EDBT 2026 Demo / reviewers in the wild / expert
Eric Osterweil
dblp:31/1732
· DBLP profile ↗
18ranked-venue papers
8as first author
4since 2021 · last 2025
0000-0003-1446-5602ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 4 first-author · 1 since 2021Security and privacy · 7 · 3 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Network security · 64% Web and mobile security · 20% Usable security · 8% | |
| Computer networks
9 papers |
Internet architecture and protocols · 69% Network measurement and analytics · 21% Network management and operations · 7% |
Topics — the 14 heaviest of 20, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › protocol security
DNS security |
0.8 | 3 | 2021 | Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKI · WWW 2021 Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis Corroboration · IEEE Trans. Parallel Distributed Syst. 2014 Quantifying the operational status of the DNSSEC deployment · Internet Measurement Conference 2008 |
Web and mobile security
web PKI |
0.5 | 1 | 2021 | Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKI · WWW 2021 |
Network security › attack strategy
man-in-the-middle attack |
0.2 | 1 | 2016 | MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era · IEEE Symposium on Security and Privacy 2016 |
Internet architecture and protocols
IPv6 |
0.2 | 1 | 2014 | Measuring IPv6 adoption · SIGCOMM 2014 |
Internet architecture and protocols › IPv6
IPv6 deployment measurement |
0.2 | 1 | 2014 | Measuring IPv6 adoption · SIGCOMM 2014 |
Usable security › authentication usability
key verification |
0.2 | 1 | 2014 | Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis Corroboration · IEEE Trans. Parallel Distributed Syst. 2014 |
Internet architecture and protocols
domain name system |
0.2 | 3 | 2016 | MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era · IEEE Symposium on Security and Privacy 2016 Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis Corroboration · IEEE Trans. Parallel Distributed Syst. 2014 Quantifying the operational status of the DNSSEC deployment · Internet Measurement Conference 2008 |
Network measurement and analytics
security measurement |
0.1 | 1 | 2021 | Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKI · WWW 2021 |
Internet architecture and protocols › domain name system
DNS security |
0.1 | 1 | 2011 | Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSEC · IEEE Trans. Dependable Secur. Comput. 2011 |
Network security › protocol security › DNS security
DNSSEC deployment |
0.1 | 1 | 2008 | Quantifying the operational status of the DNSSEC deployment · Internet Measurement Conference 2008 |
Internet architecture and protocols › domain name system
DNSSEC |
0.1 | 1 | 2014 | Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis Corroboration · IEEE Trans. Parallel Distributed Syst. 2014 |
Network measurement and analytics › internet measurement
internet-wide measurement |
0.1 | 1 | 2014 | Measuring IPv6 adoption · SIGCOMM 2014 |
Cryptographic protocols and secure computation › key management
public key infrastructure |
0.1 | 1 | 2014 | Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis Corroboration · IEEE Trans. Parallel Distributed Syst. 2014 |
Performance modeling and evaluation
simulation and emulation |
0.0 | 1 | 2004 | A system for simulation, emulation, and deployment of heterogeneous sensor networks · SenSys 2004 |
Methods — techniques the papers use, named apart from their topics
measurement study · 1.6vulnerability assessment · 0.5empirical data analysis · 0.5visualization · 0.5theoretical modeling · 0.4quantitative measurement · 0.4dependency analysis · 0.4public-key cryptography · 0.2simulation · 0.1emulation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Key to Deobfuscation is Pattern of Life, not Overcoming EncryptionabstractOnline privacy protection methods are critically important but also shield those who conduct criminal activities such as cyber-attacks. In this work, we consider scenarios where Privacy Preserving Technologies (PPTs) are used to obfuscate network source locations of users conducting malfeasance. We present a novel methodology that synthesizes measurements from key locations, and links Pattern of Life (PoL) with obfuscated network traffic, which we call Deobfuscating Using Patterns of Life (DUPOL). We illustrate DUPOL’s utility in an increasingly common scenario: malicious actors transacting on a message board, hiding their network source locations using Privacy Preserving Technologies (PPTs). Using multiple simulated monitoring points and communications from an actual year-long social network message board, we show that DNS over HTTPS (DoH), DNS over TLS (DoT), and Virtual Private Networks (VPNs) can be deobfuscated with up to $100 \%$ accuracy. In this work, we provide recommendations for ideal monitoring vantage points on the Internet to achieve the best deobfuscation accuracy. Taylor Henderson, Eric Osterweil, Pavan Kumar Dinesh |
ISNCC | 2 |
| 2022 | From the Beginning: Key Transitions in the First 15 Years of DNSSECabstractWhen the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor of better security for the overall Internet. Thereby, the scale of the loosely-federated delegation in DNS became an unprecedented cryptographic key management challenge. Though fundamental for current and future operational success, our community lacks a clear notion of how to empirically evaluate the process of securely transitioning keys. In this paper, we propose two building blocks to formally characterize and assess key transitions. First, the anatomy of key transitions, i.e., measurable and well-defined properties of key changes; and second, a novel classification model based on this anatomy for describing key transition practices in abstract terms. This abstraction allows for classifying operational behavior. We apply our proposed transition anatomy and transition classes to describe the global DNSSEC deployment. Specifically, we use measurements from the first 15 years of the DNSSEC rollout to detect and understand which key transitions have been used to what degree and which rates of errors and warnings occurred. In contrast to prior work, we consider all possible transitions and not only 1:1 key rollovers. Our results show measurable gaps between prescribed key management processes and key transitions in the wild. We also find evidence that such noncompliant transitions are needed in operations. Eric Osterweil, Pouyan Fotouhi Tehrani, Thomas C. Schmidt, Matthias Wählisch |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | A Cooperative Market-based Decision Guidance Approach for Resilient Power Systems
Alexander Brodsky 0001, Eric Osterweil, Roberto Levy |
ICORES | 2 |
| 2021 | Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKIabstractDuring disasters, crisis, and emergencies the public relies on online services provided by official authorities to receive timely alerts, trustworthy information, and access to relief programs. It is therefore crucial for the authorities to reduce risks when accessing their online services. This includes catering to secure identification of service, secure resolution of name to network service, and content security and privacy as a minimum base for trustworthy communication. Pouyan Fotouhi Tehrani, Eric Osterweil, Jochen H. Schiller, Thomas C. Schmidt, Matthias Wählisch |
WWW | 2 |
| 2017 | Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic StudyabstractThe recent unprecedented delegation of new generic top-level domains (gTLDs) has exacerbated an existing, but fallow, problem called name collisions. One concrete exploit of such problem was discovered recently, which targets internal namespaces and enables Man in the Middle (MitM) attacks against end-user devices from anywhere on the Internet. Analysis of the underlying problem shows that it is not specific to any single service protocol, but little attention has been paid to understand the vulnerability status and the defense solution space at the service level. In this paper, we perform the first systematic study of the robustness of internal network services under name collision attacks. Qi Alfred Chen, Matthew Thomas, Eric Osterweil, Z. Morley Mao |
CCS | 3 |
| 2016 | MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD EraabstractRecently, Man in the Middle (MitM) attacks on web browsing have become easier than they have ever been before because of a problem called "Name Collision" and a protocol called the Web Proxy Auto-Discovery (WPAD) protocol. This name collision attack can cause all web traffic of an Internet user to be redirected to a MitM proxy automatically right after the launching of a standard browser. The underlying problem of this attack is internal namespace WPAD query leakage, which itself is a known problem for years. However, it remains understudied since it was not easily exploitable before the recent new gTLD (generic Top-Level Domains) delegation. In this paper, we focus on this newly-exposed MitM attack vector and perform the first systematic study of the underlying problem causes and its vulnerability status in the wild. First, we show the severity of the problem by characterizing leaked WPAD query traffic to the DNS root servers, and find that a major cause of the leakage problem is actually a result of settings on the end user devices. More specifically, we find that under common settings, devices can mistakenly generate internal queries when used outside an internal network (e.g., used at home). Second, we define and quantify a candidate measure of attack surface by defining "highly-vulnerable domains", which are domains routinely exposing a large number of potential victims, and use it to perform a systematic assessment of the vulnerability status. We find that almost all leaked queries are for new gTLD domains we define to be highly-vulnerable, indirectly validating our attack surface definition. We further find that 10% of these highly-vulnerable domains have already been registered, making the corresponding users immediately vulnerable to the exploit at any time. Our results provide a strong and urgent message to deploy proactive protection. We discuss promising directions for remediation at the new gTLD registry, Autonomous System (AS), and end user levels, and use empirical data analysis to estimate and compare their effectiveness and deployment difficulties. Qi Alfred Chen, Eric Osterweil, Matthew Thomas, Z. Morley Mao |
IEEE Symposium on Security and Privacy | 2 |
| 2014 | The Shape and Size of Threats: Defining a Networked System's Attack SurfaceabstractAs more complex security services have been added to today's Internet, it becomes increasingly difficult to quantify their vulnerability to compromise. The concept of "attack surface" has emerged in recent years as a measure of such vulnerabilities, however systematically quantifying the attack surfaces of networked systems remains an open challenge. In this work we propose a methodology to both quantify the attack surface and visually represent semantically different components (or resources) of such systems by identifying their dependencies. To illustrate the efficacy of our methodology, we examine two real Internet standards (the X.509 CA verification system and DANE) as case studies. We believe this work represents a first step towards systemically modeling dependencies of (and interdependencies between) networked systems, and shows the usability benefits from leveraging existing services. Eric Osterweil, Danny McPherson, Lixia Zhang 0001 |
ICNP | 1 |
| 2014 | Measuring IPv6 adoptionabstractAfter several IPv4 address exhaustion milestones in the last three years, it is becoming apparent that the world is running out of IPv4 addresses, and the adoption of the next generation Internet protocol, IPv6, though nascent, is accelerating. In order to better understand this unique and disruptive transition, we explore twelve metrics using ten global-scale datasets to create the longest and broadest measurement of IPv6 adoption to date. Using this perspective, we find that adoption, relative to IPv4, varies by two orders of magnitude depending on the measure examined and that care must be taken when evaluating adoption metrics in isolation. Further, we find that regional adoption is not uniform. Finally, and perhaps most surprisingly, we find that over the last three years, the nature of IPv6 utilization-in terms of traffic, content, reliance on transition technology, and performance-has shifted dramatically from prior findings, indicating a maturing of the protocol into production mode. We believe IPv6's recent growth and this changing utilization signal a true quantum leap. Jakub Czyz, Mark Allman, Jing Zhang 0027, Scott Iekel-Johnson, Eric Osterweil, Michael D. Bailey |
SIGCOMM | 5 |
| 2014 | Verifying Keys through Publicity and Communities of Trust: Quantifying Off-Axis CorroborationabstractThe DNS Security Extensions (DNSSEC) arguably make DNS the first core Internet system to be protected using public key cryptography. The success of DNSSEC not only protects the DNS, but has generated interest in using this secured global database for new services such as those proposed by the IETF DANE working group. However, continued success is only possible if several important operational issues can be addressed. For example, .gov and .arpa have already suffered misconfigurations where DNS continued to function properly, but DNSSEC failed (thus, orphaning their entire subtrees in DNSSEC). Internet-scale verification systems must tolerate this type of chaos, but what kind of verification can one derive for systems with dynamism like this? In this paper, we propose to achieve robust verification with a new theoretical model, called Public Data, which treats operational deployments as Communities of Trust (CoTs) and makes them the verification substrate. Using a realization of the above idea, called Vantages, we quantitatively show that using a reasonable DNSSEC deployment model and a typical choice of a CoT, an adversary would need to be able to have visibility into and perform on-path Man-in-the-Middle (MitM) attacks on arbitrary traffic into and out of up to 90 percent of the all of the Autonomous Systems (ASes) in the Internet before having even a 10 percent chance of spoofing a DNSKEY. Further, our limited deployment of Vantages has outperformed the verifiability of DNSSEC and has properly validated its data up to 99.5 percent of the time. Eric Osterweil, Daniel Massey, Danny McPherson, Lixia Zhang 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2012 | Dissecting ghost clicks: ad fraud via misdirected human clicksabstractFBI's Operation Ghost Click, the largest cybercriminal takedown in history, recently took down an ad fraud infrastructure that affected 4 million users and made its owners 14 million USD over a period of four years. The attackers hijacked clicks and ad impressions on victim machines infected by a DNS changer malware to earn ad revenue fraudulently. We experimented with the attack infrastructure when it was in operation and present a detailed account of the attackers' modus operandi. We also study the impact of this attack on real-world users and find that 37 subscriber lines were impacted in our data set. Also, 20 ad networks and 257 legitimate Web content publishers lost ad revenue while the attackers earned revenue convincing a dozen other ad networks that their ads were served on websites with real visitors. Our work expands the understanding of modalities of ad fraud and could help guide appropriate defense strategies. Sumayah A. Alrwais, Alexandre Gerber, Christopher W. Dunn, Oliver Spatscheck, Eric Osterweil |
ACSAC | 6 |
| 2012 | Behavior of DNS' Top Talkers, a .com/.net View
Eric Osterweil, Danny McPherson, Steve DiBenedetto, Christos Papadopoulos, Daniel Massey |
PAM | 1 |
| 2011 | The great IPv4 land grab: resource certification for the IPv4 grey marketabstractThe era of free IPv4 address allocations has ended and the grey market in IPv4 addresses is now emerging. This paper argues that one cannot and should not try to regulate who sells addresses and at what price, but one does need to provide some proof of ownership in the form of resource certification. In this paper we identify key requirements of resource certification, gained from both theoretical analysis and operational history. We further argue these requirements can be achieved by making use of the existing reverse DNS hierarchy, enhanced with DNS Security. Our analysis compares reverse DNS entries and BGP routing tables and shows this is both feasible and achievable today; an essential requirement as the grey market is also emerging today and solutions are needed now, not years in the future. Eric Osterweil, Shane Amante, Daniel Massey, Danny McPherson |
HotNets | 1 |
| 2011 | Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSECabstractThe DNS Security Extensions (DNSSEC) are among the first attempts to deploy cryptographic protections in an Internet-scale operational system. DNSSEC applies well-established public key cryptography to ensure data integrity and origin authenticity in the DNS system. While the cryptographic design of DNSSEC is sound and seemingly simple, its development has taken the IETF over a decade and several protocol revisions, and even today its deployment is still in the early stage of rolling out. In this paper, we provide the first systematic examination of the design, deployment, and operational challenges encountered by DNSSEC over the years. Our study reveals a fundamental gap between cryptographic designs and operational Internet systems. To be deployed in the global Internet, a cryptographic protocol must possess several critical properties including scalability, flexibility, incremental deployability, and ability to function in face of imperfect operations. We believe that the insights gained from this study can offer valuable inputs to future cryptographic designs for other Internet-scale systems. Hao Yang 0004, Eric Osterweil, Daniel Massey, Songwu Lu, Lixia Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2009 | Deploying and Monitoring DNS Security (DNSSEC)abstractSecSpider is a DNSSEC monitoring system that helps identify operational errors in the DNSSEC deployment and discover unforeseen obstacles. It collects, verifies, and publishes the DNSSEC keys for DNSSEC-enabled zones, which enables operators of both authoritative zones and recursive resolvers to deploy DNSSEC immediately, and benefit from its cryptographic protections. In this paper we present the design and implementation of SecSpider as well as several general lessons that stem from its design and implementation. Eric Osterweil, Daniel Massey, Lixia Zhang 0001 |
ACSAC | 1 |
| 2008 | Quantifying the operational status of the DNSSEC deploymentabstractThis paper examines the deployment of the DNS Security Extensions (DNSSEC), which adds cryptographic protection to DNS, one of the core components in the Internet infrastructure. We analyze the data collected from the initial DNSSEC deployment which started over 2 years ago, and identify three critical metrics to gauge the deployment: availability, verifiability, and validity. Our results provide the first comprehensive look at DNSSEC’s deployment and reveal a number of challenges that were not anticipated in the design but have become evident in the deployment. First, obstacles such as middle-boxes (firewalls, NATs, etc.) that exist in today’s Internet infrastructure have proven to be problematic and have resulted in unforeseen availability problems. Second, the public-key delegation system of DNSSEC has not evolved as it was hoped and it currently leaves over 97 % of DNSSEC zones isolated and unverifiable, unless some external key authentication mechanism is added. Furthermore, our results show that cryptographic verification is not equivalent to validation; a piece of verified data can still contain the wrong value. Finally, our results demonstrate the essential role of monitoring and measurement in the DNSSEC deployment. We believe that the observations and lessons from the DNSSEC deployment can provide insights into measuring future Internet-scale cryptographic systems. Eric Osterweil, Michael Ryan, Daniel Massey, Lixia Zhang 0001 |
Internet Measurement Conference | 1 |
| 2006 | Security Through Publicity
Eric Osterweil, Daniel Massey, Batsukh Tsendjav, Beichuan Zhang 0001, Lixia Zhang 0001 |
HotSec | 1 |
| 2004 | Lightweight Temporal Compression of Microclimate DatasetsabstractSince the inception of sensor networks, in-network processing has been touted as the enabling technology for long-lived deployments. Radio communication is the overriding consumer of energy in such networks. Therefore, data reduction before transmission, either by compression or feature extraction, will directly and significantly increase network lifetime. This paper evaluates a simple temporal compression scheme designed specifically to be used by mica motes for the compaction of microclimate data. The algorithm makes use of the observation that over a small enough window of time, samples of microclimate data are linear. It finds such windows and generates a series of line segments that accurately represent the data. It compresses data up to 20-to-1 while introducing errors in the order of the sensor hardware's specified margin of error. Furthermore, it is simple, consumes little CPU and requires very little storage when compared to other compression techniques. This paper describes the technique and results using a dataset from a one-year microclimate deployment. Thomas Schoellhammer, Eric Osterweil, Ben Greenstein, Mike Wimbrow, Deborah Estrin |
LCN | 2 |
| 2004 | A system for simulation, emulation, and deployment of heterogeneous sensor networksabstractRecently deployed Wireless Sensor Network systems (WSNs) are increasingly following heterogeneous designs, incorporating a mixture of elements with widely varying capabilities. The development and deployment of WSNs rides heavily on the availability of simulation, emulation, visualization and analysis support. In this work, we develop tools specifically to support heterogeneous systems, as well as to support the measurement and visualization of operational systems that is critical to addressing the inevitable problems that crop up in deployment. Our system differs from related systems in three key ways: in its ability to simulate and emulate heterogeneous systems in their entirety, in its extensive support for integration and interoperability between motes and microservers, and in its unified set of tools that capture, view, and analyze real time debugging information from simulations, emulations, and deployments. Lewis Girod, Thanos Stathopoulos, Nithya Ramanathan, Jeremy Elson, Deborah Estrin, Eric Osterweil, Thomas Schoellhammer |
SenSys | 6 |