EDBT 2026 Demo / reviewers in the wild / expert
Nicholas Weaver
dblp:53/2937
· DBLP profile ↗
42ranked-venue papers
9as first author
2since 2021 · last 2024
0000-0001-7004-5819ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 5 first-author · 1 since 2021Computer networks · 10Systems, architecture and hardware · 7 · 5 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
20 papers |
Network security · 59% Web and mobile security · 15% Malware analysis · 11% | |
| Computer networks
13 papers |
Internet architecture and protocols · 45% Network measurement and analytics · 36% Network management and operations · 9% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Electronic design automation · 36% Hardware accelerators and domain-specific architectures · 28% Reconfigurable computing and FPGAs · 24% |
Topics — the 30 heaviest of 64, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Internet architecture and protocols › domain name system
DNS security |
0.5 | 2 | 2017 | Global Measurement of DNS Manipulation · USENIX Security Symposium 2017 Practical Comprehensive Bounds on Surreptitious Communication over DNS · USENIX Security Symposium 2013 |
Network measurement and analytics › internet measurement
DNS measurement |
0.3 | 1 | 2017 | Global Measurement of DNS Manipulation · USENIX Security Symposium 2017 |
Network security
traffic analysis |
0.3 | 2 | 2015 | Beyond the Radio: Illuminating the Higher Layers of Mobile Networks · MobiSys 2015 A Tangled Mass: The Android Root Certificate Stores · CoNEXT 2014 |
Network measurement and analytics › internet measurement
deployment measurement |
0.2 | 1 | 2016 | A Multi-perspective Analysis of Carrier-Grade NAT Deployment · Internet Measurement Conference 2016 |
Internet architecture and protocols › world wide web › web protocols
HTTP |
0.2 | 1 | 2016 | Host of Troubles: Multiple Host Ambiguities in HTTP Implementations · CCS 2016 |
Internet architecture and protocols › middlebox
network address translation |
0.2 | 1 | 2016 | A Multi-perspective Analysis of Carrier-Grade NAT Deployment · Internet Measurement Conference 2016 |
Network security › protocol security › DNS security
cache poisoning |
0.2 | 1 | 2016 | Host of Troubles: Multiple Host Ambiguities in HTTP Implementations · CCS 2016 |
Network security
spam |
0.2 | 2 | 2011 | Show Me the Money: Characterizing Spam-advertised Revenue · USENIX Security Symposium 2011 Click Trajectories: End-to-End Analysis of the Spam Value Chain · IEEE Symposium on Security and Privacy 2011 |
Web and mobile security › web attacks
web cache poisoning |
0.2 | 1 | 2016 | Host of Troubles: Multiple Host Ambiguities in HTTP Implementations · CCS 2016 |
Internet architecture and protocols
domain name system |
0.2 | 2 | 2015 | Internet nameserver IPv4 and IPv6 address relationships · Internet Measurement Conference 2013 Temporal Lensing and Its Application in Pulsing Denial-of-Service Attacks · IEEE Symposium on Security and Privacy 2015 |
Network measurement and analytics
mobile network measurement |
0.2 | 1 | 2015 | Beyond the Radio: Illuminating the Higher Layers of Mobile Networks · MobiSys 2015 |
Network management and operations
network configuration |
0.2 | 1 | 2015 | Beyond the Radio: Illuminating the Higher Layers of Mobile Networks · MobiSys 2015 |
Network security › attack strategy › network reconnaissance
active probing |
0.2 | 1 | 2015 | Examining How the Great Firewall Discovers Hidden Circumvention Servers · Internet Measurement Conference 2015 |
Network security › attack strategy › denial-of-service attack
amplification attack |
0.2 | 1 | 2015 | Temporal Lensing and Its Application in Pulsing Denial-of-Service Attacks · IEEE Symposium on Security and Privacy 2015 |
Network security › anonymity networks
censorship circumvention |
0.2 | 1 | 2015 | Examining How the Great Firewall Discovers Hidden Circumvention Servers · Internet Measurement Conference 2015 |
Network security › attack strategy
denial-of-service attack |
0.2 | 1 | 2015 | Temporal Lensing and Its Application in Pulsing Denial-of-Service Attacks · IEEE Symposium on Security and Privacy 2015 |
Malware analysis › malware
cryptojacking |
0.2 | 1 | 2014 | Botcoin: Monetizing Stolen Cycles · NDSS 2014 |
Web and mobile security
mobile security |
0.2 | 1 | 2014 | A Tangled Mass: The Android Root Certificate Stores · CoNEXT 2014 |
Systems and software security
vulnerability discovery |
0.2 | 1 | 2014 | The Matter of Heartbleed · Internet Measurement Conference 2014 |
Systems and software security
vulnerability management |
0.2 | 1 | 2014 | The Matter of Heartbleed · Internet Measurement Conference 2014 |
Malware analysis › malware defense
containment |
0.2 | 2 | 2011 | GQ: practical containment for measuring modern malware systems · Internet Measurement Conference 2011 Very Fast Containment of Scanning Worms · USENIX Security Symposium 2004 |
Network security › intrusion detection and prevention
covert channel detection |
0.2 | 1 | 2013 | Practical Comprehensive Bounds on Surreptitious Communication over DNS · USENIX Security Symposium 2013 |
Internet of things and sensor networks › wireless sensor network › network diagnosis
network performance diagnosis |
0.1 | 1 | 2012 | Fathom: a browser-based network measurement platform · Internet Measurement Conference 2012 |
Malware analysis › botnet
botnet analysis |
0.1 | 1 | 2010 | Botnet Judo: Fighting Spam with Itself · NDSS 2010 |
Network security
spam mitigation |
0.1 | 1 | 2010 | Botnet Judo: Fighting Spam with Itself · NDSS 2010 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 2 | 2009 | Detecting Forged TCP Reset Packets · NDSS 2009 How to Own the Internet in Your Spare Time · USENIX Security Symposium 2002 |
Network security
intrusion detection and prevention |
0.1 | 2 | 2007 | Shunting: a hardware/software architecture for flexible, high-performance network intrusion prevention · CCS 2007 The shunt: an FPGA-based accelerator for network intrusion prevention · FPGA 2007 |
Hardware accelerators and domain-specific architectures › security accelerator
network security accelerator |
0.1 | 1 | 2007 | Shunting: a hardware/software architecture for flexible, high-performance network intrusion prevention · CCS 2007 |
Network measurement and analytics › internet measurement
censorship measurement |
0.1 | 1 | 2015 | Examining How the Great Firewall Discovers Hidden Circumvention Servers · Internet Measurement Conference 2015 |
Internet architecture and protocols › middlebox
great firewall |
0.1 | 1 | 2015 | Examining How the Great Firewall Discovers Hidden Circumvention Servers · Internet Measurement Conference 2015 |
Methods — techniques the papers use, named apart from their topics
protocol implementation testing · 0.5traffic analysis · 0.4temporal lensing · 0.4app-based measurement · 0.4information-theoretic bounds · 0.3large-scale measurement · 0.3measurement study · 0.3multi-perspective measurement · 0.2data analysis · 0.2dynamic analysis · 0.2passive measurement · 0.2active probing · 0.2PTR record analysis · 0.2web crawling · 0.1TCP reset packet detection · 0.1state tables · 0.1heavy-tailed traffic analysis · 0.1caching · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | WIP: Turtle VR: Virtual Reality Field Experience for Geological Engineering Education EnhancementabstractAt colleges and universities, majors ranging from geology and ecology to environmental and agricultural engineering rely on field experiences to train students in settings outside of the classroom. These field trips are not only costly, but they might also raise safety and accessibility issues for students and increase burdens on overworked faculty. This paper describes a virtual-reality (or VR) experience that utilizes an interactive narrative to meet student learning outcomes as an affordable complement to field trips. The Turtle VR experience was developed using Unity for Metaquest VR headsets. The experience consists of three modules that guide students through a real-life scenario of collecting and testing data related to the preservation of sea turtles. We conducted a user study to collect feedback from 34 students. Participants were asked their opinions on the VR environment, as well as completing pre- and post-intervention quizzes to assess learning outcomes. Concluding this study, the feedback was overall positive: results from the pre-and post-quizzes showed that 63% of users saw an increase in scores, indicating that students acquired new knowledge from the VR experience. Additionally, the post-survey revealed that approximately 87% of students enjoyed the experience, and a majority of them did not experience the common discomforts caused by VR (headache, nausea, dizziness). Moreover, 74% of users reported that they wanted to learn more about the subject. The study revealed that most students involved were pursuing STEM disciplines, primarily in computer science, highlighting Turtle VR's success in engaging students outside the field of geology with geological science. The results suggest that utilizing a narrative approach in VR learning experiences does not impede learning yet increases enjoyment. Narrative frameworks can be redesigned to cater towards other engineering students. With this VR application, engineering students would be able to get a more hands-on approach to the underlying fundamental concepts in field settings, instead of learning about it through standard lecture materials such as PowerPoint presentations. Since the results of the aforementioned study were overall positive, this VR application has the potential to improve education in geological engineering education. Skylar Harrison, Stephanie Sarambo, Nicholas Weaver, Kelly B. Lazar, Stephen Moysey |
FIE | 3 |
| 2021 | Cache Me Outside: A New Look at DNS Cache Probing
Arian Akhavan Niaki, William R. Marczak, Sahand Farhoodi, Andrew McGregor 0001, Phillipa Gill, Nicholas Weaver |
PAM | 6 |
| 2017 | Global Measurement of DNS Manipulation
Paul Pearce, Ben Jones, Frank Li 0001, Roya Ensafi, Nick Feamster, Nicholas Weaver, Vern Paxson |
USENIX Security Symposium | 6 |
| 2016 | Host of Troubles: Multiple Host Ambiguities in HTTP ImplementationsabstractThe Host header is a security-critical component in an HTTP request, as it is used as the basis for enforcing security and caching policies. While the current specification is generally clear on how host-related protocol fields should be parsed and interpreted, we find that the implementations are problematic. We tested a variety of widely deployed HTTP implementations and discover a wide range of non-compliant and inconsistent host processing behaviours. The particular problem is that when facing a carefully crafted HTTP request with ambiguous host fields (e.g., with multiple Host headers), two different HTTP implementations often accept and understand it differently when operating on the same request in sequence. We show a number of techniques to induce inconsistent interpretations of host between HTTP implementations and how the inconsistency leads to severe attacks such as HTTP cache poisoning and security policy bypass. The prevalence of the problem highlights the potential negative impact of gaps between the specifications and implementations of Internet protocols. Jianjun Chen 0005, Jian Jiang 0002, Hai-Xin Duan, Nicholas Weaver, Tao Wan 0004, Vern Paxson |
CCS | 4 |
| 2016 | A Multi-perspective Analysis of Carrier-Grade NAT Deployment
Philipp Richter, Florian Wohlfart, Narseo Vallina-Rodriguez, Mark Allman, Randy Bush, Anja Feldmann, Christian Kreibich, Nicholas Weaver, Vern Paxson |
Internet Measurement Conference | 8 |
| 2016 | Detecting DNS Root Manipulation
Ben Jones, Nick Feamster, Vern Paxson, Nicholas Weaver, Mark Allman |
PAM | 4 |
| 2015 | Examining How the Great Firewall Discovers Hidden Circumvention ServersabstractRecently, the operators of the national censorship infrastructure of China began to employ "active probing" to detect and block the use of privacy tools. This probing works by passively monitoring the network for suspicious traffic, then actively probing the corresponding servers, and blocking any that are determined to run circumvention servers such as Tor. Roya Ensafi, David Fifield, Philipp Winter, Nick Feamster, Nicholas Weaver, Vern Paxson |
Internet Measurement Conference | 5 |
| 2015 | Beyond the Radio: Illuminating the Higher Layers of Mobile NetworksabstractCellular network performance is often viewed as primarily dominated by the radio technology. However, reality proves more complex: mobile operators deploy and configure their networks in different ways, and sometimes establish network sharing agreements with other mobile carriers. Moreover, regulators have encouraged newer operational models such as Mobile Virtual Network Operators (MVNOs) to promote competition. In this paper we draw upon data collected by the ICSI Netalyzr app for Android to characterize how operational decisions, such as network configurations, business models, and relationships between operators introduce diversity in service quality and affect user security and privacy. We delve in detail beyond the radio link and into network configuration and business relationships in six countries. We identify the widespread use of transparent middleboxes such as HTTP and DNS proxies, analyzing how they actively modify user traffic, compromise user privacy, and potentially undermine user security. In addition, we identify network sharing agreements between operators, highlighting the implications of roaming and characterizing the properties of MVNOs, including that a majority are simply rebranded versions of major operators. More broadly, our findings highlight the importance of considering higher-layer relationships when seeking to analyze mobile traffic in a sound fashion. Narseo Vallina-Rodriguez, Srikanth Sundaresan, Christian Kreibich, Nicholas Weaver, Vern Paxson |
MobiSys | 4 |
| 2015 | Temporal Lensing and Its Application in Pulsing Denial-of-Service AttacksabstractWe introduce "temporal lensing": a technique that concentrates a relatively low-bandwidth flood into a short, high-bandwidth pulse. By leveraging existing DNS infrastructure, we experimentally explore lensing and the properties of the pulses it creates. We also empirically show how attackers can use lensing alone to achieve peak bandwidths more than an order of magnitude greater than their upload bandwidth. While formidable by itself in a pulsing DoS attack, attackers can also combine lensing with amplification to potentially produce pulses with peak bandwidths orders of magnitude larger than their own. Ryan Rasti, Mukul Murthy, Nicholas Weaver, Vern Paxson |
IEEE Symposium on Security and Privacy | 3 |
| 2015 | Cookies Lack Integrity: Real-World Implications
Jian Jiang 0002, Jinjin Liang, Hai-Xin Duan, Shuo Chen 0001, Tao Wan 0004, Nicholas Weaver |
USENIX Security Symposium | 7 |
| 2014 | A Tangled Mass: The Android Root Certificate StoresabstractThe security of today's Web rests in part on the set of X.509 certificate authorities trusted by each user's browser. Users generally do not themselves configure their browser's root store but instead rely upon decisions made by the suppliers of either the browsers or the devices upon which they run. In this work we explore the nature and implications of these trust decisions for Android users. Drawing upon datasets collected by Netalyzr for Android and ICSI's Certificate Notary, we characterize the certificate root store population present in mobile devices in the wild. Motivated by concerns that bloated root stores increase the attack surface of mobile users, we report on the interplay of certificate sets deployed by the device manufacturers, mobile operators, and the Android OS. We identify certificates installed exclusively by apps on rooted devices, thus breaking the audited and supervised root store model, and also discover use of TLS interception via HTTPS proxies employed by a market research company. Narseo Vallina-Rodriguez, Johanna Amann, Christian Kreibich, Nicholas Weaver, Vern Paxson |
CoNEXT | 4 |
| 2014 | The Matter of HeartbleedabstractThe Heartbleed vulnerability took the Internet by surprise in April 2014. The vulnerability, one of the most consequential since the advent of the commercial Internet, allowed attackers to remotely read protected memory from an estimated 24--55% of popular HTTPS sites. In this work, we perform a comprehensive, measurement-based analysis of the vulnerability's impact, including (1) tracking the vulnerable population, (2) monitoring patching behavior over time, (3) assessing the impact on the HTTPS certificate ecosystem, and (4) exposing real attacks that attempted to exploit the bug. Furthermore, we conduct a large-scale vulnerability notification experiment involving 150,000 hosts and observe a nearly 50% increase in patching by notified hosts. Drawing upon these analyses, we discuss what went well and what went poorly, in an effort to understand how the technical community can respond more effectively to such events in the future. Zakir Durumeric, James Kasten, David Adrian, J. Alex Halderman, Michael D. Bailey, Frank Li 0001, Nicholas Weaver, Johanna Amann, Jethro G. Beekman, Mathias Payer, Vern Paxson |
Internet Measurement Conference | 7 |
| 2014 | Botcoin: Monetizing Stolen Cycles
Danny Yuxing Huang, Hitesh Dharmdasani, Sarah Meiklejohn, Vacha Dave, Chris Grier, Damon McCoy, Stefan Savage, Nicholas Weaver, Alex C. Snoeren, Kirill Levchenko |
NDSS | 8 |
| 2014 | Here Be Web Proxies
Nicholas Weaver, Christian Kreibich, Martin Dam, Vern Paxson |
PAM | 1 |
| 2013 | Internet nameserver IPv4 and IPv6 address relationshipsabstractThe modern Domain Name System (DNS) provides not only resolution, but also enables intelligent client routing, e.g. for Content Distribution Networks (CDNs). The adoption of IPv6 presents CDNs the opportunity to utilize different paths when optimizing traffic, and the challenge of appropriately mapping IPv6 DNS queries. This work seeks to discover the associations between Internet DNS client resolver IPv6 address(es) and IPv4 address(es). We design and implement two new techniques, one passive and one active, to gather resolver pairings. The passive technique, deployed in Akamai's production DNS infrastructure, opportunistically discovered 674k (IPv4, IPv6) associated address pairs within a six-month period. We find that 34% of addresses are one-to-one, i.e. appear in no other pair, a fraction that increases to ~50% when aggregating IPv6 addresses into /64 prefixes. The one-to-one associations are suggestive, but not a sufficient condition, of dual-stack DNS recursive resolvers. We further substantiate our inferences via PTR records and software versions, and manual verification of sample pairings by three major Network Operators. Complex associations, where e.g. distributed DNS resolution leads to inferred address groupings that span continents and many autonomous systems exist, a subset of which we explore in more depth using the active probing technique. Among potential uses, Akamai is currently utilizing screened output from the passive technique, in conjunction with prior knowledge of IPv4, to inform IPv6 geolocation within its CDN. Arthur W. Berger, Nicholas Weaver, Robert Beverly, Larry Campbell |
Internet Measurement Conference | 2 |
| 2013 | Practical Comprehensive Bounds on Surreptitious Communication over DNS
Vern Paxson, Mihai Christodorescu, Mobin Javed, Josyula R. Rao, Reiner Sailer, Douglas Lee Schales, Marc Ph. Stoecklin, Kurt Thomas, Wietse Z. Venema, Nicholas Weaver |
USENIX Security Symposium | 10 |
| 2012 | Fathom: a browser-based network measurement platformabstractFor analyzing network performance issues, there can be great utility in having the capability to measure directly from the perspective of end systems. Because end systems do not provide any external programming interface to measurement functionality, obtaining this capability today generally requires installing a custom executable on the system, which can prove prohibitively expensive. In this work we leverage the ubiquity of web browsers to demonstrate the possibilities of browsers themselves offering such a programmable environment. We present Fathom, a Firefox extension that implements a number of measurement primitives that enable websites or other parties to program network measurements using JavaScript. Fathom is lightweight, imposing < 3.2% overhead in page load times for popular web pages, and often provides 1 ms timestamp accuracy. We demonstrate Fathom's utility with three case studies: providing a JavaScript version of the Netalyzr network characterization tool, debugging web access failures, and enabling web sites to diagnose performance problems of their clients. Mohan Dhawan, Justin Samuel, Renata Teixeira, Christian Kreibich, Mark Allman, Nicholas Weaver, Vern Paxson |
Internet Measurement Conference | 6 |
| 2012 | The BIZ Top-Level Domain: Ten Years Later
Tristan Halvorson, Janos Szurdi, Gregor Maier, Márk Félegyházi, Christian Kreibich, Nicholas Weaver, Kirill Levchenko, Vern Paxson |
PAM | 6 |
| 2012 | PharmaLeaks: Understanding the Business of Online Pharmaceutical Affiliate Programs
Damon McCoy, Andreas Pitsillidis, Grant Jordan, Nicholas Weaver, Christian Kreibich, Brian Krebs, Geoffrey M. Voelker, Stefan Savage, Kirill Levchenko |
USENIX Security Symposium | 4 |
| 2011 | GQ: practical containment for measuring modern malware systemsabstractMeasurement and analysis of modern malware systems such as botnets relies crucially on execution of specimens in a setting that enables them to communicate with other systems across the Internet. Ethical, legal, and technical constraints however demand containment of resulting network activity in order to prevent the malware from harming others while still ensuring that it exhibits its inherent behavior. Current best practices in this space are sorely lacking: measurement researchers often treat containment superficially, sometimes ignoring it altogether. In this paper we present GQ, a malware execution "farm" that uses explicit containment primitives to enable analysts to develop containment policies naturally, iteratively, and safely. We discuss GQ's architecture and implementation, our methodology for developing containment policies, and our experiences gathered from six years of development and operation of the system. Christian Kreibich, Nicholas Weaver, Chris Kanich, Weidong Cui, Vern Paxson |
Internet Measurement Conference | 2 |
| 2011 | Sherlock holmes' evil twin: on the impact of global inference for online privacyabstractUser-supplied content--in the form of photos, videos, and text--is a crucial ingredient to many web sites and services today. However, many users who provide content do not realize that their uploads may be leaking personal information in forms hard to intuitively grasp. Correlation of seemingly innocuous information can create inference chains that tell much more about individuals than they are aware of revealing. We contend that adversaries can systematically exploit such relationships by correlating information from different sources in what we term global inference attacks: assembling a comprehensive understanding from individual pieces found at a variety of locations, Sherlock-style. Not only are such attacks already technically viable given the capabilities that today's multimedia content analysis and correlation technologies readily provide, but we also find business models that provide adversaries with powerful incentives for pursuing them. Gerald Friedland, Gregor Maier, Robin Sommer, Nicholas Weaver |
NSPW | 4 |
| 2011 | Click Trajectories: End-to-End Analysis of the Spam Value ChainabstractSpam-based advertising is a business. While it has engendered both widespread antipathy and a multi-billion dollar anti-spam industry, it continues to exist because it fuels a profitable enterprise. We lack, however, a solid understanding of this enterprise's full structure, and thus most anti-Spam interventions focus on only one facet of the overall spam value chain (e.g., spam filtering, URL blacklisting, site takedown).In this paper we present a holistic analysis that quantifies the full set of resources employed to monetize spam email -- including naming, hosting, payment and fulfillment -- using extensive measurements of three months of diverse spam data, broad crawling of naming and hosting infrastructures, and over 100 purchases from spam-advertised sites. We relate these resources to the organizations who administer them and then use this data to characterize the relative prospects for defensive interventions at each link in the spam value chain. In particular, we provide the first strong evidence of payment bottlenecks in the spam value chain, 95% of spam-advertised pharmaceutical, replica and software products are monetized using merchant services from just a handful of banks. Kirill Levchenko, Andreas Pitsillidis, Neha Chachra, Brandon Enright, Márk Félegyházi, Chris Grier, Tristan Halvorson, Chris Kanich, Christian Kreibich, Damon McCoy, Nicholas Weaver, Vern Paxson, Geoffrey M. Voelker, Stefan Savage |
IEEE Symposium on Security and Privacy | 12 |
| 2011 | Show Me the Money: Characterizing Spam-advertised Revenue
Chris Kanich, Nicholas Weaver, Damon McCoy, Tristan Halvorson, Christian Kreibich, Kirill Levchenko, Vern Paxson, Geoffrey M. Voelker, Stefan Savage |
USENIX Security Symposium | 2 |
| 2010 | Netalyzr: illuminating the edge networkabstractIn this paper we present Netalyzr, a network measurement and debugging service that evaluates the functionality provided by people's Internet connectivity. The design aims to prove both comprehensive in terms of the properties we measure and easy to employ and understand for users with little technical background. We structure Netalyzr as a signed Java applet (which users access via their Web browser) that communicates with a suite of measurement-specific servers. Traffic between the two then probes for a diverse set of network properties, including outbound port filtering, hidden in-network HTTP caches, DNS manipulations, NAT behavior, path MTU issues, IPv6 support, and access-modem buffer capacity. In addition to reporting results to the user, Netalyzr also forms the foundation for an extensive measurement of edge-network properties. To this end, along with describing Netalyzr 's architecture and system implementation, we present a detailed study of 130,000 measurement sessions that the service has recorded since we made it publicly available in June 2009. Christian Kreibich, Nicholas Weaver, Boris Nechaev, Vern Paxson |
Internet Measurement Conference | 2 |
| 2010 | Botnet Judo: Fighting Spam with Itself
Andreas Pitsillidis, Kirill Levchenko, Christian Kreibich, Chris Kanich, Geoffrey M. Voelker, Vern Paxson, Nicholas Weaver, Stefan Savage |
NDSS | 7 |
| 2009 | Emµcode: Masking hard faults in complex functional unitsabstractThis paper presents Emmucode, a technique for masking hard faults in modern microprocessors that provides graceful performance degradation. Emmucode employs microcode traces with control flow that replace an original instruction once a fault is detected. Emmucode adds lightweight microarchitectural hardware to assist in correcting hard faults in larger structures, such as SIMD execution units found in contemporary microprocessors, where replication is infeasible. Key challenges in implementing microcode traces include maintaining proper architectural state and the optimization of trace code. We are able to significantly optimize traces by exploiting dynamic trace behavior and by performing minor modifications to the microarchitecture. We find that removing hard to predict branches is important for optimizing traces. Emmucode uses partial predication, new microcode operations, and the full use of the microcode's flexibility and visibility to create fast traces. This paper studies the viability of implementing SIMD floating point arithmetic operations found in modern x86 processors using Emmucode traces. Our results show that for programs with 1 to 5 percent of the dynamic instructions replaced by Emmucode, a graceful performance degradation of only 1.3times to 4times is achievable. Nicholas Weaver, John H. Kelm, Matthew I. Frank |
DSN | 1 |
| 2009 | Detecting Forged TCP Reset Packets
Nicholas Weaver, Robin Sommer, Vern Paxson |
NDSS | 1 |
| 2009 | Think Evil (tm)abstractNo abstract available. Nicholas Weaver |
SOUPS | 1 |
| 2009 | An architecture for exploiting multi-core processors to parallelize network intrusion preventionabstractAbstract It is becoming increasingly difficult to implement effective systems for preventing network attacks, due to the combination of the rising sophistication of attacks requiring more complex analyses to detect; the relentless growth in the volume of network traffic that we must analyze; and, critically, the failure in recent years for uniprocessor performance to sustain the exponential gains that for so many years CPUs have enjoyed. For commodity hardware, tomorrow's performance gains will instead come frommulti‐corearchitectures in which a whole set of CPUs executes concurrently. Taking advantage of the full power of multi‐core processors for network intrusion prevention requires an in‐depth approach. In this work we frame an architecture customized for parallel execution of network attack analysis. At the lowest layer of the architecture is an ‘Active Network Interface’, a custom device based on an inexpensive FPGA platform. The analysis itself is structured as an event‐based system, which allows us to find many opportunities for concurrent execution, since events introduce a natural asynchrony into the analysis while still maintaining good cache locality. A preliminary evaluation demonstrates the potential of this architecture. Copyright © 2009 John Wiley & Sons, Ltd. Robin Sommer, Vern Paxson, Nicholas Weaver |
Concurr. Comput. Pract. Exp. | 3 |
| 2008 | Principles for Developing Comprehensive Network Visibility
Mark Allman, Christian Kreibich, Vern Paxson, Robin Sommer, Nicholas Weaver |
HotSec | 5 |
| 2007 | Shunting: a hardware/software architecture for flexible, high-performance network intrusion preventionabstractStateful, in-depth, inline traffic analysis for intrusion detection and prevention is growing increasingly more difficult as the data rates of modern networks rise. Yet it remains the case that in many environments, much of the traffic comprising a high-volume stream can, after some initial analysis, be qualified as of "likely uninteresting." We present a combined hardware/software architecture, Shunting, that provides a lightweight mechanism for an intrusion prevention system (IPS) to take advantage of the "heavy-tailed" nature of network traffic to offload work from software to hardware. José M. González, Vern Paxson, Nicholas Weaver |
CCS | 3 |
| 2007 | The shunt: an FPGA-based accelerator for network intrusion preventionabstractThe sophistication and complexity of analysis performed by today's network intrusion prevention systems (IPSs) benefits greatly from implementation using general-purpose CPUs. Yet the performance of such CPUs increasingly lags behind that necessary to process today's high-rate traffic streams. A key observation, however, is that much of the traffic comprising a high-volume stream can, after some initial analysis, be qualified as "likely uninteresting." To this end, we have developed an in-line, FPGA-based IPS ac-celerator, the Shunt, using the NetFPGA2 platform. The Shunt functions as the forwarding device used by the IPS; it alone processes the bulk of the traffic, offloading the memory bus and leaving the CPU free to inspect the subset of the traffic deemed germane for security analysis. To do so, the Shunt maintains several large state tables indexed by packet header fields, including IP/TCP flags, source and destination IP addresses, and connection tuples. The tables yield decision values the element makes on a packet-by-packet basis: forward the packet, drop it, or divert it through the IPS. By manipulating table entries, the IPS can specify the traffic it wishes to examine, directly block malicious traffic, and "cut through" traffic streams once it has had an opportunity to "vet" them, all on a fine-grained basis. We base our design on a novel series of caches, with a "fail safe" miss policy, coupled to a host PC to handle both cache management and higher level IPS analysis. The design requires only 2 MB of SRAM for its extensive caches, and can sup-port four Gbps Ethernets on a single Virtex 2 Pro 30. Nicholas Weaver, Vern Paxson, José M. González |
FPGA | 1 |
| 2007 | The Strengths of Weaker Identities: Opportunistic Personas
Mark Allman, Christian Kreibich, Vern Paxson, Robin Sommer, Nicholas Weaver |
HotSec | 5 |
| 2006 | Protocol-Independent Adaptive Replay of Application Dialog
Weidong Cui, Vern Paxson, Nicholas Weaver, Randy H. Katz |
NDSS | 3 |
| 2006 | Rethinking Hardware Support for Network Analysis and Intrusion Prevention
Vern Paxson, Krste Asanovic, Sarang Dharmapurikar, John W. Lockwood, Ruoming Pang, Robin Sommer, Nicholas Weaver |
HotSec | 7 |
| 2005 | Exploiting Underlying Structure for Detailed Reconstruction of an Internet-scale Event
Abhishek Kumar 0003, Vern Paxson, Nicholas Weaver |
Internet Measurement Conference | 3 |
| 2004 | The SFRA: a corner-turn FPGA architectureabstractFPGAs normally operate at whatever clock rate is appropriate for the loaded configuration. When FPGAs are used as computational devices in a larger system, however, it is better to employ fixed-frequency FPGAs operating at a high clock frequency. Such fixed-frequency arrays require pipelined interconnect structures, which are difficult to support in a traditional FPGA architecture. We have developed a novel approach, called a interconnect, based on a Manhattan array of logically depopulated S-boxes with full connectivity but limited routability. This interconnect supports new polynomial-time routing techniques while maintaining conventional placement and other upstream toolflow. We have used the corner-turn interconnect to define a fixed-frequency FPGA architecture, the SFRA, that is largely compatible with the Xilinx Virtex while providing higher speed, pipelined operation. Our tools automatically repipeline designs to operate at the SFRA's intrinsic clock frequency. Since the arrays are largely compatible, we directly compare the SFRA with the Virtex on four benchmark designs. On these benchmarks, the SFRA offers higher throughput and competitive throughput per area. The SFRA routing and retiming tools also run one to two orders of magnitude faster than their Xilinx counterparts. Nicholas Weaver, John R. Hauser, John Wawrzynek |
FPGA | 1 |
| 2004 | Very Fast Containment of Scanning Worms
Nicholas Weaver, Stuart Staniford-Chen, Vern Paxson |
USENIX Security Symposium | 1 |
| 2003 | Post-placement C-slow retiming for the xilinx virtex FPGAabstractC-slow retiming is a process of automatically increasing the throughput of a design by enabling fine grained pipelining of problems with feedback loops. This transformation is especially appropriate when applied to FPGA designs because of the large number of available registers. To demonstrate and evaluate the benefits of C-slow retiming, we constructed an automatic tool which modifies designs targeting the Xilinx Virtex family of FPGAs. Applying our tool to three benchmarks: AES encryption, Smith/Waterman sequence matching, and the LEON 1 synthesized microprocessor core, we were able to substantially increase the total throughput. For some parameters, throughput is effectively doubled. Nicholas Weaver, Yury Markovsky, Yatish Patel, John Wawrzynek |
FPGA | 1 |
| 2002 | The Effects of Datapath Placement and C-Slow Retiming on Three Computational BenchmarksabstractSummary form only given. Two important optimizations within the FPGA design process, C-slow retiming and datapath placement, offer significant benefits for designers. Many have advocated and implemented tools to use these techniques in both automatic and semiautomatic manner but they have not made their way into conventional FPGA toolflows. C-slow retiming is a method of accelerating computations that include feedback loops. Instead of having a single instance of the computation, the feedback loop is pipelined so that C separate instances are all calculated simultaneously. This allows fine grained pipelining to occur even in designs that include feedback loops, such as single round cryptographic implementations or microprocessors. Done properly, it imposes a significant but not imposing latency penalty for single computations while offering huge increases in throughput. Datapath placement is simply constructing the design in a manner that accounts for the higher level data flows. This offers several benefits, including improved performance, more physically compact designs, shorter wires, and faster place and route times when the FPGA is heavily utilized. Even for designs with less structure which are amenable to simulated annealing, datapath placement may still offer a significant benefit. To clearly demonstrate the importance of these optimizations we have hand-modified three computational benchmarks which represent significant themes within FPGA computation: Rijndael/AES encryption, Smith/Waterman, and a simplified 32-bit microprocessor datapath. All three represent significantly different modes of computation within FPGAs, but all gain significantly from the use of these techniques. Nicholas Weaver, John Wawrzynek |
FCCM | 1 |
| 2002 | How to Own the Internet in Your Spare Time
Stuart Staniford-Chen, Vern Paxson, Nicholas Weaver |
USENIX Security Symposium | 3 |
| 1998 | Object Oriented Circuit-Generators in JavaabstractGenerators, parameterized code which produces a digital design, have long been a staple of the VLSI community. In recent years, several field programmable gate array (FPGA) design tools have adopted generators, as it is a convenient way to specify reusable designs in a familiar programming environment. We have built a generator framework in Java as a basis for programming reconfigurable devices and as a tool to be embedded in larger development systems. In addition to the conventional benefits of generators, this powerful framework allows for partial evaluation, simulation, specialization, and easy inclusion of other automatic services. In order to verify the utility of this system, we have implemented several applications using this framework and compared them with implementations using schematic capture and HDL synthesis. Our system runs significantly faster and produces comparable or superior results when mapped to a target FPGA. Michael Chu, Nicholas Weaver, Kolja Sulimma, André DeHon, John Wawrzynek |
FCCM | 2 |