EDBT 2026 Demo / reviewers in the wild / expert
Alberto Dainotti
dblp:28/5074
· DBLP profile ↗
60ranked-venue papers
16as first author
24since 2021 · last 2026
0000-0001-6444-5656ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 47 · 14 first-author · 17 since 2021Security and privacy · 12 · 1 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti, Michael D. Bailey, Fabian Monrose |
NDSS | 4 |
| 2026 | MORP4: A Dynamic Network Telescope
Iliana Xygkou, Jithin Kallukalam Sojan, Dhruv Rauthan, Thomas Holterbach, Shane Alcock, Brian Flanagan, Ahmed Saeed 0001, Alberto Dainotti |
NSDI | 9 |
| 2025 | Replication: A Two Decade Review of Policy Atoms - Tracing the Evolution of AS Path Sharing PrefixesabstractAfek et al. characterized the formation and stability of policy atoms, groups of prefixes that share the same Autonomous System (AS) paths as observed by BGP collectors, a concept initially defined by Broido and Claffy in 2001. Policy atoms provide a valuable perspective on the inter-domain routing policies in the Internet. With the rapid growth and increasing complexity of the Internet since these studies, we believe it is important to reassess the implications and applicability of policy atoms. In this paper, we revisit the policy atom concept after two decades and replicate the study performed by Afek et al. to assess the current state of AS path sharing and shed light on the evolution of policy atoms. We demonstrate that the Internet still operates on the level of policy atoms rather than individual ASes, as prefixes within the same atom tend to experience changes in AS path simultaneously. We apply the concept of policy atoms in IPv6 and find that this observation also holds true for IPv6 prefixes. We also relate trends in the characteristics of policy atoms with the development of inter-domain routing policies. We highlight new insights generated by the perspective of policy atoms and their potential for further applications. Our code is publicly available to support reproducibility and to encourage future research on this topic. Weili Wu 0004, Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
IMC | 4 |
| 2025 | Assessing LEO Satellite Networks for National Emergency FailoverabstractIn this paper, we study the viability of LEO networks as a failover network. We contextualize our analysis by framing the capacity of satellite networks relative to lost capacity due to submarine cable failure. Specifically, we focus on scenarios where LEO networks act as failovers for submarine cables, providing a concrete target capacity to be fulfilled by the satellite network. We introduce a new model and simulator that help us estimate the failover capacity. We identify key factors determining the actual capacity available on the satellite network: the total area of the country, the terminal distribution policy used by the government, the spectrum allocation and traffic engineering policies used by the LEO network operator. Based on our findings, we make policy recommendations to governments that can result in an increase of up to 1.8× in the failover capacity without requiring additional infrastructure. However, we find after implementing all our recommendations, with 200k terminals deployed and no competing traffic in the network, a satellite network can only satisfy 0.9-14.7% of the capacity lost due to submarine cable failure in four out of six case studies. Vaibhav Bhosale, Sameer S. Kapoor, Robin Kim, Miguel T. Schlicht, Muskaan Gupta, Ekaterina Tumanova, Zachary S. Bischof, Fabián E. Bustamante, Alberto Dainotti, Ahmed Saeed 0001 |
IMC | 10 |
| 2025 | Prefix2Org: Mapping BGP Prefixes to OrganizationsabstractAccurately mapping Internet address space to organizations is critical to understanding the Internet's organizational ecosystem. Traditional approaches, which rely on individual WHOIS queries often suffer from unclear ownership structure of IP addresses and inconsistent organization names, resulting in ambiguous inferences. Alternative methods that map BGP prefixes to Autonomous Systems Numbers (ASNs) and ASNs to organizations are also inaccurate since ASes often originate prefixes on behalf of their customers. This paper introduces Prefix2Org, a comprehensive prefix-to-organization mapping framework. We introduce a taxonomy for the holders of IP addresses and a methodology to map IP addresses to organizations, based on the operational rights over them. We develop string processing heuristics and leverage RPKI Certificates and routing data to address inconsistencies in organizational names and aggregate prefixes under unified management. Our public dataset covers 99.96% (99.99%) of IPv4 (IPv6) prefixes. We validate 9.3% of routed IPv4 addresses with a 99% recall, and 5.6% of IPv6 prefixes with a 99.34% recall. For the two large organizations where we obtained complete ground truth, Prefix2Org produced no false positives. Finally, in two case studies, (i) we characterize organizations that hold address space without an ASN and (ii) demonstrate how RPKI adoption measured through Prefix2Org differs from the previously used AS-centric view. Deepak Gouda, Alberto Dainotti, Cecilia Testart |
IMC | 2 |
| 2025 | A First Look into Long-lived BGP ZombiesabstractBGP is the de facto protocol used to manage a network's reachability on the Internet. Network operators announce and withdraw their prefixes on BGP to enable or to prevent communication towards their origin network, respectively. However, the withdrawal of a prefix could fail to propagate totally in the Internet and routes towards withdrawn prefixes could remain in the routing tables of routers. These routes are called stuck or zombie BGP routes, and their persistence can lead to performance degradation, or even partial or complete outage. In this paper, we first revisit existing work on BGP zombies using RIPE RIS beacons, identify the double-counting discrepancy, and revise the methodology to address this problem and detect zombies more accurately. Second, we point out limitations of the RIPE RIS beacons with respect to their periodicity, lack of diversity, and noise, and introduce and deploy our own beacons, which address these limitations. Using our beacons and the revised methodology, we analyze the lifespan of BGP zombies. We show that zombie routes can persist in RIBs for days, weeks, or even months. Furthermore, we document that BGP zombies can be announced months after their original withdrawal, affecting new ASes. Finally, we discuss interesting cases of long-lived zombie outbreaks that affected large ISPs with hundreds of ASes in their customer cones. Iliana Xygkou, Antonis Chariton, Xenofontas A. Dimitropoulos, Alberto Dainotti |
IMC | 4 |
| 2025 | Poster: Investigating the Survivability of the Experimental TCP OptionabstractIn this work, we extend Yarrpbox to assess the survivability of the TCP experimental option across paths toward the Tranco Top-100k domains. Our findings highlight middlebox interference and motivate broader Internet-wide studies. This study represents an initial step toward understanding the feasibility of extending TCP in today's Internet, while highlighting potential pitfalls that must be considered by future protocol designers. Zahra Yazdani, Fahad Hilal, Cecilia Testart, Alberto Dainotti, Kevin Vermeulen, Tiago Heinrich, Taha Albakour |
IMC | 4 |
| 2024 | Poster: Enhancing Internet Disruption Investigation via Path MonitoringabstractLarge-scale Internet disruptions, ranging from complete disconnections to service degradations, are increasingly common, due to factors such as government-ordered shutdowns, infrastructure failures, and sophisticated traffic manipulation techniques. While existing detection platforms are effective at identifying complete disconnections, they fail to detect service degradations, such as those caused by throttling, intentional rerouting, or network attacks, which degrade performance without blocking connectivity. In this poster, we discuss our plan to improve Internet disruption investigation through additional metrics (loss, latency) and measurement techniques (traceroutes) to help identify such events and provide researchers with the network-level information necessary for investigation. Our method not only helps to identify service degradations missed by traditional connectivity checks but also provides data for generating insights into the underlying causes and impacts of Internet disruptions. Weili Wu 0004, Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
IMC | 4 |
| 2024 | Poster: Investigating Autonomous Systems Recurrently Causing Unexplained (Sub)MOAS EventsabstractThe Border Gateway Protocol (BGP) is the de facto routing protocol of the Internet. In BGP, networks (Autonomous Systems, ASes) advertise to neighboring ASes the IP address blocks (IP prefixes) they host and the ones hosted by other ASes towards which they have a path. Two ASes can announce themselves as the host (origin) of the same IP prefix (Multiple Origin AS prefix, MOAS). Alternatively, one AS can advertise itself as the host of an IP prefix, and another can advertise itself as the host of a subset of that same prefix (SubMOAS prefix). If MOAS and SubMOAS can be legitimate, they can also result in misdirected Internet traffic (BGP hijacking), whether the cause is intentional or not. Thus, network operators need a mechanism to differentiate between unauthorized and legitimate route announcements. The Global Routing Intelligence Platform (GRIP) is state-of-the-art regarding MOAS and SubMOAS detection. GRIP automatically detects SubMOAS and MOAS, then performs initial filtering to tag obvious benign events and reduce the number of cases to investigate. Between January 1, 2020, and January 1, 2023, GRIP detected 4.5M MOAS and SubMOAS, and classified 4.36M as benign, leaving 134k events without explanation. We call them unexplained events. Likely, there are still many benign cases in those 134K events, and only a few should generate an alert. This work aims to uncover AS behaviors that could cause benign MOAS or SubMOAS events but are not currently considered in BGP hijacking detection systems. Upon examining these GRIP events between January 1, 2020, and January 1, 2023, we find that they are primarily caused by a small number of ASes. Therefore, we manually investigate these ASes repeatedly causing MOAS and SubMOAS, leveraging the data collected by GRIP. For example, this data includes the BGP AS path attribute and RPKI status. In addition, we also use RIPE Stat API (routing history and ASN neighbor history), as well as WHOIS data (mainly aut-num/ASNumber and inet-num/NetRange objects). Olivier Bemba, Cecilia Testart, Alberto Dainotti |
IMC | 3 |
| 2024 | Poster: Investigating Network Security Post-Outage: Open Ports VulnerabilitiesabstractThe Internet has become an important part of our lives today, hence ensuring its security and reliability is critical. Internet outages happen frequently due to various factors, including human inter- ventions, natural disasters, and power outages. A key question is whether hosts become vulnerable when a network recovers from an outage impacting Internet infrastructure. This could happen if firewalls malfunction, even for a short while, allowing some ports to become unexpectedly open. This can potentially lead to expo- sure of previously restricted services to external users, making the network vulnerable to security threats. Previous work has shown that, in general, unnecessary open ports can increase vulnerabil- ities in systems. This study proposes a practical approach to examine network security post-outage by identifying newly open ports that can increase system vulnerability. The goal of this work is to show that such risks can indeed arise after an outage and that the proposed methodology detects these new ports. Zahra Yazdani, Paul Pearce, Alberto Dainotti, Cecilia Testart |
IMC | 3 |
| 2024 | A System to Detect Forged-Origin BGP Hijacks
Thomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti, Cristel Pelsser |
NSDI | 4 |
| 2024 | Towards Improving Outage Detection with Multiple Probing Protocols
Manasvini Sethuraman, Zachary S. Bischof, Alberto Dainotti |
PAM (1) | 3 |
| 2023 | How to Operate a Meta-Telescope in your Spare TimeabstractUnsolicited traffic sent to advertised network space that does not host active services provides insights about misconfigurations as well as potentially malicious activities, including the spread of Botnets, DDoS campaigns, and exploitation of vulnerabilities. Network telescopes have been used for many years to monitor such unsolicited traffic. Unfortunately, they are limi the available address space for such tasks and, thus, limited to specific geographic and/or network regions. Sahil Ashish Ranadive, Harm Griffioen, Michael G. Kallitsis, Alberto Dainotti, Georgios Smaragdakis, Anja Feldmann |
IMC | 5 |
| 2023 | Improving the Inference of Sibling Autonomous Systems
Zachary S. Bischof, Cecilia Testart, Alberto Dainotti |
PAM | 4 |
| 2023 | DDoS Mitigation Dilemma Exposed: A Two-Wave Attack with Collateral Damage of Millions
Lumin Shi, Jun Li 0001, Devkishen Sisodia, Mingwei Zhang 0004, Alberto Dainotti, Peter L. Reiher |
SecureComm (2) | 5 |
| 2023 | Destination Unreachable: Characterizing Internet Outages and ShutdownsabstractIn this paper, we provide the first comprehensive longitudinal analysis of government-ordered Internet shutdowns and spontaneous outages (i.e., disruptions not ordered by the government). We describe the available tools, data sources and methods to identify and analyze Internet shutdowns. We then merge manually curated datasets on known government-ordered shutdowns and large-scale Internet outages, further augmenting them with data on real-world events, macroeconomic and sociopolitical indicators, and network operator statistics. Our analysis confirms previous findings on the economic and political profiles of countries with government-ordered shutdowns. Extending this analysis, we find that countries with national-scale spontaneous outages often have profiles similar to countries with shutdowns, differing from countries that experience neither. However, we find that government-ordered shutdowns are many more times likely to occur on days of mobilization, coinciding with elections, protests, and coups. Our study also characterizes the temporal characteristics of Internet shutdowns and finds that they differ significantly in terms of duration, recurrence interval, and start times when compared to spontaneous outages. Zachary S. Bischof, Kennedy Pitcher, Esteban Carisimo, Amanda Meng, Rafael Bezerra Nunes, Ramakrishna Padmanabhan, Margaret E. Roberts, Alex C. Snoeren, Alberto Dainotti |
SIGCOMM | 9 |
| 2023 | Access Denied: Assessing Physical Risks to Internet Access Networks
Alexander Marder, Zesen Zhang, Ricky K. P. Mok, Ramakrishna Padmanabhan, Bradley Huffaker, Matthew J. Luckie, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Aaron Schulman |
USENIX Security Symposium | 7 |
| 2022 | iGDB: connecting the physical and logical layers of the internetabstractMaps of physical and logical Internet connectivity that are informed by and consistent with each other can expand scope and improve accuracy in analysis of performance, robustness and security. In this paper, we describe a methodology for linking physical and logical Internet maps that aims toward a consistent, cross-layer representation. Our approach is constructive and uses geographic location as the key feature for linking physical and logical layers. We begin by building a representation of physical connectivity using online sources to identify locations that house transport hardware (i.e., PoPs, colocation centers, IXPs, etc.), and approximate locations of links between these based on shortest-path rights-of-way. We then utilize standard data sources for generating maps of IP-level and AS-level logical connectivity, and graft these onto physical maps using geographic anchors. We implement our methodology in an open-source framework called the Internet Geographic Database (iGDB), which includes tools for updating measurement data and assuring internal consistency. iGDB is built to be used with ArcGIS, a geographic information system that provides broad capability for spatial analysis and visualization. We describe the details of the iGDB implementation and demonstrate how it can be used in a variety of settings. Scott Anderson, Loqman Salamatian, Zachary S. Bischof, Alberto Dainotti, Paul Barford |
IMC | 4 |
| 2022 | Analysis of IPv4 address space utilization with ANT ISI dataset and censysabstractSince 2003, the ANT Lab at ISI has used active measurements to conduct a census of the IPv4 address space [1]. Each census lasts approximately 2--3 months, scanning the entire IPv4 address space using ICMP ping probes and recording replies. To date, there have been 85 surveys. One of the by-products of these surveys is the address history dataset [5], which contains the ICMP responses from more than 1.4 billion IPv4 addresses over an 18 year period, starting in 2006. Manasvini Sethuraman, Zachary S. Bischof, Alberto Dainotti |
IMC | 3 |
| 2022 | Investigating the impact of DDoS attacks on DNS infrastructureabstractDenial of Service (DDoS) attacks both abuse and target core Internet infrastructures and services, including the Domain Name System (DNS). To characterize recent DDoS attacks against authoritative DNS infrastructure, we join two existing data sets - DoS activity inferred from a sizable darknet, and contemporaneous DNS measurement data - for a 17-month period (Nov. 20 - Mar. 22). Our measurements reveal evidence that millions of domains (up to 5% of the DNS namespace) experienced a DoS attack during our observation window. Most attacks did not substantially harm DNS performance, but in some cases we saw 100-fold increases in DNS resolution time, or complete unreachability. Our measurements captured a devastating attack against a large provider in the Netherlands (TransIP), and attacks against Russian infrastructure. Our data corroborates the value of known best practices to improve DNS resilience to attacks, including the use of anycast and topological redundancy in nameserver infrastructure. We discuss the strengths and weaknesses of our data sets for DDoS tracking and impact on the DNS, and promising next steps to improve our understanding of the evolving DDoS ecosystem. Raffaele Sommese, K. C. Claffy, Roland van Rijswijk-Deij, Arnab Chattopadhyay, Alberto Dainotti, Anna Sperotto, Mattijs Jonker |
IMC | 5 |
| 2022 | Quantifying Nations' Exposure to Traffic Observation and Selective Tampering
Alexander Gamero-Garrido, Esteban Carisimo, Shuai Hao 0001, Bradley Huffaker, Alex C. Snoeren, Alberto Dainotti |
PAM | 6 |
| 2022 | Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope
Raphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti, Thomas C. Schmidt, Matthias Wählisch |
USENIX Security Symposium | 4 |
| 2021 | Identifying ASes of state-owned internet operatorsabstractIn this paper we present and apply a methodology to accurately identify state-owned Internet operators worldwide and their Autonomous System Numbers (ASNs). Obtaining an accurate dataset of ASNs of state-owned Internet operators enables studies where state ownership is an important dimension, including research related to Internet censorship and surveillance, cyber-warfare and international relations, ICT development and digital divide, critical infrastructure protection, and public policy. Our approach is based on a multi-stage, in-depth manual analysis of datasets that are highly diverse in nature. We find that each of these datasets contributes in different ways to the classification process and we identify limitations and shortcomings of these data sources. We obtain the first data set of this type, make it available to the research community together with the several lessons we learned in the process, and perform a preliminary analysis based on our data. We find that 53% (i.e., 123) of the world's countries are majority owners of Internet operators, highlighting that this is a widespread phenomenon. We also find and document the existence of subsidiaries of state-owned governments operating in foreign countries, an aspect that touches every continent and particularly affects Africa. We hope that this work and the associated data set will inspire and enable a broad set of Internet measurement studies and interdisciplinary research. Esteban Carisimo, Alexander Gamero-Garrido, Alex C. Snoeren, Alberto Dainotti |
Internet Measurement Conference | 4 |
| 2021 | The parallel lives of autonomous systems: ASN allocations vs. BGPabstractAutonomous Systems (ASes) exist in two dimensions on the Internet: the administrative and the operational one. Regional Internet Registries (RIRs) rule the former, while BGP the latter. In this work, we reconstruct the lives of the ASes on both dimensions, performing a joint analysis that covers 17 years of data. For the administrative dimension, we leverage delegation files published by RIRs to report the daily status of Internet resources they allocate. For the operational dimension, we characterize the temporal activity of ASNs in the Internet control plane using BGP data collected by the RouteViews and RIPE RIS projects. We present a methodology to extract insights about AS life cycles, including dealing with pitfalls affecting authoritative public datasets. We then perform a joint analysis to establish the relationship (or lack of) between these two dimensions for all allocated ASNs and all ASNs visible in BGP. We characterize the usual behaviors, specific differences between RIRs and historical resources, as well as measure the discrepancies between the two "parallel" lives. We find discrepancies and misalignment that reveal useful insights, and we highlight through examples the potential of this new lens to help pinpoint malicious BGP activity and various types of misconfigurations. This study illuminates a largely unexplored aspect of the Internet global routing system and provides methods and data to support broader studies that relate to security, policy, and network management. Eugenio Nerio Nemmi, Francesco Sassi, Massimo La Morgia, Cecilia Testart, Alessandro Mei, Alberto Dainotti |
Internet Measurement Conference | 6 |
| 2020 | DynamIPs: analyzing address assignment practices in IPv4 and IPv6abstractIP addresses are commonly used to identify hosts or properties of hosts. The address assigned to a host may change, however, and the extent to which these changes occur in time as well as in the address space is currently unknown, especially in IPv6. Ramakrishna Padmanabhan, John P. Rula, Philipp Richter, Stephen D. Strowes, Alberto Dainotti |
CoNEXT | 5 |
| 2020 | AS-Path Prepending: there is no rose without a thornabstractInbound traffic engineering (ITE)---the process of announcing routes to, e.g., maximize revenue or minimize congestion---is an essential task for Autonomous Systems (ASes). AS Path Prepending (ASPP) is an easy to use and well-known ITE technique that routing manuals show as one of the first alternatives to influence other ASes' routing decisions. We observe that origin ASes currently prepend more than 25% of all IPv4 prefixes. Pedro de B. Marcos, Lars Prehn, Lucas Leal, Alberto Dainotti, Anja Feldmann, Marinho P. Barcellos |
Internet Measurement Conference | 4 |
| 2020 | MAnycast2: Using Anycast to Measure AnycastabstractAnycast addressing - assigning the same IP address to multiple, distributed devices - has become a fundamental approach to improving the resilience and performance of Internet services, but its conventional deployment model makes it impossible to infer from the address itself that it is anycast. Existing methods to detect anycast IPv4 prefixes present accuracy challenges stemming from routing and latency dynamics, and efficiency and scalability challenges related to measurement load. We review these challenges and introduce a new technique we call "MAnycast2" that can help overcome them. Our technique uses a distributed measurement platform of anycast vantage points as sources to probe potential anycast destinations. This approach eliminates any sensitivity to latency dynamics, and greatly improves efficiency and scalability. We discuss alternatives to overcome remaining challenges relating to routing dynamics, suggesting a path toward establishing the capability to complete, in under 3 hours, a full census of which IPv4 prefixes in the ISI hitlist are anycast. Raffaele Sommese, Leandro Marcio Bertholdo, Gautam Akiwate, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
Internet Measurement Conference | 6 |
| 2020 | When Parents and Children Disagree: Diving into DNS Delegation Inconsistency
Raffaele Sommese, Giovane Cesar Moreira Moura, Mattijs Jonker, Roland van Rijswijk-Deij, Alberto Dainotti, K. C. Claffy, Anna Sperotto |
PAM | 5 |
| 2020 | To Filter or Not to Filter: Measuring the Benefits of Registering in the RPKI Today
Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
PAM | 4 |
| 2019 | Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing TableabstractBGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems. Cecilia Testart, Philipp Richter, Alistair King, Alberto Dainotti, David D. Clark |
Internet Measurement Conference | 4 |
| 2019 | Blink: Fast Connectivity Recovery Entirely in the Data Plane
Thomas Holterbach, Edgar Costa Molero, Maria Apostolaki, Alberto Dainotti, Stefano Vissicchio, Laurent Vanbever |
NSDI | 4 |
| 2019 | How to Find Correlated Internet Failures
Ramakrishna Padmanabhan, Aaron Schulman, Alberto Dainotti, Dave Levin, Neil Spring |
PAM | 3 |
| 2018 | A First Joint Look at DoS Attacks and BGP Blackholing in the Wild
Mattijs Jonker, Aiko Pras, Alberto Dainotti, Anna Sperotto |
Internet Measurement Conference | 3 |
| 2018 | Inferring Carrier-Grade NAT Deployment in the WildabstractGiven the increasing scarcity of IPv4 addresses, network operators are resorting to measures to expand their address pool or prolong the life of existing addresses. One such approach is Carrier-Grade NAT (CGN), where many end-users in a network share a single public IPv4 address. There is limited data about the prevalence of CGN, despite the implications on performance, security, and ultimately, the adoption of IPv6. In this work, we present passive measurement-based techniques for detecting CGN deployments across the entire Internet, without the requirement of access to machines behind a CGN. Specifically, we identify patterns in how client IP addresses are observed at M-Lab servers and at the UCSD network telescope to infer whether those clients are behind a CGN. We apply our methods on data collected from 2014 to 2016. We find that CGN deployment is increasing rapidly. Overall, we infer that 4.1K autonomous systems are deploying CGN, 6 times the number inferred by the most recent studies. Ioana Livadariu, Karyn Benson, Ahmed Elmokashfi, Amogh Dhamdhere, Alberto Dainotti |
INFOCOM | 5 |
| 2018 | ARTEMIS: Neutralizing BGP Hijacking Within a MinuteabstractBorder gateway protocol (BGP) prefix hijacking is a critical threat to Internet organizations and users. Despite the availability of several defense approaches (ranging from RPKI to popular third-party services), none of them solves the problem adequately in practice. In fact, they suffer from: (i) lack of detection comprehensiveness, allowing sophisticated attackers to evade detection; (ii) limited accuracy, especially in the case of third-party detection; (iii) delayed verification and mitigation of incidents, reaching up to days; and (iv) lack of privacy and of flexibility in post-hijack counteractions, on the side of network operators. In this paper, we propose ARTEMIS, a defense approach (a) based on accurate and fast detection operated by the autonomous system itself, leveraging the pervasiveness of publicly available BGP monitoring services and their recent shift towards real-time streaming and thus (b) enabling flexible and fast mitigation of hijacking events. Compared to the previous work, our approach combines characteristics desirable to network operators, such as comprehensiveness, accuracy, speed, privacy, and flexibility. Finally, we show through real-world experiments that with the ARTEMIS approach, prefix hijacking can be neutralized within a minute. Pavlos Sermpezis, Vasileios Kotronis, Petros Gigis, Xenofontas A. Dimitropoulos, Danilo Cicalese, Alistair King, Alberto Dainotti |
IEEE/ACM Trans. Netw. | 7 |
| 2017 | Millions of targets under attack: a macroscopic characterization of the DoS ecosystemabstractDenial-of-Service attacks have rapidly increased in terms of frequency and intensity, steadily becoming one of the biggest threats to Internet stability and reliability. However, a rigorous comprehensive characterization of this phenomenon, and of countermeasures to mitigate the associated risks, faces many infrastructure and analytic challenges. We make progress toward this goal, by introducing and applying a new framework to enable a macroscopic characterization of attacks, attack targets, and DDoS Protection Services (DPSs). Our analysis leverages data from four independent global Internet measurement infrastructures over the last two years: backscatter traffic to a large network telescope; logs from amplification honeypots; a DNS measurement platform covering 60% of the current namespace; and a DNS-based data set focusing on DPS adoption. Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all / 24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks. In our data, Web servers were the most prominent attack target; an average of 3% of the Web sites in .com, .net, and .org were involved with attacks, daily. Finally, we shed light on factors influencing migration to a DPS. Mattijs Jonker, Alistair King, Johannes Krupp, Christian Rossow, Anna Sperotto, Alberto Dainotti |
Internet Measurement Conference | 6 |
| 2017 | SWIFT: Predictive Fast RerouteabstractNetwork operators often face the problem of remote outages in transit networks leading to significant (sometimes on the order of minutes) downtimes. The issue is that BGP, the Internet routing protocol, often converges slowly upon such outages, as large bursts of messages have to be processed and propagated router by router. Thomas Holterbach, Stefano Vissicchio, Alberto Dainotti, Laurent Vanbever |
SIGCOMM | 3 |
| 2016 | BGPStream: A Software Framework for Live and Historical BGP Data Analysis
Chiara Orsini 0001, Alistair King, Danilo Giordano, Vasileios Giotsas, Alberto Dainotti |
Internet Measurement Conference | 5 |
| 2016 | Lost in Space: Improving Inference of IPv4 Address Space UtilizationabstractOne challenge in understanding the evolution of the Internet infrastructure is the lack of systematic mechanisms for monitoring the extent to which allocated IP addresses are actually used. In this paper, we advance the science of inferring IPv4 address space utilization by proposing a novel taxonomy and analyzing and correlating results obtained through different types of measurements. We have previously studied an approach based on passive measurements that can reveal used portions of the address space unseen by active approaches. In this paper, we study such passive approaches in detail, extending our methodology to new types of vantage points and identifying traffic components that most significantly contribute to discovering used IPv4 network blocks. We then combine the results we obtained through passive measurements together with data from active measurement studies, as well as measurements from Border Gateway Protocol and additional data sets available to researchers. Through the analysis of this large collection of heterogeneous data sets, we substantially improve the state of the art in terms of: 1) understanding the challenges and opportunities in using passive and active techniques to study address utilization and 2) knowledge of the utilization of the IPv4 space. Alberto Dainotti, Karyn Benson, Alistair King, Bradley Huffaker, Eduard Glatz, Xenofontas A. Dimitropoulos, Philipp Richter, Alessandro Finamore, Alex C. Snoeren |
IEEE J. Sel. Areas Commun. | 1 |
| 2015 | Leveraging Internet Background Radiation for Opportunistic Network AnalysisabstractFor more than a decade, unsolicited traffic sent to unused regions of the address space has provided valuable insight into malicious Internet activities. In this paper, we explore the utility of this traffic, known as Internet Background Radiation (IBR), for a different purpose: as a data source of Internet-wide measurements. We collect and analyze IBR from two large darknets, carefully deconstructing its various components and characterizing them along dimensions applicable to Internet-wide measurements. Intuitively, IBR can provide insight into network properties when traffic from that network contains relevant information and is of sufficient volume. We turn this intuition into a scientific investigation, examining which networks send IBR, identifying components of IBR that enable opportunistic network inferences, and characterizing the frequency and granularity of traffic sources. We also consider the influences of time of collection and position in the address space on our results. We leverage IBR properties in three case studies to show that IBR can supplement existing techniques by improving coverage and/or diversity of analyzable networks while reducing measurement overhead. Our main contribution is a new framework for understanding the circumstances and properties for which unsolicited traffic is an appropriate data source for inference of macroscopic Internet properties, which can help other researchers assess its utility for a given study. Karyn Benson, Alberto Dainotti, K. C. Claffy, Alex C. Snoeren, Michael G. Kallitsis |
Internet Measurement Conference | 2 |
| 2015 | Analysis of a "/0" Stealth Scan From a BotnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
IEEE/ACM Trans. Netw. | 1 |
| 2014 | Uncovering network tarpits with degreaserabstractNetwork tarpits, whereby a single host or appliance can masquerade as many fake hosts on a network and slow network scanners, are a form of defensive cyber-deception. In this work, we develop degreaser, an efficient fingerprinting tool to remotely detect tarpits. In addition to validating our tool in a controlled environment, we use degreaser to perform an Internet-wide scan. We discover tarpits of non-trivial size in the wild (prefixes as large as/16), and characterize their distribution and behavior. We then show how tarpits pollute existing network measurement surveys that are tarpit-naïve, e.g. Internet census data, and how degreaser can improve the accuracy of such surveys. Lastly, our findings suggest several ways in which to advance the realism of current network tarpits, thereby raising the bar on tarpits as an operational security mechanism. Lance Alt, Robert Beverly, Alberto Dainotti |
ACSAC | 3 |
| 2014 | Analysis of Country-Wide Internet Outages Caused by CensorshipabstractIn the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper, we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data, unsolicited data plane traffic to unassigned address space, active macroscopic traceroute measurements, RIR delegation files, and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin autonomous systems (ASs) using publicly available BGP data repositories in the US and Europe. We then analyzed observable activity related to these sets of prefixes and ASs throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions. Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè |
IEEE/ACM Trans. Netw. | 1 |
| 2013 | Gaining insight into AS-level outages through analysis of Internet background radiationabstractInternet Background Radiation (IBR) is unsolicited network traffic mostly generated by malicious software, e.g., worms, scans. In previous work, we extracted a signal from IBR traffic arriving at a large (/8) segment of unassigned IPv4 address space to identify large-scale disruptions of connectivity at an Autonomous System (AS) granularity, and used our technique to study episodes of government censorship and natural disasters [1]. Here we explore other IBR-derived metrics that may provide insights into the causes of macroscopic connectivity disruptions. We propose metrics indicating packet loss (e.g., due to link congestion) along a path from a specific AS to our observation point. We use three case studies to illustrate how our metrics can help identify packet loss characteristics of an outage. These metrics could be used in the diagnostic component of a semiautomated system for detecting and characterizing large-scale outages. Karyn Benson, Alberto Dainotti, K. C. Claffy, Emile Aben |
INFOCOM | 2 |
| 2012 | Analysis of a "/0" stealth scan from a botnetabstractBotnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial of service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February of last year. This 12-day scan originated from approximately 3 million distinct IP addresses, and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers, its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This work offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet. Alberto Dainotti, Alistair King, K. C. Claffy, Ferdinando Papale, Antonio Pescapè |
Internet Measurement Conference | 1 |
| 2012 | A tool for the generation of realistic network workload for emerging networking scenarios
Alessio Botta, Alberto Dainotti, Antonio Pescapè |
Comput. Networks | 2 |
| 2011 | Traffic Classification through Joint Distributions of Packet-Level StatisticsabstractInterest in traffic classification, in both industry and academia, has dramatically grown in the past few years. Research is devoting great efforts to statistical approaches using robust features. In this paper we propose a classification approach based on the joint distribution of Packet Size (PS) and Inter-Packet Time (IPT) and on machine- learning algorithms. Provided results, obtained using different real traffic traces, demonstrate how the proposed approach is able to achieve high (byte) accuracy (till 98%) and how the new features we introduced show properties of robustness, which suggest their use in the design of classification/identification approaches robust to traffic encryption and protocol obfuscation. Alberto Dainotti, Antonio Pescapè |
GLOBECOM | 1 |
| 2011 | Analysis of country-wide internet outages caused by censorshipabstractIn the first months of 2011, Internet communications were disrupted in several North African countries in response to civilian protests and threats of civil war. In this paper we analyze episodes of these disruptions in two countries: Egypt and Libya. Our analysis relies on multiple sources of large-scale data already available to academic researchers: BGP interdomain routing control plane data; unsolicited data plane traffic to unassigned address space; active macroscopic traceroute measurements; RIR delegation files; and MaxMind's geolocation database. We used the latter two data sets to determine which IP address ranges were allocated to entities within each country, and then mapped these IP addresses of interest to BGP-announced address ranges (prefixes) and origin ASes using publicly available BGP data repositories in the U.S. and Europe. We then analyzed observable activity related to these sets of prefixes and ASes throughout the censorship episodes. Using both control plane and data plane data sets in combination allowed us to narrow down which forms of Internet access disruption were implemented in a given region over time. Among other insights, we detected what we believe were Libya's attempts to test firewall-based blocking before they executed more aggressive BGP-based disconnection. Our methodology could be used, and automated, to detect outages or similar macroscopically disruptive events in other geographic or topological regions. Alberto Dainotti, Claudio Squarcella, Emile Aben, K. C. Claffy, Marco Chiesa, Michele Russo, Antonio Pescapè |
Internet Measurement Conference | 1 |
| 2010 | Identification of Traffic Flows Hiding behind TCP Port 80abstractBeyond Quality of Service and billing, one of the most important applications of traffic identification is in the field of network security. Despite their simplicity, current approaches based on port numbers are highly unreliable. This paper proposes an identification approach, based on a cascade of decision trees. The approach uses the sign pattern and payload size of the first four packets in each flow, thus remaining applicable to encrypted traffic too. The effectiveness of the proposed approach is evaluated on five real traffic traces collected in different time periods and over four different networks. The obtained overall accuracy gives us grounds to consider the adoption of this approach as stand-alone in on-line platforms for network traffic identification or in combination with classical firewall architectures. Alberto Dainotti, Francesco Gargiulo 0001, Ludmila I. Kuncheva, Antonio Pescapè, Carlo Sansone |
ICC | 1 |
| 2009 | Traffic analysis of peer-to-peer IPTV communities
Thomas Silverston, Olivier Fourmaux, Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre, Kavé Salamatian |
Comput. Networks | 4 |
| 2009 | A cascade architecture for DoS attacks detection based on the wavelet transformabstractIn this paper we propose an automated system able to detect volume-based anomalies in network traffic caused by Denial of Service (DoS) attacks. We designed a system with a two-stage architecture that combines more traditional change point detection approaches (Adaptive Threshold and Cumulative Sum ) with a novel one based on the Continuous Wavelet Transform. The presented anomaly detection system is able to achieve good results in terms of the trade-off between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available attack-free traffic traces to which we superimpose anomaly profiles obtained both as time series of known common behaviors and by generating traffic with real tools for DoS attacks. Extensive test results show how the proposed system accurately detects a wide range of DoS anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration). Moreover, we separately consider and evaluate some special test-cases. Alberto Dainotti, Antonio Pescapè, Giorgio Ventre |
J. Comput. Secur. | 1 |
| 2008 | Classification of Network Traffic via Packet-Level Hidden Markov ModelsabstractTraffic classification and identification is a fertile research area. Beyond Quality of Service, service differentiation, and billing, one of the most important applications of traffic classification is in the field of network security. This paper proposes a packet-level traffic classification approach based on Hidden Markov Model (HMM). Classification is performed by using real network traffic and estimating - in a combined fashion - Packet Size (PS) and Inter Packet Time (IPT) characteristics, thus remaining applicable to encrypted traffic too. The effectiveness of the proposed approach is evaluated by considering several traffic typologies: we applied our model to real traffic traces of Age of Mythology and Counter Strike (two Multi Player Network Games), HTTP, SMTP, Edonkey, PPlive (a peer-to-peer IPTV application), and MSN Messenger. An analytical basis and the mathematical details regarding the model are given. Results show how the proposed approach is able to classify network traffic by using packet-level statistical properties and therefore it is a good candidate as a component for a multi-classification framework. Alberto Dainotti, Walter de Donato, Antonio Pescapè, Pierluigi Salvo Rossi |
GLOBECOM | 1 |
| 2008 | Internet traffic modeling by means of Hidden Markov Models
Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Francesco Palmieri 0001, Giorgio Ventre |
Comput. Networks | 1 |
| 2007 | Do you know what you are generating?abstractSoftware-based traffic generators are commonly used in experimental research on computer networks. However, there are no much studies focusing on how such instruments are accurate. Here we start a discussion reviewing the problem of using software-based traffic generators over common hardware/software, highlighting interesting issues that pose some threats to common beliefs. We started comparing the operator-requested traffic profile against the real behavior of commonly used software-based traffic generators. We aim at performing tests under different conditions and looking both at packet/bit rate and inter-packet time distribution. Preliminary results show notable differences in some cases, opening the way to interesting discussions and further investigations. Alberto Dainotti, Alessio Botta, Antonio Pescapè |
CoNEXT | 1 |
| 2007 | Reducing Network Traffic Data SetsabstractIn the study of network traffic, the collection and the processing of measurement data sets play a fundamental role. Due to the large size of typical traffic traces, their analysis is often heavy in terms of computational time and resources. In addition, even when the data sets are small, due to the intrinsic redundancy of the data, there is no need to consider the entire data sets in the processing stages. To cope with these issues, we use anentropy-based methodology to reduce network traffic data sets obtained by measurements over real networks. The off-line approach we used is based on themarginalutilityconcept, and reveals encouraging results when applied to real data captured over real networks, especially when dealing with large amounts of data. To show the applicability of our approach, we present and discuss results obtained in the analysis and characterization, at packet-level, of traffic traces from two popular network games:Counter-StrikeandAgeofMythology. Thanks to the differences between the two considered on-line games and their traffic traces we can draw pros and cons in realistic scenarios. Alessio Botta, Alberto Dainotti, Antonio Pescapè, Giorgio Ventre |
ICC | 2 |
| 2007 | Worm Traffic Analysis and CharacterizationabstractInternet worms are gaining ever more attention by the research community, representing one of the hot research topics in the field of network security. Our knowledge of phenomena related to Internet worms (from their intrinsic characteristics to their impact and to possible countermeasures) is still in its infancy. This is one of the main reasons for the existence of different kinds of research approaches. In this paper we focus on worm traffic analysis. We propose a general methodology, we discuss issues involved, and we present a software platform which can be used for this kind of study. Moreover, we show some interesting preliminary results from our traffic analysis of two of the most relevant worms that spread over the Internet: Witty and Slammer. Our results provide interesting evidences of (spatial and temporal) invariance and give some hints on worm traffic fingerprinting. Alberto Dainotti, Antonio Pescapè, Giorgio Ventre |
ICC | 1 |
| 2007 | SCTP performance evaluation over heterogeneous networksabstractAbstract Since its definition in 2000, the Stream Control Transmission Protocol (SCTP) has attracted increasing interest. Several research works, often validated through analytical and simulative analysis, have attempted to evaluate the benefits of substituting TCP with SCTP, both for signaling and data transfer. In this work, we present a traffic generation and performance analysis tool to test SCTP on real networks. We study the performance of SCTP on real heterogeneous (wired/wireless) scenarios, providing results in terms of throughput and jitter, and comparing its performance against TCP and UDP over the same conditions. Our experimental analysis shows that the current performance of SCTP (operating on a Linux platform) does not justify the use of SCTP as a simple substitute for TCP. Copyright © 2007 John Wiley & Sons, Ltd. Alberto Dainotti, Salvatore Loreto, Antonio Pescapè, Giorgio Ventre |
Concurr. Comput. Pract. Exp. | 1 |
| 2006 | Searching for invariants in network games trafficabstractEven if Internet traffic analysis and characterization is a fertile research area, a lot of work still must be done to study and understand the traffic characteristics of new emerging multimedia applications. Among them, an interesting category is that of multiplayer network games. This paper aims at demonstrating that, at packet level, spatial and temporal invariants exist in the traffic of such applications. For this purpose, we study Counter-Strike, a popular client/server network game, comparing results from two different networks. The effectiveness of the proposed approach is evaluated by studying statistics of both packet size and inter-packet time. Results provide a view on packet-level game traffic and they confirm that the main traffic dynamics present properties that can be generalized, independently of the observation point and time. Alberto Dainotti, Alessio Botta, Antonio Pescapè, Giorgio Ventre |
CoNEXT | 1 |
| 2006 | An HMM Approach to Internet Traffic ModelingabstractTraffic modeling is a fertile research area. This paper proposes a packet-level traffic model of traffic sources based on hidden Markov model. It has been developed by using real network traffic and estimating in a combined fashion packet size and inter packet time. The effectiveness of the proposed model is evaluated by studying several traffic types with strong differences in terms of both applications/users and protocol behavior. Indeed, we applied our model to real traffic traces of Age of Mythology (a Multi Player Network Game), SMTP, and HTTP. An analytical basis and the mathematical details regarding the model are given. Results show how the proposed model captures first-order statistics, as well as temporal dynamics via auto- and cross-correlation. Also, the capability to accurately replicate the considered traffic sources is shown. Finally, preliminary results for model-based traffic prediction reveal encouraging. Alberto Dainotti, Antonio Pescapè, Pierluigi Salvo Rossi, Giulio Iannello, Francesco Palmieri 0001, Giorgio Ventre |
GLOBECOM | 1 |
| 2006 | Wavelet-based Detection of DoS AttacksabstractAutomated detection of anomalies in network traffic is an important and challenging task. In this work we propose an automated system to detect volume-based anomalies in network traffic caused by denial of service (DoS) attacks. The system has a two-stage architecture that combines more traditional approaches (adaptive threshold and cumulative sum) with a novel one based on the continuous wavelet transform. Thanks to the proposed architecture, we obtain good results in terms of tradeoff between correct detections and false alarms, estimation of anomaly duration, and ability to distinguish between subsequent anomalies. We test our system using a set of publicly available traffic traces to which we superimpose anomalies related to real DoS attacks tools. Extensive test results show how the proposed system accurately detects a wide range of anomalies and how the performance indicators are affected by anomalies characteristics (i.e. amplitude and duration). Alberto Dainotti, Antonio Pescapè, Giorgio Ventre |
GLOBECOM | 1 |