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019
Lost in Space: Improving Inference of IPv4 Address Space Utilization · IEEE J. Sel. Areas Commun. 2016
Network security › network scanning
internet-wide scanning
0.612022
Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope · USENIX Security Symposium 2022
Network security
network measurement
0.612022
Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope · USENIX Security Symposium 2022
Network security › routing security › interdomain routing security
BGP hijacking
0.412019
Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019
Malware analysis
botnet
0.422015
Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015
Analysis of a "/0" stealth scan from a botnet · Internet Measurement Conference 2012
Routing and switching › inter-domain routing › inter-domain routing security
BGP hijacking
0.312018
ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018
Internet architecture and protocols
network security
0.312018
ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018
Network measurement and analytics › internet measurement › routing measurement
BGP data analysis
0.212016
BGPStream: A Software Framework for Live and Historical BGP Data Analysis · Internet Measurement Conference 2016
Network measurement and analytics
passive measurement
0.212016
Lost in Space: Improving Inference of IPv4 Address Space Utilization · IEEE J. Sel. Areas Commun. 2016
Network measurement and analytics
traffic measurement
0.212015
Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015
Routing and switching › inter-domain routing
inter-domain routing security
0.112019
Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table · Internet Measurement Conference 2019
Network measurement and analytics › internet measurement › routing measurement
BGP monitoring
0.112018
ARTEMIS: Neutralizing BGP Hijacking Within a Minute · IEEE/ACM Trans. Netw. 2018
Internet of things and sensor networks › wireless sensor network › data collection protocol
collection routing
0.112016
BGPStream: A Software Framework for Live and Historical BGP Data Analysis · Internet Measurement Conference 2016
Network security › intrusion detection and prevention
intrusion detection
0.112015
Analysis of a "/0" Stealth Scan From a Botnet · IEEE/ACM Trans. Netw. 2015
Network measurement and analytics › traffic analysis
darknet traffic analysis
0.012012
Analysis of a "/0" stealth scan from a botnet · Internet Measurement Conference 2012

Methods — techniques the papers use, named apart from their topics

machine learning · 0.8feature engineering · 0.8traffic correlation · 0.7network traffic analysis · 0.6honeypot logs · 0.6backscatter analysis · 0.6DNS measurement · 0.6visualization · 0.4darknet measurement · 0.3passive measurement · 0.2active measurement · 0.2
YearPublicationVenuePosition
2022 Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope
Raphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti, Thomas C. Schmidt, Matthias Wählisch
USENIX Security Symposium3
2020 To Filter or Not to Filter: Measuring the Benefits of Registering in the RPKI Today
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark
PAM3
2019 Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table
abstract
BGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems.
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark
Internet Measurement Conference3
2018 ARTEMIS: Neutralizing BGP Hijacking Within a Minute
abstract
Border gateway protocol (BGP) prefix hijacking is a critical threat to Internet organizations and users. Despite the availability of several defense approaches (ranging from RPKI to popular third-party services), none of them solves the problem adequately in practice. In fact, they suffer from: (i) lack of detection comprehensiveness, allowing sophisticated attackers to evade detection; (ii) limited accuracy, especially in the case of third-party detection; (iii) delayed verification and mitigation of incidents, reaching up to days; and (iv) lack of privacy and of flexibility in post-hijack counteractions, on the side of network operators. In this paper, we propose ARTEMIS, a defense approach (a) based on accurate and fast detection operated by the autonomous system itself, leveraging the pervasiveness of publicly available BGP monitoring services and their recent shift towards real-time streaming and thus (b) enabling flexible and fast mitigation of hijacking events. Compared to the previous work, our approach combines characteristics desirable to network operators, such as comprehensiveness, accuracy, speed, privacy, and flexibility. Finally, we show through real-world experiments that with the ARTEMIS approach, prefix hijacking can be neutralized within a minute.
Pavlos Sermpezis, Vasileios Kotronis, Petros Gigis, Xenofontas A. Dimitropoulos, Danilo Cicalese, Alistair King, Alberto Dainotti
IEEE/ACM Trans. Netw.6
2017 Millions of targets under attack: a macroscopic characterization of the DoS ecosystem
abstract
Denial-of-Service attacks have rapidly increased in terms of frequency and intensity, steadily becoming one of the biggest threats to Internet stability and reliability. However, a rigorous comprehensive characterization of this phenomenon, and of countermeasures to mitigate the associated risks, faces many infrastructure and analytic challenges. We make progress toward this goal, by introducing and applying a new framework to enable a macroscopic characterization of attacks, attack targets, and DDoS Protection Services (DPSs). Our analysis leverages data from four independent global Internet measurement infrastructures over the last two years: backscatter traffic to a large network telescope; logs from amplification honeypots; a DNS measurement platform covering 60% of the current namespace; and a DNS-based data set focusing on DPS adoption. Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all / 24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks. In our data, Web servers were the most prominent attack target; an average of 3% of the Web sites in .com, .net, and .org were involved with attacks, daily. Finally, we shed light on factors influencing migration to a DPS.
Mattijs Jonker, Alistair King, Johannes Krupp, Christian Rossow, Anna Sperotto, Alberto Dainotti
Internet Measurement Conference2
2016 BGPStream: A Software Framework for Live and Historical BGP Data Analysis
Chiara Orsini 0001, Alistair King, Danilo Giordano, Vasileios Giotsas, Alberto Dainotti
Internet Measurement Conference2
2016 Lost in Space: Improving Inference of IPv4 Address Space Utilization
abstract
One challenge in understanding the evolution of the Internet infrastructure is the lack of systematic mechanisms for monitoring the extent to which allocated IP addresses are actually used. In this paper, we advance the science of inferring IPv4 address space utilization by proposing a novel taxonomy and analyzing and correlating results obtained through different types of measurements. We have previously studied an approach based on passive measurements that can reveal used portions of the address space unseen by active approaches. In this paper, we study such passive approaches in detail, extending our methodology to new types of vantage points and identifying traffic components that most significantly contribute to discovering used IPv4 network blocks. We then combine the results we obtained through passive measurements together with data from active measurement studies, as well as measurements from Border Gateway Protocol and additional data sets available to researchers. Through the analysis of this large collection of heterogeneous data sets, we substantially improve the state of the art in terms of: 1) understanding the challenges and opportunities in using passive and active techniques to study address utilization and 2) knowledge of the utilization of the IPv4 space.
Alberto Dainotti, Karyn Benson, Alistair King, Bradley Huffaker, Eduard Glatz, Xenofontas A. Dimitropoulos, Philipp Richter, Alessandro Finamore, Alex C. Snoeren
IEEE J. Sel. Areas Commun.3
2015 Analysis of a "/0" Stealth Scan From a Botnet
abstract
Botnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet.
Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè
IEEE/ACM Trans. Netw.2
2014 Nightlights: Entropy-Based Metrics for Classifying Darkspace Traffic Patterns
Tanja Zseby, Nevil Brownlee, Alistair King, K. C. Claffy
PAM3
2013 The Day after Patch Tuesday: Effects Observable in IP Darkspace Traffic
Tanja Zseby, Alistair King, Nevil Brownlee, K. C. Claffy
PAM2
2012 Analysis of a "/0" stealth scan from a botnet
abstract
Botnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial of service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February of last year. This 12-day scan originated from approximately 3 million distinct IP addresses, and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers, its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This work offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet.
Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè
Internet Measurement Conference2