Sebastian Zander

dblp:65/333 · DBLP profile ↗
← Back
26ranked-venue papers
15as first author
2since 2021 · last 2026
0000-0002-2084-7204ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 14 first-authorSecurity and privacy · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Beyond self-reporting: Uncovering the operational realities of SME cybersecurity through expert assessment
abstract
This study builds upon the foundational research of Chidukwani et al. (2022, 2024) to critically examine and validate cybersecurity assertions made by small and medium-sized enterprises (SMEs). Through a mixed-method multiple case study design, the research employed a comprehensive methodology to gain firsthand insights into SME cybersecurity postures. Central to this study is the introduction of the Validated Cybersecurity Posture Assessment Framework (VCPAF), a novel multi-layered methodology tailored to the SME context. VCPAF integrates self-reported assessments, expert-led interviews, technical vulnerability scanning, artifact and documentation review, and a triangulated scoring and gap analysis. This holistic and iterative approach enables a more accurate and context-sensitive validation of cybersecurity practices, bridging the gap between perceived and actual security postures. Fieldwork included site visits, inspections, direct observations, and in-depth interviews with key personnel to validate initial survey responses from Chidukwani et al. (2024). Benchmarking against the NIST Cybersecurity Framework (CSF), the study revealed significant disparities between SMEs’ self-reported cybersecurity practices and evidence from expert assessments. SMEs consistently overstated their cybersecurity maturity, often conflating IT support with cybersecurity services. Overestimations were particularly notable across the NIST CSF’s five core functions: Identify, Protect, Detect, Respond, and Recover with critical weaknesses identified in asset management, patch management, network security, access control, monitoring, and incident response. Additionally, misunderstandings regarding IT provider responsibilities and regulatory obligations were found to exacerbate vulnerabilities. We conclude that self-reporting alone is insufficient for accurately assessing SME cybersecurity posture. To close the gap between perceived and actual security practices, independent validation and tailored frameworks are critical. We advocate for sector-specific adaptations of established standards, transparent service provider agreements, and mandatory employee training. Additionally, introducing an industry standardised terminology and taxonomy similar to those used in healthcare insurance would simplify service offerings, and improve SME understanding of cybersecurity responsibilities.
Alladean Chidukwani, Sebastian Zander, Polychronis Koutsakis
Comput. Secur.2
2024 Cybersecurity preparedness of small-to-medium businesses: A Western Australia study with broader implications
abstract
This study was prompted by the scarcity of focused quantitative research on the cybersecurity of SMBs. Our research aimed to understand the factors influencing SMBs' approach to cybersecurity, their level of threat awareness and the importance placed on cybersecurity. It also explored the extent to which NIST CSF practices are implemented by SMBs while also detecting and ranking the prevalent challenges faced by SMBs. Additionally, resources that SMBs turn to for help and guidance were also evaluated. While the survey-based study was on Western Australian SMBs, the results are of more general and wider interest. Our study found the lack of funds to be the biggest hindrance to cybersecurity, along with a lack of knowledge on where to start implementing good security practices. SMBs also lacked familiarity with relevant regulations and frameworks. The study highlights areas for improvement, such as access control mechanisms, individual user accounts, formalised policies and procedures, and dedicated budgets. SMBs heavily rely on Google search for cybersecurity information, emphasising the need for optimised search results from authoritative sources. IT service providers and informal networks also emerge as important sources of cybersecurity guidance, while local universities could assist SMBs but remain underutilised in this regard. Interestingly, factors such as organisational size, industry sector, and revenue level did not significantly impact SMBs' perception of vulnerability to cyber threats. However, further investigation is needed to evaluate the effectiveness of different IT service models for SMBs' cybersecurity needs. Overall, the research provides valuable insights into the specific gaps and challenges faced by SMBs in the cybersecurity domain, as well as their preferred methods of seeking and consuming cybersecurity assistance. The findings can guide the development of targeted strategies and policies to enhance the cybersecurity posture of SMBs.
Alladean Chidukwani, Sebastian Zander, Polychronis Koutsakis
Comput. Secur.2
2018 Extending the model of internet standards adoption: A cross-country comparison of IPv6 adoption
Xuequn Wang, Sebastian Zander
Inf. Manag.2
2018 Emerging and Unconventional: New Attacks and Innovative Detection Techniques
abstract
Art. 9672523, 1 S.
Luca Caviglione, Wojciech Mazurczyk, Steffen Wendzel, Sebastian Zander
Secur. Commun. Networks4
2018 Are We There Yet? IPv6 in Australia and China
abstract
IP (Internet Protocol) version 6 (IPv6) was standardised in 1998 to address the expected runout of IP version 4 (IPv4) addresses. However, the transition from IPv4 to IPv6 has been very slow in many countries. We investigate the state of IPv6 deployment in Australian and Chinese organisations based on a survey of organisations’ IT staff. Compared to earlier studies, IPv6 deployment has advanced markedly, but it is still years away for a significant portion of organisations. We provide insights into the deployment problems, arguments for deploying IPv6, and how to speed up the transition, which are relevant for many countries.
Sebastian Zander, Xuequn Wang
ACM Trans. Internet Techn.1
2017 An analysis of changing enterprise network traffic characteristics
abstract
Studies on the composition and nature of Internet protocols are crucial for continued research and innovation. This study used three different methods to investigate the presence and level of support for various Internet protocols. Internet traffic entering and exiting a university network was passively captured, anonymised and analysed to test protocol usage. Active tests probed the Internet's most popular websites and experiments on the default behaviour of popular client, server and mobile operating systems were performed to reconcile the findings of the passive data collection. These results are valuable to research areas, such as those using emulations and simulations, where realism is dependent on the accuracy of the underlying assumptions about Internet traffic. Prior work is leveraged to explore changes and protocol adoption trends. This study shows that the majority of Internet traffic is now encrypted. There has also been an increase in large UDP frames, which we attribute to the Google QUIC protocol. Support for TCP options such as Selective Acknowledgements (SACK) and Maximum Segment Size (MSS) can now be assumed. Explicit Congestion Notification (ECN) usage is still marginal, yet active measurement shows that many servers will support the protocol if requested. Recent IETF standards such as Multipath TCP and TCP Fast Open have small but measurable levels of adoption.
David Murray, Terry Koziniec, Sebastian Zander, Michael W. Dixon, Polychronis Koutsakis
APCC3
2017 Experimental evaluation of less-than-best-effort TCP over 802.11 wireless networks
Kevin Ong, Sebastian Zander, David Murray, Tanya Jane McGill
APCC2
2017 Experimental Evaluation of Less-Than-Best-Effort TCP Congestion Control Mechanisms
abstract
Increasing use of online backup services, as well as the popularity of user-generated content, has increased the demand for bandwidth. However, traffic generated by these applications can impact on the responsiveness of delay-sensitive applications if they receive a 'fair-share' of the available bandwidth. Less-than-Best-Effort TCP congestion control mechanisms aim to allow lower-priority applications to utilise excess bandwidth with minimum impact to regular TCP traffic. We evaluated the performance of six Less-than-Best-Effort congestion control algorithms in different scenarios in a Linux testbed, only three of which had existing implementations for modern operating systems. The findings of this study suggest that Nice provides background throughput comparable to that of regular TCP, while maintaining low queuing delay, while CAIA Delay-Gradient (CDG) has the least impact on regular TCP traffic, at the expense of reduced throughput.
Kevin Ong, Sebastian Zander, David Murray, Tanya Jane McGill
LCN2
2017 Detecting Covert Channels in FPS Online Games
abstract
Encryption is often not sufficient to secure communication, since it does not hide that communication takes place or who is communicating with whom. Covert channels hide the very existence of communication enabling individuals to communicate secretly. Previous work proposed a covert channel hidden inside multi-player first person shooter online game traffic (FPSCC). FPSCC has a low bit rate, but it is practically impossible to eliminate other than by blocking the overt game traffic. This paper shows that with knowledge of the channel's encoding and using machine learning techniques, FPSCC can be detected with an accuracy of 95% or higher.
Sebastian Zander
LCN1
2017 Share or Not: Investigating the Presence of Large-Scale Address Sharing in the Internet
abstract
Network Address Translation (NAT) allows multiple devices with private addresses to share one public address. NAT was mainly confined to home gateways, but with the exhaustion of the IPv4 address space, large-scale NATs have been deployed. Other technologies causing large-scale address sharing are on the rise as well (e.g. VPNs). Large-scale address sharing is problematic, since it limits the number of concurrent TCP connections and severely limits geolocation and geoblocking. We investigate the presence of large-scale address sharing in the Internet, including how frequently it occurs, in which types of organisations it occurs, where it occurs geographically, how many users share addresses, and whether its presence is linked to IPv4 address shortage. Our results show that there are thousands of addresses with significant large-scale sharing with up to a few thousand users sharing a single address. Most of this sharing occurs within ISPs, many of which are located in countries with IPv4 address shortage, indicating that large-scale NATs may be a consequence of IPv4 shortages.
Sebastian Zander, David Murray
LCN1
2017 Collaborative and privacy-preserving estimation of IP address space utilisation
Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage
Comput. Networks1
2014 Capturing ghosts: predicting the used IPv4 space by inferring unobserved addresses
abstract
The pool of unused routable IPv4 prefixes is dwindling, with less than 4% remaining for allocation at the end of June 2014. Yet the adoption of IPv6 remains slow. We demonstrate a new capture-recapture technique for improved estimation of the size of "IPv4 reserves" (allocated yet unused IPv4 addresses or routable prefixes) from multiple incomplete data sources. A key contribution of our approach is the plausible estimation of both observed and unobserved-yet-active (ghost) IPv4 address space. This significantly improves our community's understanding of IPv4 address space exhaustion and likely pressure for IPv6 adoption. Using "ping scans", network traces and server logs we estimate that 6.3 million /24 subnets and 1.2 billion IPv4 addresses are currently in use (roughly 60% and 45% of the publicly routed space respectively). We also show how utilisation has changed over the last 2--3 years and provide an up-to-date estimate of potentially-usable remaining IPv4 space.
Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage
Internet Measurement Conference1
2013 Minimally-intrusive frequent round trip time measurements using Synthetic Packet-Pairs
abstract
Accurate and frequent round trip time (RTT) measurements are important in testbeds and operational networks. Active measurement techniques inject probe packets that may modify the behaviour of the observed network and may produce misleading RTT estimates if the network handles probe packets differently to regular packets. Previous passive measurement techniques address these issues, but require precise time synchronisation or are limited to certain traffic types. We introduce Synthetic Packet-Pairs (SPP), a novel passive technique for RTT measurement. SPP provides frequently updated RTT measurements using any network traffic already present in the network without the need for time synchronisation. SPP accurately measures the RTT experienced by any application's traffic, even applications that do not exhibit symmetric client-server packet exchanges. We experimentally demonstrate the advantages of SPP.
Sebastian Zander, Grenville J. Armitage
LCN1
2012 Mitigating sampling error when measuring internet client IPv6 capabilities
abstract
Despite the predicted exhaustion of unallocated IPv4 addresses between 2012 and 2014, it remains unclear how many current clients can use its successor, IPv6, to access the Internet. We propose a refinement of previous measurement studies that mitigates intrinsic measurement biases, and demonstrate a novel web-based technique using Google ads to perform IPv6 capability testing on a wider range of clients. After applying our sampling error reduction, we find that 6% of world-wide connections are from IPv6-capable clients, but only 1--2% of connections preferred IPv6 in dual-stack (dual-stack failure rates less than 1%). Except for an uptick around IPv6-day 2011 these proportions were relatively constant, while the percentage of connections with IPv6-capable DNS resolvers has increased to nearly 60%. The percentage of connections from clients with native IPv6 using happy eyeballs has risen to over 20%.
Sebastian Zander, Lachlan L. H. Andrew, Grenville J. Armitage, Geoff Huston, George Michaelson
Internet Measurement Conference1
2012 Detecting protocol switching covert channels
abstract
Network covert channels enable hidden communication and can be used to break security policies. Within the last years, new techniques for such covert channels arose, including protocol switching covert channels (PSCCs). PSCCs transfer hidden information by sending network packets with different selected network protocols. In this paper we present the first detection methods for PSCCs. We show that the number of packets between network protocol switches and the time between switches can be monitored to detect PSCCs with 98-99% accuracy for bit rates of 4 bits/second or higher.
Steffen Wendzel, Sebastian Zander
LCN2
2012 Sub-flow packet sampling for scalable ML classification of interactive traffic
abstract
Machine Learning (ML) classifiers have been shown to provide accurate, timely and continuous IP flow classification when evaluating sub-flows (short moving windows of packets within flows). They can be used to provide automated QoS management for interactive traffic, such as fast-paced multiplayer games or VoIP. As with other ML classification approaches, previous sub-flow techniques have assumed all packets in all flows are being observed and evaluated. This limits scalability and poses a problem for practical deployment in network core or edge routers. In this paper we propose and evaluate subflow packet sampling (SPS) to reduce an ML sub-flow classifier's resource requirements with minimal compromise of accuracy. While random packet sampling increases classification time from <;1 second to over 30 seconds and can reduce accuracy from 98% to <;90%, our tailored SPS technique retains classification times of <;1 second while providing 98% accuracy.
Sebastian Zander, Thuy T. T. Nguyen, Grenville J. Armitage
LCN1
2012 Timely and continuous machine-learning-based classification for interactive IP traffic
abstract
Machine Learning (ML) for classifying IP traffic has relied on the analysis of statistics of full flows or their first few packets only. However, automated QoS management for interactive traffic flows requires quick and timely classification well before the flows finish. Also, interactive flows are often long-lived and should be continuously monitored during their lifetime. We propose to achieve this by using statistics derived from sub-flows—a small number of most recent packets taken at any point in a flow's lifetime. Then, the ML classifier must be trained on a set of sub-flows, and we investigate different sub-flow selection strategies. We also propose to augment training datasets so that classification accuracy is maintained even when a classifier mixes up client-to-server and server-to-client directions for applications exhibiting asymmetric traffic characteristics. We demonstrate the effectiveness of our approach with the Naive Bayes and C4.5 Decision Tree ML algorithms, for the identification of first-person-shooter online game and VoIP traffic. Our results show that we can classify both applications with up to 99% Precision and 95% Recall within less than 1 s. Stable results are achieved regardless of where within a flow the classifier captures the packets and the traffic direction.
Thuy T. T. Nguyen, Grenville J. Armitage, Philip Branch, Sebastian Zander
IEEE/ACM Trans. Netw.4
2011 Practical machine learning based multimedia traffic classification for distributed QoS management
abstract
A multi-service Internet requires routers to recognise and prioritise IP flows carrying interactive or multimedia traffic. It is increasingly problematic for legal or administrative reasons to recognise such flows using unique port numbers or deep packet inspection. New work in recent years shows that Machine Learning (ML) techniques can use externally observable statistical characteristics to usefully differentiate such IP traffic. However, most previous work has not addressed the practicality of ML-based traffic classification in terms of CPU and memory usage. Here we describe our design, implementation and performance evaluation of a distributed, ML-based traffic classification and control system for FreeBSD's IP Firewall (IPFW). On an Intel Core i7 2.8 GHz PC our system can classify up to 400 000 packets per second using only one core and our system scales well to up to 100 000 simultaneous flows. Also our implementation allows one classifier PC to control subsequent traffic shaping or blocking at multiple (potentially lower performance) routers or gateways distributed around the network.
Sebastian Zander, Grenville J. Armitage
LCN1
2011 Stealthier Inter-packet Timing Covert Channels
Sebastian Zander, Grenville J. Armitage, Philip Branch
Networking (1)1
2009 Reliable transmission over covert channels in first person shooter multiplayer games
abstract
We propose and evaluate a novel improvement to a previously published, unreliable covert channel based on the network traffic of multiplayer, first person shooter online games (FPSCC). Covert channels typically embed themselves within pre-existing (overt) data transmissions in order to carry hidden messages. FPSCC encodes covert bits as slight, yet continuous, variations of a player's character's movements. These variations are visually imperceptible to human players, yet occur frequently enough to create a low bit-rate covert channel. The nature of first person shooter network protocols means the original FPSCC channel is noisy (not reliable), experiencing a significant number of bit errors (including synchronisation errors). We have now augmented FPSCC to ensure bits are transmitted reliably. Evaluation of our technique with a prototype demonstrates throughput of up to 13 bits/second without any bit errors.
Sebastian Zander, Grenville J. Armitage, Philip Branch
LCN1
2008 Covert channels in multiplayer first person shooter online games
abstract
Covert channels aim to hide the existence of communication between two or more parties. Such channels typically utilise pre-existing (overt) data transmissions to carry hidden messages. Internet-based covert channels often encode new information into unused (or loosely specified) IP packet header fields, or the time intervals between IP packet arrivals. We propose a novel covert channel embedded within the traffic of multiplayer, first person shooter online games. We encode covert bits as slight, yet continuous, variations of a playerpsilas characterpsilas movements. Movement information is propagated to all clients attached to a given game server, yet the channel remains covert so long as the variations are visually imperceptible to the human players. A modified version of Quake III Arena is used to demonstrate our concept. We empirically analyse the covert channelpsilas bit rate, and compare the statistical characteristics of unmodified game traffic with those of game traffic carrying covert information.
Sebastian Zander, Grenville J. Armitage, Philip Branch
LCN1
2008 An Improved Clock-skew Measurement Technique for Revealing Hidden Services
Sebastian Zander, Steven J. Murdoch
USENIX Security Symposium1
2005 Automated Traffic Classification and Application Identification using Machine Learning
abstract
The dynamic classification and identification of network applications responsible for network traffic flows offers substantial benefits to a number of key areas in IP network engineering, management and surveillance. Currently such classifications rely on selected packet header fields (e.g. port numbers) or application layer protocol decoding. These methods have a number of shortfalls e.g. many applications can use unpredictable port numbers and protocol decoding requires a high amount of computing resources or is simply infeasible in case protocols are unknown or encrypted. We propose a novel method for traffic classification and application identification using an unsupervised machine learning technique. Flows are automatically classified based on statistical flow characteristics. We evaluate the efficiency of our approach using data from several traffic traces collected at different locations of the Internet. We use feature selection to find an optimal feature set and determine the influence of different features
Sebastian Zander, Thuy T. T. Nguyen, Grenville J. Armitage
LCN1
2005 A traffic model for the Xbox game Halo 2
abstract
This paper analyses the traffic characteristics of, and proposes a traffic model for, the Xbox game Halo 2. Our goal is to help players and network providers to estimate the amount of traffic caused by the game and the impact on access links or provider networks. It also enables other researchers to use a realistic Halo 2 traffic model in network simulations. We focus on the following characteristics: bandwidth, packet rate and distribution of packet inter-arrival times and packet lengths. We compare the results with a previous analysis of Halo 1 and find some major differences - the client packet rate has been reduced, packet sizes have no longer a single fixed value per game and the mean packet size has decreased (so Halo 2 requires less bandwidth). Finally we develop traffic simulation models for Halo 2 and compare them against the experimentally obtained data.
Sebastian Zander, Grenville J. Armitage
NOSSDAV1
2005 The 'pure-IP' Moby Dick 4G architecture
Jürgen Jähnert, Rui L. Aguiar, Victor Marques 0001, Michelle Wetterwald, Eric Melin, José Ignacio Moreno, Antonio Cuevas, Marco Liebsch, Ralf Schmitz, Piotr Pacyna, Telemaco Melia, Pascal Kurtansky, Hasan, Davinder Singh, Sebastian Zander, Hans Joachim Einsiedler, Burkhard Stiller
Comput. Commun.16
2004 Extensions of AAA for future IP networks
abstract
The design of an extended and generic authentication, authorization, accounting, and charging architecture (AAAC Arch.) has been performed within the IST project MobyDick. In addition, this architecture has been implemented to address MobyDick's main objective: to facilitate the deployment of a ubiquitous mobile IPv6-based, quality-of-service (QoS)-aware infrastructure through a flexible and evolutionary AAAC Architecture. While the AAAC Arch. is based on the DIAMETER protocol, basic concepts developed cover session and services models, user profiles to allow for user mobility and QoS-aware authorization. Based on those basic building blocks for the extended AAAC Arch., the implementation of user registration, service authorization, metering, accounting, charging, and auditing is discussed. The paper closes with the presentation of the two trial sites used and their testbeds.
Pascal Kurtansky, Hasan, Burkhard Stiller, Antonio Cuevas, Davinder Singh, Sebastian Zander, Jürgen Jähnert
WCNC6