Roya Ensafi

dblp:24/973 · DBLP profile ↗
← Back
43ranked-venue papers
5as first author
22since 2021 · last 2026
0000-0003-2188-8267ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 32 · 3 first-author · 19 since 2021Computer networks · 8 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorArtificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Characterizing the Implementation of Censorship Policies in Chinese LLM Services
Anna Ablove, Shreyas Chandrashekaran, Xiao Qiang, Roya Ensafi
NDSS4
2026 MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs
Wayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley, Piyush Kumar Sharma, Afsah Anwar, Roya Ensafi
NDSS7
2026 CenRL: A Framework for Performing Intelligent Censorship Measurements
Armin Huremagic, Roya Ensafi, Ram Sundara Raman
SP4
2026 CenAlert: Amplifying User Voices to Rally Censorship Investigation
Aaron Ortwein, Anna Ablove, Armin Huremagic, Luqin Chang, Vinicius Fortuna, Roya Ensafi
SP6
2025 Fingerprinting Deep Packet Inspection Devices by their Ambiguities
abstract
Users around the world face escalating network interference such as censorship, throttling, and interception, largely driven by the commoditization and growing availability of Deep Packet Inspection (DPI) devices. Once reserved for a few well-resourced nation-state actors, the ability to interfere with traffic at scale is now within reach of nearly any network operator. Despite this proliferation, our understanding of DPIs and their deployments on the Internet remains limited---being network intermediary leaves DPI unresponsive to conventional host-based scanning tools, and DPI vendors actively obscuring their products further complicates measurement efforts.
Diwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman, Roya Ensafi
CCS5
2025 The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic
Diwen Xue, Robert Stanley, Roya Ensafi
NDSS4
2025 CenPush: Blocking-Resistant Control Channel Using Push Notifications
abstract
The rapid increase in global censorship events has stimulated a substantial growth in users relying on circumvention tools. Fighting against censors requires tool maintainers to frequently update client-side configurations and proxy IPs. However, existing methods for doing so require clients to explicitly query for updates. Further, this client-initiated communication relies mostly on ad-hoc and out-of-band channels. This work demonstrates the utility of push notification services as an efficient and sustainable communication channel between tool maintainers and their clients. A push notification channel allows tool maintainers to update client configurations automatically without the need for clients to initiate a query themselves. We develop a general-purpose design for integrating push notifications as a control channel in circumvention tools. We utilize the design to integrate and implement push notifications for use in the popular circumvention tool Tor and demonstrate their utility to push bridge line updates to Tor clients.
Piyush Kumar Sharma, Diwen Xue, Aaron Ortwein, Cecylia Bocovich, Harry, Roya Ensafi
Proc. Priv. Enhancing Technol.6
2024 Modeling and Detecting Internet Censorship Events
Elisa Tsai, Ram Sundara Raman, Atul Prakash 0001, Roya Ensafi
NDSS4
2024 Digital Discrimination of Users in Sanctioned States: The Case of the Cuba Embargo
Anna Ablove, Shreyas Chandrashekaran, Ram Sundara Raman, Reethika Ramesh, Harry Oppenheimer, Roya Ensafi
USENIX Security Symposium7
2024 CalcuLatency: Leveraging Cross-Layer Network Latency Measurements to Detect Proxy-Enabled Abuse
Reethika Ramesh, Philipp Winter, Sam Korman, Roya Ensafi
USENIX Security Symposium4
2024 Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS Handshakes
Diwen Xue, Michael G. Kallitsis, Amir Houmansadr, Roya Ensafi
USENIX Security Symposium4
2024 Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention Landscape
Diwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu, Roya Ensafi
USENIX Security Symposium5
2024 Attacking Connection Tracking Frameworks as used by Virtual Private Networks
abstract
VPNs (Virtual Private Networks) have become an essential privacy-enhancing technology, particularly for at-risk users like dissidents, journalists, NGOs, and others vulnerable to targeted threats. While previous research investigating VPN security has focused on cryptographic strength or traffic leakages, there remains a gap in understanding how lower-level primitives fundamental to VPN operations, like connection tracking, might undermine the security and privacy that VPNs are intended to provide. In this paper, we examine the connection tracking frameworks used in common operating systems, identifying a novel exploit primitive that we refer to as the port shadow. We use the port shadow to build four attacks against VPNs that allow an attacker to intercept and redirect encrypted traffic, de-anonymize a VPN peer, or even portscan a VPN peer behind the VPN server. We build a formal model of modern connection tracking frameworks and identify that the root cause of the port shadow lies in five shared, limited resources. Through bounded model checking, we propose and verify six mitigations in terms of enforcing process isolation. We hope our work leads to more attention on the security aspects of lower-level systems and the implications of integrating them into security-critical applications.
Benjamin Mixon-Baca, Jeffrey Knockel, Diwen Xue, Tarun Ayyagari, Deepak Kapur, Roya Ensafi, Jedidiah R. Crandall
Proc. Priv. Enhancing Technol.6
2023 Network Responses to Russia's Invasion of Ukraine in 2022: A Cautionary Tale for Internet Freedom
Reethika Ramesh, Ram Sundara Raman, Apurva Virkud, Alexandra Dirksen, Armin Huremagic, David Fifield, Dirk Rodenburg, Rod Hynes, Douglas Madory, Roya Ensafi
USENIX Security Symposium10
2023 "All of them claim to be the best": Multi-perspective study of VPN users and VPN providers
Reethika Ramesh, Anjali Vyas, Roya Ensafi
USENIX Security Symposium3
2023 CERTainty: Detecting DNS Manipulation at Scale using TLS Certificates
abstract
DNS manipulation is an increasingly common technique used by censors and other network adversaries to prevent users from accessing restricted Internet resources and hijack their connections. Prior work in detecting DNS manipulation relies largely on comparing DNS resolutions with trusted control results to identify inconsistencies. However, the emergence of CDNs and other cloud providers practicing content localization and load balancing leads to these heuristics being inaccurate, paving the need for more verifiable signals of DNS manipulation. In this paper, we develop a new technique, CERTainty, that utilizes the widely established TLS certificate ecosystem to accurately detect DNS manipulation, and obtain more information about the adversaries performing such manipulation. We find that untrusted certificates, mismatching hostnames, and blockpages are powerful proxies for detecting DNS manipulation. Our results show that previous work using consistency-based heuristics is inaccurate, allowing for 72.45% false positives in the cases detected as DNS manipulation. Further, we identify 17 commercial DNS filtering products in 52 countries, including products such as SafeDNS, SkyDNS, and Fortinet, and identify the presence of 55 ASes in 26 countries that perform ISP-level DNS manipulation. We also identify 226 new blockpage clusters that are not covered by previous research. We are integrating techniques used by CERTainty into active measurement platforms to continuously and accurately monitor DNS manipulation.
Elisa Tsai, Deepak Kumar 0006, Ram Sundara Raman, Gavin Li, Yael Eiger, Roya Ensafi
Proc. Priv. Enhancing Technol.6
2022 Network measurement methods for locating and examining censorship devices
abstract
Advances in networking and firewall technology have led to the emergence of network censorship devices that can perform large-scale, highly-performant content blocking. While such devices have proliferated, techniques to locate, identify, and understand them are still limited, require cumbersome manual effort, and are developed on a case-by-case basis.
Ram Sundara Raman, Mona Wang, Jakub Dalek, Jonathan R. Mayer, Roya Ensafi
CoNEXT5
2022 TSPU: Russia's decentralized censorship system
abstract
Russia's Sovereign RuNet was designed to build a Russian national firewall. Previous anecdotes and isolated events in the past two years reflected centrally coordinated censorship behaviors across multiple ISPs, suggesting the deployment of "special equipment" in networks, colloquially known as "TSPU". Despite the TSPU comprising a critical part of the technical stack of RuNet, very little is known about its design, its capabilities, or the extent of its deployment.
Diwen Xue, Benjamin Mixon-Baca, ValdikSS, Anna Ablove, Beau Kujath, Jedidiah R. Crandall, Roya Ensafi
IMC7
2022 VPNInspector: Systematic Investigation of the VPN Ecosystem
Reethika Ramesh, Leonid Evdokimov, Diwen Xue, Roya Ensafi
NDSS4
2022 A Large-scale Investigation into Geodifferences in Mobile Apps
Renuka Kumar, Apurva Virkud, Ram Sundara Raman, Atul Prakash 0001, Roya Ensafi
USENIX Security Symposium5
2022 OpenVPN is Open to VPN Fingerprinting
Diwen Xue, Reethika Ramesh, Arham Jain, Michael G. Kallitsis, J. Alex Halderman, Jedidiah R. Crandall, Roya Ensafi
USENIX Security Symposium7
2021 Throttling Twitter: an emerging censorship technique in Russia
abstract
In March 2021, the Russian government started to throttle Twitter on a national level, marking the first ever use of large-scale, targeted throttling for censorship purposes. The slowdown was intended to pressure Twitter to comply with content removal requests from the Russian government.
Diwen Xue, Reethika Ramesh, Valdik S. S, Leonid Evdokimov, Andrey Viktorov, Arham Jain, Eric Wustrow, Simone Basso, Roya Ensafi
Internet Measurement Conference9
2020 Censored Planet: An Internet-wide, Longitudinal Censorship Observatory
abstract
Remote censorship measurement techniques offer capabilities for monitoring Internet reachability around the world. However, operating these techniques continuously is labor-intensive and requires specialized knowledge and synchronization, leading to limited adoption. In this paper, we introduce Censored Planet, an online censorship measurement platform that collects and analyzes measurements from ongoing deployments of four remote measurement techniques (Augur, Satellite/Iris, Quack, and Hyperquack). Censored Planet adopts a modular design that supports synchronized baseline measurements on six Internet protocols as well as customized measurements that target specific countries and websites. Censored Planet has already collected and published more than 21.8 billion data points of longitudinal network observations over 20 months of operation. Censored Planet complements existing censorship measurement platforms such as OONI and ICLab by offering increased scale, coverage, and continuity. We introduce a new representative censorship metric and show how time series analysis can be applied to Censored Planet's longitudinal measurements to detect 15 prominent censorship events, two-thirds of which have not been reported previously. Using trend analysis, we find increasing censorship activity in more than 100 countries, and we identify 11 categories of websites facing increasing censorship, including provocative attire, human rights issues, and news media. We hope that the continued publication of Censored Planet data helps counter the proliferation of growing restrictions to online freedom.
Ram Sundara Raman, Prerana Shenoy, Katharina Kohls, Roya Ensafi
CCS4
2020 Investigating Large Scale HTTPS Interception in Kazakhstan
abstract
Increased adoption of HTTPS has created a largely encrypted web, but these security gains are on a collision course with governments that desire visibility into and control over user communications. Last year, the government of Kazakhstan conducted an unprecedented large-scale HTTPS interception attack by forcing users to trust a custom root certificate. We were able to detect the interception and monitor its scale and evolution using measurements from in-country vantage points and remote measurement techniques. We find that the attack targeted connections to 37 unique domains, with a focus on social media and communication services, suggesting a surveillance motive, and that it affected a large fraction of connections passing through the country's largest ISP, Kazakhtelecom. Our continuous real-time measurements indicated that the interception system was shut down after being intermittently active for 21 days. Subsequently, supported by our findings, two major browsers (Mozilla Firefox and Google Chrome) completely blocked the use of Kazakhstan's custom root. However, the incident sets a dangerous precedent, not only for Kazakhstan but for other countries that may seek to circumvent encryption online.
Ram Sundara Raman, Leonid Evdokimov, Eric Wustrow, J. Alex Halderman, Roya Ensafi
Internet Measurement Conference5
2020 Measuring the Deployment of Network Censorship Filters at Global Scale
Ram Sundara Raman, Adrian Stoll, Jakub Dalek, Reethika Ramesh, Will Scott, Roya Ensafi
NDSS6
2020 Decentralized Control: A Case Study of Russia
Reethika Ramesh, Ram Sundara Raman, Matthew Bernhard, Victor Ongkowijaya, Leonid Evdokimov, Anne Edmundson, Steven Sprecher, Muhammad Ikram 0001, Roya Ensafi
NDSS9
2020 Measuring and Analysing the Chain of Implicit Trust: A Study of Third-party Resources Loading
abstract
The web is a tangled mass of interconnected services, whereby websites import a range of external resources from various third-party domains. The latter can also load further resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This article performs a large-scale study of dependency chains in the web to find that around 50% of first-party websites render content that they do not directly load. Although the majority (84.91%) of websites have short dependency chains (below three levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third parties are classified as suspicious—although seemingly small, this limited set of suspicious third parties have remarkable reach into the wider ecosystem. We find that 73% of websites under-study load resources from suspicious third parties, and 24.8% of first-party webpages contain at least three third parties classified as suspicious in their dependency chain. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript codes downloading malware.
Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi
ACM Trans. Priv. Secur.6
2019 The Chain of Implicit Trust: An Analysis of the Web Third-party Resources Loading
abstract
The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.
Muhammad Ikram 0001, Rahat Masood, Gareth Tyson, Mohamed Ali Kâafar, Noha Loizon, Roya Ensafi
WWW6
2018 Nation-State Hegemony in Internet Routing
abstract
While the growth of the Internet has fostered more efficient communications around the world, there is a large digital divide between Western countries and the rest of the world. Countries such as Brazil, China, and Saudi Arabia have questioned and criticized America's Internet hegemony. This paper studies the extent to which various countries rely on the United States and other Western countries to connect to popular Internet destinations in those countries. Unfortunately, our measurements reveal that underserved regions are dependent on North American and Western European regions for two reasons: local content is often hosted in foreign countries (such as the United States and the Netherlands), and networks within a country often fail to peer with one another. Fortunately, we also find that routing traffic through strategically placed relay nodes can in some cases reduce the number of transnational routing detours by more than a factor of two, which subsequently reduces the dependence of underserved regions on other regions. Based on these findings, we design and implement Region-Aware Networking, RAN, a lightweight system that routes a client's web traffic around specified countries with no modifications to client software (and in many cases with little performance overhead).
Anne Edmundson, Roya Ensafi, Nick Feamster, Jennifer Rexford
COMPASS2
2018 403 Forbidden: A Global View of CDN Geoblocking
Allison McDonald, Matthew Bernhard, Luke Valenta, Benjamin VanderSloot, Will Scott, Nick Sullivan, J. Alex Halderman, Roya Ensafi
Internet Measurement Conference8
2018 Quack: Scalable Remote Measurement of Application-Layer Censorship
Benjamin VanderSloot, Allison McDonald, Will Scott, J. Alex Halderman, Roya Ensafi
USENIX Security Symposium5
2017 A look at router geolocation in public and commercial databases
abstract
Internet measurement research frequently needs to map infrastructure components, such as routers, to their physical locations. Although public and commercial geolocation services are often used for this purpose, their accuracy when applied to network infrastructure has not been sufficiently assessed. Prior work focused on evaluating the overall accuracy of geolocation databases, which is dominated by their performance on end-user IP addresses. In this work, we evaluate the reliability of router geolocation in databases. We use a dataset of about 1.64M router interface IP addresses extracted from the CAIDA Ark dataset to examine the country- and city-level coverage and consistency of popular public and commercial geolocation databases. We also create and provide a ground-truth dataset of 16,586 router interface IP addresses and their city-level locations, and use it to evaluate the databases' accuracy with a regional breakdown analysis. Our results show that the databases are not reliable for geolocating routers and that there is room to improve their country- and city-level accuracy. Based on our results, we present a set of recommendations to researchers concerning the use of geolocation databases to geolocate routers.
Manaf Gharaibeh, Anant Shah, Bradley Huffaker, Han Zhang 0050, Roya Ensafi, Christos Papadopoulos
Internet Measurement Conference5
2017 Augur: Internet-Wide Detection of Connectivity Disruptions
abstract
Anecdotes, news reports, and policy briefings collectively suggest that Internet censorship practices are pervasive. The scale and diversity of Internet censorship practices makes it difficult to precisely monitor where, when, and how censorship occurs, as well as what is censored. The potential risks in performing the measurements make this problem even more challenging. As a result, many accounts of censorship begin-and end-with anecdotes or short-term studies from only a handful of vantage points. We seek to instead continuously monitor information about Internet reachability, to capture the onset or termination of censorship across regions and ISPs. To achieve this goal, we introduce Augur, a method and accompanying system that utilizes TCP/IP side channels to measure reachability between two Internet locations without directly controlling a measurement vantage point at either location. Using these side channels, coupled with techniques to ensure safety by not implicating individual users, we develop scalable, statistically robust methods to infer network-layer filtering, and implement a corresponding system capable of performing continuous monitoring of global censorship. We validate our measurements of Internet-wide disruption in nearly 180 countries over 17 days against sites known to be frequently blocked, we also identify the countries where connectivity disruption is most prevalent.
Paul Pearce, Roya Ensafi, Frank Li 0001, Nick Feamster, Vern Paxson
IEEE Symposium on Security and Privacy2
2017 Global Measurement of DNS Manipulation
Paul Pearce, Ben Jones, Frank Li 0001, Roya Ensafi, Nick Feamster, Nicholas Weaver, Vern Paxson
USENIX Security Symposium4
2016 A Case Study of Traffic Demand Response to Broadband Service-Plan Upgrades
Sarthak Grover, Roya Ensafi, Nick Feamster
PAM2
2016 A First Look into Transnational Routing Detours
abstract
An increasing number of countries are passing laws that facilitate the mass surveillance of their citizens. In response, governments and citizens are increasingly paying attention to the countries that their Internet traffic traverses. In some cases, countries are taking extreme steps, such as building new IXPs and encouraging local interconnection to keep local traffic local. We find that although many of these efforts are extensive, they are often futile, due to the inherent lack of hosting and route diversity for many popular sites. We investigate how the use of overlay network relays and the DNS open resolver infrastructure can prevent traffic from traversing certain jurisdictions.
Anne Edmundson, Roya Ensafi, Nick Feamster, Jennifer Rexford
SIGCOMM2
2016 Identifying and Characterizing Sybils in the Tor Network
Philipp Winter, Roya Ensafi, Karsten Loesing, Nick Feamster
USENIX Security Symposium2
2015 Examining How the Great Firewall Discovers Hidden Circumvention Servers
abstract
Recently, the operators of the national censorship infrastructure of China began to employ "active probing" to detect and block the use of privacy tools. This probing works by passively monitoring the network for suspicious traffic, then actively probing the corresponding servers, and blocking any that are determined to run circumvention servers such as Tor.
Roya Ensafi, David Fifield, Philipp Winter, Nick Feamster, Nicholas Weaver, Vern Paxson
Internet Measurement Conference1
2015 Analyzing the Great Firewall of China Over Space and Time
abstract
Abstract A nation-scale firewall, colloquially referred to as the “Great Firewall of China,” implements many different types of censorship and content filtering to control China’s Internet traffic. Past work has shown that the firewall occasionally fails. In other words, sometimes clients in China are able to reach blacklisted servers outside of China. This phenomenon has not yet been characterized because it is infeasible to find a large and geographically diverse set of clients in China from which to test connectivity. In this paper, we overcome this challenge by using a hybrid idle scan technique that is able to measure connectivity between a remote client and an arbitrary server, neither of which are under the control of the researcher performing measurements. In addition to hybrid idle scans, we present and employ a novel side channel in the Linux kernel’s SYN backlog. We show that both techniques are practical by measuring the reachability of the Tor network which is known to be blocked in China. Our measurements reveal that failures in the firewall occur throughout the entire country without any conspicuous geographical patterns.We give some evidence that routing plays a role, but other factors (such as how the GFW maintains its list of IP/port pairs to block) may also be important.
Roya Ensafi, Philipp Winter, Abdullah Mueen, Jedidiah R. Crandall
Proc. Priv. Enhancing Technol.1
2014 Detecting Intentional Packet Drops on the Internet via TCP/IP Side Channels
Roya Ensafi, Jeffrey Knockel, Geoffrey Alexander, Jedidiah R. Crandall
PAM1
2010 Idle Port Scanning and Non-interference Analysis of Network Protocol Stacks Using Model Checking
Roya Ensafi, Jong Chun Park, Deepak Kapur, Jedidiah R. Crandall
USENIX Security Symposium1
2008 Optimizing Fuzzy K-means for network anomaly detection using PSO
abstract
Intrusion detection has become an indispensable defense line in the information security infrastructure. The existing signature-based intrusion detection mechanisms are often not sufficient in detecting many types of attacks. K-means is a popular anomaly intrusion detection method to classify unlabeled data into different categories. However, it suffers from the local convergence and high false alarms. In this paper, two soft computing techniques, fuzzy logic and swarm intelligence, are used to solve these problems. We proposed SFK-means approach which inherits the advantages of K-means, Fuzzy K-means and Swarm K-means, simultaneously we improve the deficiencies. The most advantages of our SFK-means algorithm are solving the local convergence problem in Fuzzy Kmeans and the sharp boundary problem in Swarm Kmeans. The experimental results on dataset KDDCup99 show that our proposed method can be effective in detecting various attacks.
Roya Ensafi, Soheila Dehghanzadeh, Mohammad R. Akbarzadeh-Totonchi
AICCSA1
2008 The ecology of Malware
abstract
The fight against malicious software (or malware, which includes everything from worms to viruses to botnets) is often viewed as an "arms race." Conventional wisdom is that we must continually "raise the bar" for the malware creators. However, the multitude of malware has itself evolved into a complex environment, and properties not unlike those of ecological systems have begun to emerge. This may include competition between malware, facilitation, parasitism, predation, and density-dependent population regulation. Ecological principles will likely be useful for understanding the effects of these ecological interactions, for example, carrying capacity, species-time and species-area relationships, the unified neutral theory of biodiversity, and the theory of island bio-geography. The emerging malware ecology can be viewed as a critical challenge to all aspects of malware defense, including collection, triage, analysis, intelligence estimates, detection, mitigation, and forensics. It can also be viewed as an opportunity.
Jedidiah R. Crandall, Roya Ensafi, Stephanie Forrest, Joshua Ladau, Bilal Shebaro
NSPW2