Md. Ishtiaq Ashiq

dblp:260/9262 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0001-8282-6225ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Unraveling the Complexities of MTA-STS Deployment and Management in Securing Email
abstract
Email has been a cornerstone of online communication for decades, but its lack of built-in confidentiality has left it vulnerable to various attacks. To address this issue, two key protocols are being used: MTA-STS (Mail Transfer Agent Strict Transport Security) and DANE (DNS-based Authentication of Named Entities). While DANE was introduced first, MTA-STS has been actively adopted by major email providers like Google and Microsoft, as it does not require the complex DNSSEC chain that poses a significant challenge in deploying and managing DANE. However, despite its significance, there has been limited research on how MTA-STS is deployed and managed in practice. In this study, we present a thorough, longitudinal investigation of the MTA-STS ecosystem. We base our analysis on a dataset capturing over 87 million domains from DNS scans collected across four TLDs over 31 months, along with 10 months of additional component scanning such as TLS certificates, thereby offering a broad perspective on MTA-STS adoption and its management. Our analysis uncovers a concerning trend of misconfigurations and inconsistencies in MTA-STS setups. In our most recent snapshot, out of ~68K domains with MTA-STS record, 29.6% of domains were incorrectly configured, while 3.2% of these should encounter email delivery failure from MTA-STS supporting senders. To gain insights into the challenges faced by email administrators, we surveyed 117 operators. While awareness of MTA-STS was high (94.7%), many cited operational complexity (48.8%) and a preference for DANE (45.4%) as reasons for not deploying the protocol. Our study not only highlights the growing importance of MTA-STS but also reveals the significant challenges in its deployment and management.
Md. Ishtiaq Ashiq, Tobias Fiebig, Taejoong Chung
IMC1
2025 Decoding DNSSEC Errors at Scale: An Automated DNSSEC Error Resolution Framework using Insights from DNSViz Logs
abstract
Low adoption and high misconfiguration rates continue to blunt the security benefits of DNSSEC. Drawing on 1.1M historical diagnostic snapshots covering 319K second-level and their subdomains between 2020 and 2024 from the DNSViz service, this paper delivers the first longitudinal, data-driven taxonomy of real-world DNSSEC failures. The study shows that NSEC3 misconfigurations, delegation failures and missing/expired signatures account for more than 70% of all bogus states, and that 18% of such domains remain broken.
Md. Ishtiaq Ashiq, Olivier Hureau, Casey T. Deccio, Taejoong Chung
IMC1
2024 SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical Recommendations
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung
USENIX Security Symposium1
2023 RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
abstract
The Resource Public Key Infrastructure (RPKI) is a system to add security to the Internet routing. In recent years, the publication of Route Origin Authorization (ROA) objects, which bind IP prefixes to their legitimate origin ASN, has been rapidly increasing. However, ROAs are effective only if the routers use them to verify and filter invalid BGP announcements, a process called Route Origin Validation (ROV).
Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, Taejoong Chung
IMC3
2023 TTL Violation of DNS Resolvers in the Wild
Protick Bhowmick, Md. Ishtiaq Ashiq, Casey T. Deccio, Taejoong Chung
PAM2
2023 You've Got Report: Measurement and Security Implications of DMARC Reporting
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung
USENIX Security Symposium1
2022 Under the Hood of DANE Mismanagement in SMTP
Hyeonmin Lee, Md. Ishtiaq Ashiq, Roland van Rijswijk-Deij, Ted Taekyoung Kwon, Taejoong Chung
USENIX Security Symposium2
2021 Measurement and Analysis of Automated Certificate Reissuance
Olamide Omolola, Md. Ishtiaq Ashiq, Taejoong Chung, Dave Levin, Alan Mislove
PAM3