EDBT 2026 Demo / reviewers in the wild / expert
Derek Leonard
dblp:77/2734
· DBLP profile ↗
19ranked-venue papers
8as first author
0since 2021 · last 2016
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 7 first-authorSystems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
10 papers |
Network measurement and analytics · 63% Internet of things and sensor networks · 16% Network performance modeling · 10% | |
| Computer architecture, parallel and distributed computing, and storage systems
9 papers |
Distributed systems · 84% Performance modeling and evaluation · 16% | |
| Network and information security
5 papers |
Network security · 88% Systems and software security · 12% |
Topics — the 27 heaviest of 31, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Distributed systems
peer-to-peer systems |
0.5 | 7 | 2009 | Node isolation model and age-based neighbor selection in unstructured P2P networks · IEEE/ACM Trans. Netw. 2009 On static and dynamic partitioning behavior of large-scale P2P networks · IEEE/ACM Trans. Netw. 2008 On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networks · IEEE/ACM Trans. Netw. 2007 |
Network measurement and analytics › device fingerprinting
OS fingerprinting |
0.4 | 2 | 2016 | Hershel: Single-Packet OS Fingerprinting · IEEE/ACM Trans. Netw. 2016 Hershel: single-packet os fingerprinting · SIGMETRICS 2014 |
Network measurement and analytics › active measurement
internet-wide scanning |
0.4 | 3 | 2013 | Demystifying Internet-Wide Service Discovery · IEEE/ACM Trans. Netw. 2013 Stochastic analysis of horizontal IP scanning · INFOCOM 2012 Demystifying service discovery: implementing an internet-wide scanner · Internet Measurement Conference 2010 |
Internet of things and sensor networks
service discovery |
0.3 | 2 | 2013 | Demystifying Internet-Wide Service Discovery · IEEE/ACM Trans. Netw. 2013 Demystifying service discovery: implementing an internet-wide scanner · Internet Measurement Conference 2010 |
Network security
traffic analysis |
0.2 | 1 | 2014 | Hershel: single-packet os fingerprinting · SIGMETRICS 2014 |
Network security
network scanning |
0.2 | 1 | 2013 | Demystifying Internet-Wide Service Discovery · IEEE/ACM Trans. Netw. 2013 |
Network security › intrusion detection and prevention
intrusion detection |
0.1 | 1 | 2012 | Stochastic analysis of horizontal IP scanning · INFOCOM 2012 |
Network security › intrusion detection and prevention › intrusion detection › attack detection
scan detection |
0.1 | 1 | 2012 | Stochastic analysis of horizontal IP scanning · INFOCOM 2012 |
Systems and software security
vulnerability discovery |
0.1 | 1 | 2010 | Demystifying service discovery: implementing an internet-wide scanner · Internet Measurement Conference 2010 |
Network measurement and analytics › latency measurement
end-to-end delay estimation |
0.1 | 1 | 2008 | Turbo King: Framework for Large-Scale Internet Delay Measurements · INFOCOM 2008 |
Network measurement and analytics
latency measurement |
0.1 | 1 | 2008 | Turbo King: Framework for Large-Scale Internet Delay Measurements · INFOCOM 2008 |
Network measurement and analytics
web crawling |
0.1 | 1 | 2008 | IRLbot: scaling to 6 billion pages and beyond · WWW 2008 |
Distributed systems › fault tolerance › failure models
network partitioning |
0.1 | 1 | 2008 | On static and dynamic partitioning behavior of large-scale P2P networks · IEEE/ACM Trans. Netw. 2008 |
Performance modeling and evaluation
workload characterization |
0.1 | 1 | 2008 | IRLbot: scaling to 6 billion pages and beyond · WWW 2008 |
Distributed systems
fault tolerance |
0.1 | 2 | 2006 | Modeling Heterogeneous User Churn and Local Resilience of Unstructured P2P Networks · ICNP 2006 On Static and Dynamic Partitioning Behavior of Large-Scale Networks · ICNP 2005 |
Network security › network scanning
internet-wide scanning |
0.1 | 1 | 2016 | Hershel: Single-Packet OS Fingerprinting · IEEE/ACM Trans. Netw. 2016 |
Distributed systems › peer-to-peer systems
churn |
0.1 | 1 | 2007 | On Node Isolation Under Churn in Unstructured P2P Networks with Heavy-Tailed Lifetimes · INFOCOM 2007 |
Distributed systems › fault tolerance › resilience
node failure resilience |
0.1 | 1 | 2007 | On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networks · IEEE/ACM Trans. Netw. 2007 |
Network optimization and economics › fairness
max-min fairness |
0.1 | 1 | 2006 | JetMax: Scalable Max-Min Congestion Control for High-Speed Heterogeneous Networks · INFOCOM 2006 |
Performance modeling and evaluation › statistical analysis
statistical modeling |
0.1 | 1 | 2014 | Hershel: single-packet os fingerprinting · SIGMETRICS 2014 |
Distributed systems › peer-to-peer systems › churn
churn resilience |
0.1 | 1 | 2005 | On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networks · SIGMETRICS 2005 |
Distributed systems
network connectivity |
0.1 | 1 | 2005 | On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networks · SIGMETRICS 2005 |
Distributed systems › fault tolerance › resilience
network resilience |
0.1 | 1 | 2005 | On Static and Dynamic Partitioning Behavior of Large-Scale Networks · ICNP 2005 |
Graph algorithms and graph theory
graph connectivity |
0.1 | 1 | 2005 | On Static and Dynamic Partitioning Behavior of Large-Scale Networks · ICNP 2005 |
Combinatorics and discrete mathematics › probabilistic combinatorics
random graph theory |
0.1 | 1 | 2005 | On Static and Dynamic Partitioning Behavior of Large-Scale Networks · ICNP 2005 |
Performance modeling and evaluation
analytical modeling |
0.0 | 1 | 2006 | Modeling Heterogeneous User Churn and Local Resilience of Unstructured P2P Networks · ICNP 2006 |
Distributed systems › fault tolerance
node failure |
0.0 | 1 | 2005 | On Static and Dynamic Partitioning Behavior of Large-Scale Networks · ICNP 2005 |
Methods — techniques the papers use, named apart from their topics
stochastic modeling · 1.5classification · 1.1internet-wide scanning · 0.6OS fingerprinting · 0.5ACK scanning · 0.5analytical modeling · 0.5chen-stein theorem · 0.3per-host rate limiting · 0.2breadth-first search · 0.2random graph theory · 0.2closed-form analysis · 0.1DNS-based measurement · 0.1random walk · 0.1degree distribution analysis · 0.1simulation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Hershel: Single-Packet OS FingerprintingabstractTraditional TCP/IP fingerprinting tools (e.g., nmap) are poorly suited for Internet-wide use due to the large amount of traffic and intrusive nature of the probes. This can be overcome by approaches that rely on a single SYN packet to elicit a vector of features from the remote server. However, these methods face difficult classification problems due to the high volatility of the features and severely limited amounts of information contained therein. Since these techniques have not been studied before, we first pioneer stochastic theory of single-packet OS fingerprinting, build a database of 116 OSs, design a classifier based on our models, evaluate its accuracy in simulations, and then perform OS classification of 37.8M hosts from an Internet-wide scan. Zain Shamsi, Ankur Nandwani, Derek Leonard, Dmitri Loguinov |
IEEE/ACM Trans. Netw. | 3 |
| 2014 | Hershel: single-packet os fingerprintingabstractTraditional TCP/IP fingerprinting tools (e.g., nmap) are poorly suited for Internet-wide use due to the large amount of traffic and intrusive nature of the probes. This can be overcome by approaches that rely on a single SYN packet to elicit a vector of features from the remote server; however, these methods face difficult classification problems due to the high volatility of the features and severely limited amounts of information contained therein. Since these techniques have not been studied before, we first pioneer stochastic theory of single-packet OS fingerprinting, build a database of 116 OSes, design a classifier based on our models, evaluate its accuracy in simulations, and then perform OS classification of 37.8M hosts from an Internet-wide scan. Zain Shamsi, Ankur Nandwani, Derek Leonard, Dmitri Loguinov |
SIGMETRICS | 3 |
| 2013 | Demystifying Internet-Wide Service DiscoveryabstractThis paper develops a high-performance, Internet-wide service discovery tool, which we call IRLscanner, whose main design objectives have been to maximize politeness at remote networks, allow scanning rates that achieve coverage of the Internet in minutes/hours (rather than weeks/months), and significantly reduce administrator complaints. Using IRLscanner and 24-h scans, we perform 21 Internet-wide experiments using six different protocols (i.e., DNS, HTTP, SMTP, EPMAP, ICMP, and UDP ECHO), demonstrate the usefulness of ACK scans in detecting live hosts behind stateless firewalls, and undertake the first Internet-wide OS fingerprinting. In addition, we analyze the feedback generated (e.g., complaints, IDS alarms) and suggest novel approaches for reducing the amount of blowback during similar studies, which should enable researchers to collect valuable experimental data in the future with significantly fewer hurdles. Derek Leonard, Dmitri Loguinov |
IEEE/ACM Trans. Netw. | 1 |
| 2012 | Stochastic analysis of horizontal IP scanningabstractIntrusion Detection Systems (IDS) have become ubiquitous in the defense against virus outbreaks, malicious exploits of OS vulnerabilities, and botnet proliferation. As attackers frequently rely on host scanning for reconnaissance leading to penetration, IDS is often tasked with detecting scans and preventing them. However, it is currently unknown how likely an IDS is to detect a given Internet-wide scan pattern and whether there exist sufficiently fast scan techniques that can remain virtually undetectable at large-scale. To address these questions, we propose a simple analytical model for the window-expiration rules of popular IDS tools (i.e., Snort and Bro) and utilize a variation of the Chen-Stein theorem to derive the probability that they detect some of the commonly used scan permutations. Using this analysis, we also prove the existence of stealth-optimal scan patterns, examine their performance, and contrast it with that of well-known techniques. Derek Leonard, Zhongmei Yao, Xiaoming Wang 0002, Dmitri Loguinov |
INFOCOM | 1 |
| 2010 | Demystifying service discovery: implementing an internet-wide scannerabstractThis paper develops a high-performance, Internet-wide service discovery tool, which we call IRLscanner, whose main design objectives have been to maximize politeness at remote networks, allow scanning rates that achieve coverage of the Internet in minutes/hours (rather than weeks/months), and significantly reduce administrator complaints. Using IRLscanner and 24-hour scans, we perform 21 Internet-wide experiments using 6 different protocols (i.e., DNS, HTTP, SMTP, EPMAP, ICMP and UDP ECHO), demonstrate the usefulness of ACK scans in detecting live hosts behind stateless firewalls, and undertake the first Internet-wide OS fingerprinting. In addition, we analyze the feedback generated (e.g., complaints, IDS alarms) and suggest novel approaches for reducing the amount of blowback during similar studies, which should enable researchers to collect valuable experimental data in the future with significantly fewer hurdles. Derek Leonard, Dmitri Loguinov |
Internet Measurement Conference | 1 |
| 2009 | Optimizing Capacity-Heterogeneous Unstructured P2P Networks for Random-Walk TrafficabstractExisting algorithms for utilizing high-capacity nodes in heterogeneous P2P systems (e.g.) often require unrealistically large node degree and high maintenance overhead in P2P networks with highly diverse node capacities and high churn. In this paper, we propose an unstructured P2P system that addresses these issues. We first prove that the overall throughput of search queries in a heterogeneous network is maximized if and only if traffic load through each node is proportional to its capacity. We then propose a system that achieves this traffic distribution by biasing search walks using the Metropolis-Hastings algorithm without requiring any special underlying topology. We finish the paper by comparing our method with Gia, where we find in simulation that the former outperforms the latter under all studied conditions, two novel saturation metrics introduced in this paper, and such end-to-end parameters as query success rate, latency, and query-hits. Derek Leonard, Dmitri Loguinov |
Peer-to-Peer Computing | 2 |
| 2009 | Node isolation model and age-based neighbor selection in unstructured P2P networks
Zhongmei Yao, Xiaoming Wang 0002, Derek Leonard, Dmitri Loguinov |
IEEE/ACM Trans. Netw. | 3 |
| 2009 | IRLbot: Scaling to 6 billion pages and beyondabstractThis article shares our experience in designing a Web crawler that can download billions of pages using a single-server implementation and models its performance. We first show that current crawling algorithms cannot effectively cope with the sheer volume of URLs generated in large crawls, highly branching spam, legitimate multimillion-page blog sites, and infinite loops created by server-side scripts. We then offer a set of techniques for dealing with these issues and test their performance in an implementation we call IRLbot. In our recent experiment that lasted 41 days, IRLbot running on a single server successfully crawled 6.3 billion valid HTML pages (7.6 billion connection requests) and sustained an average download rate of 319 mb/s (1,789 pages/s). Unlike our prior experiments with algorithms proposed in related work, this version of IRLbot did not experience any bottlenecks and successfully handled content from over 117 million hosts, parsed out 394 billion links, and discovered a subset of the Web graph with 41 billion unique nodes. Hsin-Tsang Lee, Derek Leonard, Xiaoming Wang 0002, Dmitri Loguinov |
ACM Trans. Web | 2 |
| 2008 | Turbo King: Framework for Large-Scale Internet Delay MeasurementsabstractDistance estimation and topological proximity in the Internet have recently emerged as important problems for many distributed applications [1], [10], [11], [19], [29], [31], [40], [41], [44]. Besides deploying tracers and using virtual coordinates, distance is often estimated using end-to-end methods such as King [13] that rely on the existing DNS infrastructure. However, the question of accuracy in such end-to-end estimation and its ability to produce a large-scale map of Internet delays has never been examined. We undertake this task below and show that King suffers from non-negligible error when DNS zones employ geographically diverse authoritative servers or utilize forwarders, both of which are very common in the existing Internet. We also show that King requires insertion of numerous unwanted DNS records in caches of remote servers (which is called cache pollution) and requires large traffic overhead when deployed in large-scale. To overcome these limitations, we propose a new framework we call Turbo King (T-King) that obtains end-to-end delay samples without bias in the presence of distant authoritative servers and forwarders, while consuming half the bandwidth needed by King and reducing the impact of cache pollution by several orders of magnitude. We finish the paper by evaluating Turbo King in several experiments. Derek Leonard, Dmitri Loguinov |
INFOCOM | 1 |
| 2008 | IRLbot: scaling to 6 billion pages and beyondabstractThis paper shares our experience in designing a web crawler that can download billions of pages using a single-server implementation and models its performance. We show that with the quadratically increasing complexity of verifying URL uniqueness, BFS crawl order, and fixed per-host rate-limiting, current crawling algorithms cannot effectively cope with the sheer volume of URLs generated in large crawls, highly-branching spam, legitimate multi-million-page blog sites, and infinite loops created by server-side scripts. We offer a set of techniques for dealing with these issues and test their performance in an implementation we call IRLbot. In our recent experiment that lasted 41 days, IRLbot running on a single server successfully crawled 6.3 billion valid HTML pages ($7.6$ billion connection requests) and sustained an average download rate of 319 mb/s (1,789 pages/s). Unlike our prior experiments with algorithms proposed in related work, this version of IRLbot did not experience any bottlenecks and successfully handled content from over 117 million hosts, parsed out 394 billion links, and discovered a subset of the web graph with 41 billion unique nodes. Hsin-Tsang Lee, Derek Leonard, Xiaoming Wang 0002, Dmitri Loguinov |
WWW | 2 |
| 2008 | Jetmax: Scalable max-min congestion control for high-speed heterogeneous networks
Yueping Zhang, Derek Leonard, Dmitri Loguinov |
Comput. Networks | 2 |
| 2008 | On static and dynamic partitioning behavior of large-scale P2P networks
Derek Leonard, Zhongmei Yao, Xiaoming Wang 0002, Dmitri Loguinov |
IEEE/ACM Trans. Netw. | 1 |
| 2007 | On Node Isolation Under Churn in Unstructured P2P Networks with Heavy-Tailed LifetimesabstractPrevious analytical studies [12], [18] of unstructured P2P resilience have assumed exponential user lifetimes and only considered age-independent neighbor replacement. In this paper, we overcome these limitations by introducing a general node-isolation model for heavy-tailed user lifetimes and arbitrary neighbor-selection algorithms. Using this model, we analyze two age-biased neighbor-selection strategies and show that they significantly improve the residual lifetimes of chosen users, which dramatically reduces the probability of user isolation and graph partitioning compared to uniform selection of neighbors. In fact, the second strategy based on random walks on age-weighted graphs demonstrates that for lifetimes with infinite variance, the system monotonically increases its resilience as its age and size grow. Specifically, we show that the probability of isolation converges to zero as these two metrics tend to infinity. We finish the paper with simulations in finite-size graphs that demonstrate the effect of this result in practice. Zhongmei Yao, Xiaoming Wang 0002, Derek Leonard, Dmitri Loguinov |
INFOCOM | 3 |
| 2007 | On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networks
Derek Leonard, Zhongmei Yao, Vivek Rai, Dmitri Loguinov |
IEEE/ACM Trans. Netw. | 1 |
| 2006 | Modeling Heterogeneous User Churn and Local Resilience of Unstructured P2P NetworksabstractPrevious analytical results on the resilience of un-structured P2P systems have not explicitly modeled heterogeneity of user churn (i.e., difference in online behavior) or the impact of in-degree on system resilience. To overcome these limitations, we introduce a generic model of heterogeneous user churn, derive the distribution of the various metrics observed in prior experimental studies (e.g., lifetime distribution of joining users, joint distribution of session time of alive peers, and residual lifetime of a randomly selected user), derive several closed-form results on the transient behavior of in-degree, and eventually obtain the joint in/out degree isolation probability as a simple extension of the out-degree model in [13]. Zhongmei Yao, Derek Leonard, Xiaoming Wang 0002, Dmitri Loguinov |
ICNP | 2 |
| 2006 | JetMax: Scalable Max-Min Congestion Control for High-Speed Heterogeneous NetworksabstractAbstract — Recent surge of interest towards congestion control that relies on single-router feedback (e.g., XCP [12], RCP [1], [5], MaxNet [24], EMKC [28], VCP [26]) suggests that such systems may offer certain benefits over traditional models of additive packet loss [13]. Besides topology-independent stability and faster convergence to efficiency/fairness [24], it was recently shown [28] that any stable single-router system with a symmetric Jacobian tolerates arbitrary fixed, as well as time-varying, feedback delays. Although delay-independence is an appealing characteristic, the EMKC system developed in [28] exhibits undesirable equilibrium properties and slow convergence behavior. To overcome these drawbacks, we propose a new method called JetMax and show that it admits a low-overhead implementation inside routers (three additions per packet), overshoot-free transient and steady state, tunable link utilization, and delay-insensitive flow dynamics. The proposed framework also provides capacity-independent convergence time, where fairness and utilization are reached in the same number of RTT steps for a link of any bandwidth. Given a 1 mb/s, 10 gb/s, or googol (10 100) bps link, the method converges to within 1 % of the stationary state in 6 control intervals. We finish the paper by comparing JetMax’s performance to that of existing methods in ns2 simulations and discussing its Linux implementation. Yueping Zhang, Derek Leonard, Dmitri Loguinov |
INFOCOM | 2 |
| 2005 | On Static and Dynamic Partitioning Behavior of Large-Scale NetworksabstractIn this paper, we analyze the problem of network disconnection in the context of large-scale P2P networks and understand how both static and dynamic patterns of node failure affect the resilience of such graphs. We start by applying classical results from random graph theory to show that a large variety of deterministic and random P2P graphs almost surely (i.e., with probability 1-o(1)) remain connected under random failure if and only if they have no isolated nodes. This simple, yet powerful, result subsequently allows us to derive in closed-form the probability that a P2P network develops isolated nodes, and therefore partitions, under both types of node failure. We finish the paper by demonstrating that our models match simulations very well and that dynamic P2P systems are extremely resilient under node churn as long as the neighbor replacement delay is much smaller than the average user lifetime. Derek Leonard, Zhongmei Yao, Xiaoming Wang 0002, Dmitri Loguinov |
ICNP | 1 |
| 2005 | On lifetime-based node failure and stochastic resilience of decentralized peer-to-peer networksabstractTo understand how high rates of churn and random departure decisions of end-users affect connectivity of P2P networks, this paper investigates resilience of random graphs to lifetime-based node failure and derives the expected delay before a user is forcefully isolated from the graph and the probability that this occurs within his/her lifetime. Our results indicate that systems with heavy-tailed lifetime distributions are more resilient than those with light-tailed (e.g., exponential) distributions and that for a given average degree, k-regular graphs exhibit the highest resilience. As a practical illustration of our results, each user in a system with n = 100 billion peers, 30-minute average lifetime, and 1-minute node-replacement delay can stay connected to the graph with probability 1 - 1 n using only 9 neighbors. This is in contrast to 37 neighbors required under previous modeling efforts. We finish the paper by showing that many P2P networks are almost surely (i.e., with probability 1-o(1)) connected if they have no isolated nodes and derive a simple model for the probability that a P2P system partitions under churn. Derek Leonard, Vivek Rai, Dmitri Loguinov |
SIGMETRICS | 1 |
| 2004 | On Reshaping of Clustering Coefficients in Degree-Based Topology Generators
Xiafeng Li, Derek Leonard, Dmitri Loguinov |
WAW | 2 |