EDBT 2026 Demo / reviewers in the wild / expert
Johannes Zirngibl
dblp:175/1273
· DBLP profile ↗
12ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0002-2918-016XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 2 first-author · 8 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Still on Target? An Evaluation of IPv6 Target Generation Algorithms
Lion Steger, Liming Kuang, Johannes Zirngibl, Georg Carle, Oliver Gasser |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Measuring the deployment of DNSSEC Bootstrapping Using Authenticated SignalsabstractThe DNS, the Internet's address book, traditionally does not guarantee authenticity of data. The DNS Security Extensions (DNSSEC) exist to add cryptographic authenticity checks to the DNS. In spite of DNSSEC being over 30 years old, its widespread deployment has not yet come to fruition. Current work in the IETF tries automating the setup of DNSSEC, in the hopes of furthering its deployment. Q. Misell, Florian Steurer, Johannes Zirngibl, Anja Feldmann, Tobias Fiebig |
IMC | 3 |
| 2025 | Lazy Eye Inspection: Capturing the State of Happy Eyeballs ImplementationsabstractWhile transitioning to an IPv6-only communication, many devices settled on a dual-stack setup. IPv4 and IPv6 are available to these hosts for new connections. Happy Eyeballs (HE) describes a mechanism to prefer IPv6 for such hosts while ensuring a fast fallback to IPv4 when IPv6 fails. The IETF is currently working on the third version of HE. While the standards include recommendations for HE parameter choices, it is up to the client and OS to implement HE. In this paper, we investigate the state of HE in various clients, particularly web browsers and recursive resolvers. We introduce a framework to analyze and measure clients' HE implementations and parameter choices. According to our evaluation, only Safari supports all HE features. Safari is also the only client implementation in our study that uses a dynamic IPv4 connection attempt delay, a resolution delay, and interlaces addresses. We further show that problems with the DNS A record lookup can even delay and interrupt the network connectivity despite a fully functional IPv6 setup with Chrome and Firefox. We operate a publicly available website ( www.happy-eyeballs.net ) which measures the browser's HE behavior, and we publish our testbed measurement framework. Patrick Sattler, Matthias Kirstein, Lars Wüstrich, Johannes Zirngibl, Georg Carle |
IMC | 4 |
| 2025 | Measuring Increasing Heterogeneity in BGPabstractAutonomous Systems (ASes) on the Internet use the Border Gateway Protocol (BGP) to distribute routing information. The BGP-a policy-based protocol-defines a best path decision process that chooses one path per prefix. Some researchers assume ASes use the same path for the same prefix, i.e., that ASes are homogeneous networks. However, this is not the case. Previous work has shown the existence of heterogeneous ASes, i.e., ASes that use different best paths for the same prefix. Nevertheless, this work is outdated due to the Internet's fast pace of evolution. Our work thus aims to quantize the number of heterogeneous ASes by improving upon previous limitations. We introduce a novel method to find heterogeneous ASes that works by finding detours in AS paths from different vantage points. Our analysis covers samples from the last 10 years to show the historical growth and ongoing adoption of heterogeneity on the Internet. We found that the number of heterogeneous ASes steadily increased over the last decade. For example, there has been an increase of up to 173% since 2014. Further, especially Content Delivery Networks have become more heterogeneous (an increase of 360%), followed by Internet Service Providers (196%), and Network Service Providers (173%). Lastly, we found that smaller ASes with fewer customers are becoming more prone to being heterogeneous. Pascal Hennen, Tiago Heinrich, Johannes Zirngibl |
NOMS | 3 |
| 2024 | QUIC Hunter: Finding QUIC Deployments and Identifying Server Libraries Across the Internet
Johannes Zirngibl, Florian Gebauer, Patrick Sattler, Markus Sosnowski, Georg Carle |
PAM (2) | 1 |
| 2024 | QUIC on the Fast Lane: Extending Performance Evaluations on High-rate LinksabstractQUIC is a new protocol standardized in 2021 designed to improve on the widely used TCP / TLS stack. The main goal is to speed up web traffic via HTTP, but it is also used in other areas like tunneling. Based on UDP, it offers features like reliable in-order delivery, flow and congestion control, stream-based multiplexing, and always-on encryption using TLS 1.3. Unlike TCP, QUIC integrates these capabilities in user space, relying on kernel interaction solely for UDP. Operating in user space allows more flexibility but sacrifices some kernel-level efficiency and optimization that TCP benefits from. Various QUIC implementations exist, each distinct in programming language, architecture, and design. QUIC is already widely deployed on the Internet and has been evaluated, focussing on low latency, interoperability, and standard compliance. However, benchmarks on high-speed network links are still scarce. This paper presents an extension to the QUIC Interop Runner, a framework for testing the interoperability of QUIC implementations. Our contribution enables reproducible QUIC benchmarks on dedicated hardware and high-speed links. We provide results on 10G links, including multiple implementations, evaluate how OS features like buffer sizes and NIC offloading impact QUIC performance, and show which data rates can be achieved with QUIC compared to TCP. Moreover, we analyze different CPUs and CPU architectures influence reproducible and comparable performance measurements. Furthermore, our framework can be applied to evaluate the effects of future improvements to the protocol or the OS. Our results show that QUIC performance varies widely between client and server implementations from around 50 Mbit/s to over 6000 Mbit/s. We show that the OS generally sets the default buffer size too small. Based on our findings, the buffer size should be increased by at least an order of magnitude. Our profiling analysis identifies Packet I/O as the most expensive task for QUIC implementations. Furthermore, QUIC benefits less from AES NI hardware acceleration while both features improve the goodput of TCP to around 8000 Mbit/s. The lack of support for NIC offloading from QUIC implementations results in missed opportunities for performance improvement. The assessment of CPUs from different vendors and generations revealed significant performance variations. We employed core pinning to examine if the performance of QUIC implementations is affected by the allocation to specific CPU cores. The results indicated an increased goodput of up to 20% when running on a specifically chosen core compared to a randomly assigned core. This outcome highlights the impact of CPU core selection on the performance of QUIC implementations but also for reproducible measurements. Marcel Kempf, Benedikt Jaeger, Johannes Zirngibl, Kevin Ploch, Georg Carle |
Comput. Commun. | 3 |
| 2024 | EFACTLS: Effective Active TLS Fingerprinting for Large-Scale Server Deployment CharacterizationabstractActive measurements allow the collection of server characteristics on a large scale that can aid in discovering hidden relations and commonalities among server deployments. Finding these relations opens up new possibilities for clustering and classifying server deployments; for example, identifying a previously unknown cybercriminal infrastructure can be valuable cyber-threat intelligence. In this work, we propose a methodology based on active measurements to acquire Transport Layer Security (TLS) metadata from servers and leverage it for fingerprinting. Our fingerprints capture characteristic behavior of the TLS stack, primarily influenced by the server’s implementation, configuration, and hardware support. Using an empirical optimization strategy that maximizes information gained from every handshake to minimize measurement costs, we generated 10 general-purpose Client Hellos. They served as scanning probes to create an extensive database of TLS configurations to classify servers. We propose the Shannon Entropy to measure collected information and compare different approaches. This study fingerprinted 8 million servers from the Tranco top list and two Command and Control (C2) blocklists over 60 weeks with weekly snapshots. The resulting data formed the foundation for two long-term case studies: classification of Content Delivery Network and C2 servers. Moreover, the detection was fine-grained enough to detect C2 server families. The proposed methodology demonstrated a precision of 99% and enabled a stable identification of new servers over time. This study shows how active measurements can provide valuable security-relevant insights and improve our understanding of the Internet. Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle, Claas Grohnfeldt, Michele Russo, Daniele Sgandurra |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | DissecTLS: A Scalable Active Scanner for TLS Server Configurations, Capabilities, and TLS FingerprintingabstractAbstract Collecting metadata from Transport Layer Security (TLS) servers on a large scale allows to draw conclusions about their capabilities and configuration. This provides not only insights into the Internet but it enables use cases like detecting malicious Command and Control (C &C) servers. However, active scanners can only observe and interpret the behavior of TLS servers, the underlying configuration and implementation causing the behavior remains hidden. Existing approaches struggle between resource intensive scans that can reconstruct this data and light-weight fingerprinting approaches that aim to differentiate servers without making any assumptions about their inner working. With this work we propose DissecTLS, an active TLS scanner that is both light-weight enough to be used for Internet measurements and able to reconstruct the configuration and capabilities of the TLS stack. This was achieved by modeling the parameters of the TLS stack and derive an active scan that dynamically creates scanning probes based on the model and the previous responses from the server. We provide a comparison of five active TLS scanning and fingerprinting approaches in a local testbed and on toplist targets. We conducted a measurement study over nine weeks to fingerprint C &C servers and analyzed popular and deprecated TLS parameter usage. Similar to related work, the fingerprinting achieved a maximum precision of 99 % for a conservative detection threshold of 100 %; and at the same time, we improved the recall by a factor of 2.8. Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle |
PAM | 2 |
| 2022 | Towards a tectonic traffic shift?: investigating Apple's new relay networkabstractApple recently published its first Beta of the iCloud Private Relay, a privacy protection service with promises resembling the ones of VPNs. The architecture consists of two layers (ingress and egress), operated by disjoint providers. The service is directly integrated into Apple's operating systems, providing a low entry-level barrier for a large user base. It seems to be set up for significant adoption with its relatively moderate entry-level price. Patrick Sattler, Juliane Aulbach, Johannes Zirngibl, Georg Carle |
IMC | 3 |
| 2022 | Rusty clusters?: dusting an IPv6 research foundationabstractThe long-running IPv6 Hitlist service is an important foundation for IPv6 measurement studies. It helps to overcome infeasible, complete address space scans by collecting valuable, unbiased IPv6 address candidates and regularly testing their responsiveness. However, the Internet itself is a quickly changing ecosystem that can affect long-running services, potentially inducing biases and obscurities into ongoing data collection means. Frequent analyses but also updates are necessary to enable a valuable service to the community. Johannes Zirngibl, Lion Steger, Patrick Sattler, Oliver Gasser, Georg Carle |
IMC | 1 |
| 2021 | It's over 9000: analyzing early QUIC deployments with the standardization on the horizonabstractAfter nearly five years and 34 draft versions, standardization of the new connection oriented transport protocol QUIC was finalized in May 2021. Designed as a fundamental network protocol with increased complexity due to the combination of functionality from multiple network stack layers, it has the potential to drastically influence the Internet ecosystem. Nevertheless, even in its early stages, the protocol attracted a variety of parties including large providers. Our study shows, that more than 2.3 M IPv4 and 300k IPv6 addresses support QUIC hosting more than 30 M domains. Johannes Zirngibl, Philippe Buschmann, Patrick Sattler, Benedikt Jaeger, Juliane Aulbach, Georg Carle |
Internet Measurement Conference | 1 |
| 2016 | Analyzing Locality of Mobile Messaging Traffic using the MATAdOR Framework
Quirin Scheitle, Matthias Wachs, Johannes Zirngibl, Georg Carle |
PAM | 3 |