Oliver Gasser

dblp:147/1125 · DBLP profile ↗
← Back
29ranked-venue papers
3as first author
20since 2021 · last 2026
0000-0002-3425-9331ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 1 first-author · 12 since 2021Security and privacy · 9 · 1 first-author · 8 since 2021
YearPublicationVenuePosition
2026 Unpacking Internet Ossification: A Large-Scale Study of Path-Impairing Middleboxes Across IPv4 and IPv6
Fahad Hilal, Taha Albakour, Oliver Gasser, Kevin Vermeulen
PAM3
2026 Still on Target? An Evaluation of IPv6 Target Generation Algorithms
Lion Steger, Liming Kuang, Johannes Zirngibl, Georg Carle, Oliver Gasser
IEEE Trans. Netw. Serv. Manag.5
2025 Sibling Prefixes: Identifying Similarities in IPv4 and IPv6 Prefixes
abstract
Since the standardization of IPv6 in 1998, both versions of the Internet Protocol have coexisted in the Internet. Clients usually run algorithms such as Happy Eyeballs, to decide whether to connect to an IPv4 or IPv6 endpoint for dual-stack domains. To identify whether two addresses belong to the same device or service, researchers have proposed different forms of alias resolution techniques. Similarly, one can also form siblings of IPv4 and IPv6 addresses belonging to the same device. Traditionally, all of these approaches have focused on individual IP addresses. In this work, we propose the concept of ''sibling prefixes'', where we extend the definition of an IPv4-IPv6 sibling to two IP prefixes---one IPv4 prefix and its sibling IPv6 prefix. We present a technique based on large-scale DNS resolution data to identify 76k IPv4-IPv6 sibling prefixes. We find sibling prefixes to be relatively stable over time. We present SP-Tuner algorithm to tune the CIDR size of sibling prefixes and improve the perfect match siblings from 52% to 82%. For more than half of sibling prefixes, the organization names for their IPv4 and IPv6 origin ASes are identical, and 60% of all sibling prefixes have at least one of the prefixes with a valid ROV status in RPKI. Furthermore, we identify sibling prefixes in 24 hypergiant and CDN networks. Finally, we plan to regularly publish a list of sibling prefixes to be used by network operators and fellow researchers in dual-stack studies.
Fariba Osali, Khwaja Zubair Sediqi, Oliver Gasser
IMC3
2025 Intractable Cookie Crumbs: Unveiling the Nexus of Stateful Banner Interaction and Tracking Cookies
abstract
In response to the ePrivacy Directive and the consent requirements introduced by the GDPR, websites began deploying consent banners to obtain user permission for data collection and processing. However, due to shared third-party services and technical loopholes, non-consensual cross-site tracking can still occur. In fact, contrary to user expectations of seemingly isolated consent, a user's decision on one website may affect tracking behavior on others. In this study, we investigate the technical and behavioral mechanisms behind these discrepancies. Specifically, we disclose a persistent tracking mechanism exploiting web cookies. These cookies, which we refer to as intractable, are initially set on websites with accepted banners, persist in the browser, and are subsequently sent to trackers before the user provides explicit consent on other websites. To meticulously analyze this covert tracking behavior, we conduct an extensive measurement study performing stateful crawls on over 20k domains from the Tranco top list, strategically accepting banners in the first half of domains and measuring intractable cookies in the second half. Our findings reveal that around 50% of websites send at least one intractable cookie, with the majority set to expire after more than 10 days. In addition, enabling the Global Privacy Control (GPC) signal initially reduces the number of intractable cookies by 30% on average, with a further 32% reduction possible on subsequent visits by rejecting the banners. Moreover, websites with Consent Management Platform (CMP) banners, on average, send 6.9 times more intractable cookies compared to those with native banners. Our research further reveals that even if users reject all other banners, they still receive a large number of intractable cookies set by websites with cookie paywalls. Additionally, our measurement on the partitioned cookies---cookies that are restricted to the top-level site and thus mitigate cross-site tracking---shows that only 1.3% of tracking cookies are marked as such, indicating their minimal impact on cross-site tracking via intractable cookies.
Ali Rasaii, Ha Dao, Anja Feldmann, Mohammadmahdi Javid, Oliver Gasser, Devashish Gosain
Proc. Priv. Enhancing Technol.5
2024 Kirin: Hitting the Internet with Distributed BGP Announcements
abstract
The Internet is a critical resource in the daily life of billions of users. To support the growing number of users and their increasing demands, operators continuously scale their network footprint---e.g., by joining Internet Exchange Points (IXPs)---and adopt relevant technologies---such as IPv6---which provides a vastly larger address space than its predecessor.
Lars Prehn, Pawel Foremski, Oliver Gasser
AsiaCCS3
2024 A First Look at NAT64 Deployment In-The-Wild
Amanda Hsu, Frank Li 0001, Paul Pearce, Oliver Gasser
PAM (1)4
2023 Illuminating Router Vendor Diversity Within Providers and Along Network Paths
abstract
The Internet architecture has facilitated a multi-party, distributed, and heterogeneous physical infrastructure where routers from different vendors connect and inter-operate via IP. Such vendor heterogeneity can have important security and policy implications. For example, a security vulnerability may be specific to a particular vendor and implementation, and thus will have a disproportionate impact on particular networks and paths if exploited. From a policy perspective, governments are now explicitly banning particular vendors-or have threatened to do so.
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
IMC2
2023 Pushing Alias Resolution to the Limit
abstract
In this paper, we show that utilizing multiple protocols offers a unique opportunity to improve IP alias resolution and dual-stack inference substantially. Our key observation is that prevalent protocols, e.g., SSH and BGP, reply to unsolicited requests with a set of values that can be combined to form a unique device identifier. More importantly, this is possible by just completing the TCP hand-shake. Our empirical study shows that utilizing readily available scans and our active measurements can double the discovered IPv4 alias sets and more than 30× the dual-stack sets compared to the state-of-the-art techniques. We provide insights into our method's accuracy and performance compared to popular techniques.
Taha Albakour, Oliver Gasser, Georgios Smaragdakis
IMC2
2023 Fifteen Months in the Life of a Honeyfarm
abstract
Honeypots have been used for decades to detect, monitor, and understand attempts of unauthorized use of information systems. Previous studies focused on characterizing the spread of malware, e.g., Mirai and other attacks, or proposed stealthy and interactive architectures to improve honeypot efficiency.
Cristian Munteanu 0001, Said Jawad Saidi, Oliver Gasser, Georgios Smaragdakis, Anja Feldmann
IMC3
2023 Thou Shalt Not Reject: Analyzing Accept-Or-Pay Cookie Banners on the Web
abstract
Privacy regulations have led to many websites showing cookie banners to their users. Usually, cookie banners present the user with the option to "accept" or "reject" cookies. Recently, a new form of paywall-like cookie banner has taken hold on the Web, giving users the option to either accept cookies (and consequently user tracking) or buy a paid subscription for a tracking-free website experience.
Ali Rasaii, Devashish Gosain, Oliver Gasser
IMC3
2023 Characterizing the VPN Ecosystem in the Wild
Aniss Maghsoudlou, Lukas Vermeulen, Ingmar Poese, Oliver Gasser
PAM4
2023 Exploring the Cookieverse: A Multi-Perspective Analysis of Web Cookies
Ali Rasaii, Devashish Gosain, Oliver Gasser
PAM4
2023 How Ready is DNS for an IPv6-Only World?
abstract
Abstract DNS is one of the core building blocks of the Internet. In this paper, we investigate DNS resolution in a strict IPv6-only scenario and find that a substantial fraction of zones cannot be resolved. We point out, that the presence of an resource record for a zone’s nameserver does not necessarily imply that it is resolvable in an IPv6-only environment since the full DNS delegation chain must resolve via IPv6 as well. Hence, in an IPv6-only setting zones may experience an effect similar to what is commonly referred to as lame delegation. Our longitudinal study shows that the continuing centralization of the Internet has a large impact on IPv6 readiness, i.e., a small number of large DNS providers has, and still can, influence IPv6 readiness for a large number of zones. A single operator that enabled IPv6 DNS resolution–by adding IPv6 glue records–was responsible for around 20.3% of all zones in our dataset not resolving over IPv6 until January 2017. Even today, 10% of DNS operators are responsible for more than 97.5% of all zones that do not resolve using IPv6 .
Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig
PAM6
2022 FlowDNS: correlating netflow and DNS streams at scale
abstract
Knowing customer's interests, e.g. which Video-On-Demand (VoD) or Social Network services they are using, helps telecommunication companies with better network planning to enhance the performance exactly where the customer's interests lie, and also offer the customers relevant commercial packages. However, with the increasing deployment of CDNs by different services, identification, and attribution of the traffic on network-layer information alone becomes a challenge: If multiple services are using the same CDN provider, they cannot be easily distinguished based on IP prefixes alone. Therefore, it is crucial to go beyond pure network-layer information for traffic attribution.
Aniss Maghsoudlou, Oliver Gasser, Ingmar Poese, Anja Feldmann
CoNEXT2
2022 Illuminating large-scale IPv6 scanning in the internet
abstract
While scans of the IPv4 space are ubiquitous, today little is known about scanning activity in the IPv6 Internet. In this work, we present a longitudinal and detailed empirical study on large-scale IPv6 scanning behavior in the Internet, based on firewall logs captured at some 230,000 hosts of a major Content Distribution Network (CDN). We develop methods to identify IPv6 scans, assess current and past levels of IPv6 scanning activity, and study dominant characteristics of scans, including scanner origins, targeted services, and insights on how scanners find target IPv6 addresses. Where possible, we compare our findings to what can be assessed from publicly available traces. Our work identifies and highlights new challenges to detect scanning activity in the IPv6 Internet, and uncovers that today's scans of the IPv6 space show widely different characteristics when compared to the more well-known IPv4 scans.
Philipp Richter, Oliver Gasser, Arthur W. Berger
IMC2
2022 Deep dive into the IoT backend ecosystem
abstract
Internet of Things (IoT) devices are becoming increasingly ubiquitous, e.g., at home, in enterprise environments, and in production lines. To support the advanced functionalities of IoT devices, IoT vendors as well as service and cloud companies operate IoT backends---the focus of this paper. We propose a methodology to identify and locate them by (a) compiling a list of domains used exclusively by major IoT backend providers and (b) then identifying their server IP addresses. We rely on multiple sources, including IoT backend provider documentation, passive DNS data, and active scanning. For analyzing IoT traffic patterns, we rely on passive network flows from a major European ISP.
Said Jawad Saidi, Srdjan Matic, Georgios Smaragdakis, Oliver Gasser, Anja Feldmann
IMC4
2022 Rusty clusters?: dusting an IPv6 research foundation
abstract
The long-running IPv6 Hitlist service is an important foundation for IPv6 measurement studies. It helps to overcome infeasible, complete address space scans by collecting valuable, unbiased IPv6 address candidates and regularly testing their responsiveness. However, the Internet itself is a quickly changing ecosystem that can affect long-running services, potentially inducing biases and obscurities into ongoing data collection means. Frequent analyses but also updates are necessary to enable a valuable service to the community.
Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle
IMC4
2021 Third time's not a charm: exploiting SNMPv3 for router fingerprinting
abstract
In this paper, we show that adoption of the SNMPv3 network management protocol standard offers a unique---but likely unintended---opportunity for remotely fingerprinting network infrastructure in the wild. Specifically, by sending unsolicited and unauthenticated SNMPv3 requests, we obtain detailed information about the configuration and status of network devices including vendor, uptime, and the number of restarts. More importantly, the reply contains a persistent and strong identifier that allows for lightweight Internet-scale alias resolution and dual-stack association. By launching active Internet-wide SNMPv3 scan campaigns, we show that our technique can fingerprint more than 4.6 million devices of which around 350k are network routers. Not only is our technique lightweight and accurate, it is complementary to existing alias resolution, dual-stack inference, and device fingerprinting approaches. Our analysis not only provides fresh insights into the router deployment strategies of network operators worldwide, but also highlights potential vulnerabilities of SNMPv3 as currently deployed.
Taha Albakour, Oliver Gasser, Robert Beverly, Georgios Smaragdakis
Internet Measurement Conference2
2021 From Single Lane to Highways: Analyzing the Adoption of Multipath TCP in the Internet
abstract
Multipath TCP (MPTCP) extends traditional TCP to enable simultaneous use of multiple connection endpoints at the source and destination. MPTCP has been under active development since its standardization in 2013, and more recently in February 2020, MPTCP was upstreamed to the Linux kernel. In this paper, we provide the first broad analysis of MPTCPv0 in the Internet. We probe the entire IPv4 address space and an IPv6 hitlist to detect MPTCP-enabled systems operational on port 80 and 443. Our scans reveal a steady increase in MPTCP-capable IPs, reaching 9k+ on IPv4 and a few dozen on IPv6. We also discover a significant share of seemingly MPTCP-capable hosts, an artifact of middleboxes mirroring TCP options. We conduct targeted HTTP(S) measurements towards select hosts and find that middleboxes can aggressively impact the perceived quality of applications utilizing MPTCP. Finally, we analyze two complementary traffic traces from CAIDA and MAWI to shed light on the real-world usage of MPTCP. We find that while MPTCP usage has increased by a factor of 20 over the past few years, its traffic share is still quite low.
Florian Aschenbrenner, Tanya Shreedhar, Oliver Gasser, Nitinder Mohan, Jörg Ott
Networking3
2021 Zeroing in on Port 0 Traffic in the Wild
Aniss Maghsoudlou, Oliver Gasser, Anja Feldmann
PAM2
2020 The Lockdown Effect: Implications of the COVID-19 Pandemic on Internet Traffic
abstract
Due to the COVID-19 pandemic, many governments imposed lock-downs that forced hundreds of millions of citizens to stay at home. The implementation of confinement measures increased Internet traffic demands of residential users, in particular, for remote working, entertainment, commerce, and education, which, as a result, caused traffic shifts in the Internet core.
Anja Feldmann, Oliver Gasser, Franziska Lichtblau, Enric Pujol-Gil, Ingmar Poese, Christoph Dietzel, Matthias Wichtlhuber, Juan Tapiador, Narseo Vallina-Rodriguez, Oliver Hohlfeld, Georgios Smaragdakis
Internet Measurement Conference2
2019 DNS Observatory: The Big Picture of the DNS
abstract
The Domain Name System (DNS) is thought of as having the simple-sounding task of resolving domains into IP addresses. With its stub resolvers, different layers of recursive resolvers, authoritative nameservers, a multitude of query types, and DNSSEC, the DNS ecosystem is actually quite complex.
Pawel Foremski, Oliver Gasser, Giovane Cesar Moreira Moura
Internet Measurement Conference2
2019 Prefix Top Lists: Gaining Insights with Prefixes from Domain-based Top Lists on DNS Deployment
abstract
Domain-based top lists such as the Alexa Top 1M strive to portray the popularity of web domains. Even though their shortcomings (e.g., instability, no aggregation, lack of weights) have been pointed out, domain-based top lists still are an important element of Internet measurement studies.
Johannes Naab, Patrick Sattler, Jonas Jelten, Oliver Gasser, Georg Carle
Internet Measurement Conference4
2018 Clusters in the Expanse: Understanding and Unbiasing IPv6 Hitlists
Oliver Gasser, Quirin Scheitle, Pawel Foremski, Qasim Lone, Maciej Korczynski, Stephen D. Strowes, Luuk Hendriks, Georg Carle
Internet Measurement Conference1
2018 The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem
Quirin Scheitle, Oliver Gasser, Theodor Nolte, Johanna Amann, Lexi Brent, Georg Carle, Ralph Holz, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference2
2018 In Log We Trust: Revealing Poor Security Practices with Certificate Transparency Logs and Internet Measurements
Oliver Gasser, Benjamin Hof, Max Helm, Maciej Korczynski, Ralph Holz, Georg Carle
PAM1
2017 Opportunities and Challenges of Ad-based Measurements from the Edge of the Network
abstract
For many years, the research community, practitioners, and regulators have used myriad methods and tools to understand the complex structure and behavior of ISPs from the edge of the network. Unfortunately, the nature of these techniques forces the researcher to find a balance between ISP-coverage, user scale, and accuracy. In this paper we present AdTag, a network measurement paradigm that leverages the opportunistic nature of online targeted advertising to measure the Internet from the edge of the network. We discuss and formalize AdTag's design space---including technical, ethical, deployability and economic factors---and its potential to analyze a wide spectrum of Internet connectivity aspects from the browser. We run several experiments to demonstrate that AdTag can be tailored towards geographic and device-based user groups, finding also several challenges to be faced in order to maximize the number of samples. In a 7-day campaign, AdTag could access more than 20K ISPs at a global scale (185 countries) using millions of edge nodes.
Patricia Callejo, Conor Kelton, Narseo Vallina-Rodriguez, Rubén Cuevas Rumín, Oliver Gasser, Christian Kreibich, Florian Wohlfart, Ángel Cuevas
HotNets5
2017 Mission accomplished?: HTTPS security after diginotar
abstract
Driven by CA compromises and the risk of man-in-the-middle attacks, new security features have been added to TLS, HTTPS, and the web PKI over the past five years. These include Certificate Transparency (CT), for making the CA system auditable; HSTS and HPKP headers, to harden the HTTPS posture of a domain; the DNS-based extensions CAA and TLSA, for control over certificate issuance and pinning; and SCSV, for protocol downgrade protection.
Johanna Amann, Oliver Gasser, Quirin Scheitle, Lexi Brent, Georg Carle, Ralph Holz
Internet Measurement Conference2
2014 A deeper understanding of SSH: Results from Internet-wide scans
abstract
Until recently, relatively little was known about the characteristics of the SSH protocol on the Internet, until two larger studies analysed the cryptographic properties of SSH host keys and identified weaknesses in a number of SSH devices. However, there is no succinct comprehensive image yet how the SSH landscape looks like from the point of view of deployment practices, especially with respect to key management. In this paper, we present the results of Internet-wide SSH scans that we carried out over a period of 7 months, which resulted in the largest data set to date. We enriched our data set with large-scale mappings obtained from DNS scans, AS and WHOIS lookups, and a geo-IP database. We analysed the distribution of server and protocol versions, and found that while SSH 2 has displaced SSH 1, the rate of software updates seems to be slow. We analysed the mentioned cryptographic weaknesses and found they have become fewer, but continue to persist one year after the disclosure. Finally, we investigated the reasons for duplicate yet cryptographically strong keys. We found these are used in very different setups at varying degrees of security. Some are indeed dangerous weaknesses, others are the result of a careful and centralised setup. By example of the ten most common keys, we show the circumstances in which they occur and assess the security of each deployment. Finally, we analysed the deployment of ciphers and associated key lengths and found good results in terms of security. As our scans are of a sensitive nature, we also document the ethical considerations that guided us.
Oliver Gasser, Ralph Holz, Georg Carle
NOMS1