EDBT 2026 Demo / reviewers in the wild / expert
Nick Feamster
dblp:87/840 · also Nicholas G. Feamster
· DBLP profile ↗
159ranked-venue papers
10as first author
38since 2021 · last 2026
0000-0001-9315-5201ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 81 · 5 first-author · 10 since 2021Security and privacy · 46 · 1 first-author · 16 since 2021Human-computer interaction and ubiquitous computing · 13 · 1 first-author · 7 since 2021Systems, architecture and hardware · 8 · 2 first-authorDatabases, data management, data science and information retrieval · 8 · 3 since 2021Software engineering, systems software and programming languages · 7 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Governance of AI-Generated Content: A Case Study on Social Media PlatformsabstractOnline platforms are seeing increasing amounts of AI-generated content—text and other forms of media that are made or co-created with generative AI. This trend suggests platforms may need to establish governance frameworks, including policies and enforcement strategies for how users create, post, share, and engage with such content to encourage responsible use. We investigate the governance of AI-generated content across 40 popular social media platforms. Just over two-thirds explicitly describe governance of AI-generated content spanning six themes. Most platforms focus on moderating AI-generated content that violates established content rules and discloses AI-generated content. Fewer platforms—those that are focused on creativity and knowledge-sharing—address other issues such as ownership and monetization. Based on these findings, we suggest stakeholders and policymakers develop more direct, comprehensive, and forward-looking AI-generated content governance, as well as tools and education for users about the use of such content. Lan Gao 0001, Abani Ahmed, Oscar Chen, Margaux Reyl, Zayna Cheema, Nick Feamster, Chenhao Tan, Kurt Thomas, Marshini Chetty |
CHI | 6 |
| 2026 | Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM InferenceabstractLarge Language Models (LLMs) such as ChatGPT can infer personal attributes from seemingly innocuous text, raising privacy risks beyond memorized data leakage. While prior work has demonstrated these risks, little is known about how users estimate and respond. We conducted a survey with 240 U.S. participants who judged text snippets for inference risks, reported concern levels, and attempted rewrites to block inference. We compared their rewrites with those generated by ChatGPT and Rescriber, a state-of-the-art sanitization tool. Results show that participants struggled to anticipate inference, performing a little better than chance. User rewrites were effective in just 28% of cases - better than Rescriber but worse than ChatGPT. We examined our participants’ rewriting strategies, and observed that while paraphrasing was the most common strategy it is also the least effective; instead abstraction and adding ambiguity were more successful. Our work highlights the importance of inference-aware design in LLM interactions. Qia Wang 0001, Sai Teja Peddinti, Nina Taft, Nick Feamster |
CHI | 4 |
| 2026 | WiFinger: Fingerprinting Noisy IoT Event Traffic Using Packet-level Sequence Matching
Ronghua Li 0002, Shinan Liu, Haibo Hu 0001, Qingqing Ye 0001, Nick Feamster |
NDSS | 5 |
| 2026 | LoFi: Low-Cost Early Application Filter Based on Cached ML Decisions
Johann Hugon, Shinan Liu, Paul Schmitt, Nick Feamster, Francesco Bronzino |
NetSoft | 4 |
| 2026 | Measuring Low Latency at Scale: A Field Study of L4S in Residential Broadband
Ayoub Ben-Ameur, Francesco Bronzino, Paul Schmitt, Nick Feamster |
PAM | 4 |
| 2026 | Understanding Privacy and Quality Tradeoffs in Synthetic Network DataabstractThe limited availability of high-quality computer networking data, and the privacy risks of sharing what does exist, has prompted development of ML-based methods for generating synthetic network data that mimics real communication between networked devices. The viability of these models hinges on both the quality of their output and how well they preserve private information encoded in their training data. Prior work has sought to address this by training models with differential privacy (DP). However, how this choice affects the actual privacy of the training data, and subsequently the quality of the generated output, is not well understood. In this work, we analyze the relationship between privacy and quality in generative network data models. Using the success of membership inference attacks (MIAs) as the metric for privacy, we observe that whether DP mitigates MIAs depends heavily on model architecture and representation of network data used for training. In particular, we empirically find that some approaches to generating synthetic network data train models that heavily skew towards either overgeneralizing or undergeneralizing to their training data, resulting in poor or inconsistent MIA performance. In these cases, using DP does not yield substantive improvements in vulnerability to MIAs. As for the quality of generated data, we find that DP synthetic network data can retain statistical similarity to real data even under strict privacy budgets, and that downstream models (e.g., classifiers, regressors) trained on this data tend to achieve at least as good accuracy as models trained on non-DP data. These results suggest that DP, depending on the model, offers protection against MIAs without degrading the utility of the generated output, and in some cases, improves utility. Andrew Chu, Kyle MacMillan, Paul Schmitt, Nick Feamster |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Dark Patterns in the Opt-Out Process and Compliance with the California Consumer Privacy Act (CCPA)abstractTo protect consumer privacy, the California Consumer Privacy Act (CCPA) mandates that businesses provide consumers with a straightforward way to opt out of the sale and sharing of their personal information. However, the control that businesses enjoy over the opt-out process allows them to impose hurdles on consumers aiming to opt out, including by employing dark patterns. Motivated by the enactment of the California Privacy Rights Act (CPRA), which strengthens the CCPA and explicitly forbids certain dark patterns in the opt-out process, we investigate how dark patterns are used in opt-out processes and assess their compliance with CCPA regulations. Our research reveals that websites employ a variety of dark patterns. Some of these patterns are explicitly prohibited under the CCPA; others evidently take advantage of legal loopholes. Despite the initial efforts to restrict dark patterns by policymakers, there is more work to be done. Van Hong Tran, Aarushi Mehrotra, Ranya Sharma, Marshini Chetty, Nick Feamster, Jens Frankenreiter, Lior Jacob Strahilevitz |
CHI | 5 |
| 2025 | Poster: Global Measurements of the Availability and Response Times of Public Encrypted DNS ResolversabstractPrevious studies have measured encrypted DNS performance, but they have mostly focused on mainstream DNS resolvers [4, 6, 7]. We expand on previous studies, exploring the performance of all encrypted DNS resolvers—from a variety of global vantage points, as opposed to simply characterizing the mainstream DoH providers from well-connected vantage points. Our goal is to compare the performance of encrypted DNS resolvers to each other to understand the extent to which this larger set of DNS resolvers could be used by clients and applications in different regions. Ranya Sharma, Nick Feamster |
IMC | 2 |
| 2025 | CATO: End-to-End Optimization of ML-Based Traffic Analysis Pipelines
Gerry Wan, Shinan Liu, Francesco Bronzino, Nick Feamster, Zakir Durumeric |
NSDI | 4 |
| 2025 | "I Cannot Write This Because It Violates Our Content Policy": Understanding Content Moderation Policies and User Experiences in Generative AI Products
Lan Gao 0001, Oscar Chen, Rachel Lee, Nick Feamster, Chenhao Tan, Marshini Chetty |
USENIX Security Symposium | 4 |
| 2025 | The Silent Danger in HTTP: Identifying HTTP Desync Vulnerabilities with Gray-box Testing
Keran Mu, Jianjun Chen 0005, Jianwei Zhuge, Qi Li 0002, Hai-Xin Duan, Nick Feamster |
USENIX Security Symposium | 6 |
| 2025 | Understanding User Privacy Concerns of Shared Smart TVsabstractAs smart TVs gain popularity, they introduce significant privacy and security concerns due to their extensive data collection and multi-user contexts. This paper investigates user perceptions of privacy concerns regarding both service providers and the multi-user use case in the context of smart TVs. Through in-depth interviews with 22 smart TV users, we found that participants expressed uncertainty about the data collection practices of smart TVs and a desire for clearer communication of such practices. Participants reported discomfort with how their personal information is handled through their smart TVs but felt forced to accept it due to the lack of ability to opt out. Our study also highlights varied privacy concerns when smart TVs are shared in public versus private settings. While participants expressed significantly less concern when sharing smart TVs with acquaintances in private settings, concerns were more prevalent in public settings like hotels and Airbnbs. Based on the findings, we provide recommendations for designers, policymakers, and researchers to improve privacy protection and user experience around smart TVs. Qia Wang 0001, Lan Gao 0001, Marshini Chetty, Nick Feamster |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2025 | Algorithmic Data Minimization for Machine Learning over Internet-of-Things Data Streams
Ted Shaowang, Shinan Liu, Jonatas Marques, Nick Feamster, Sanjay Krishnan |
Proc. VLDB Endow. | 4 |
| 2024 | "Community Guidelines Make this the Best Party on the Internet": An In-Depth Study of Online Platforms' Content Moderation PoliciesabstractModerating user-generated content on online platforms is crucial for balancing user safety and freedom of speech. Particularly in the United States, platforms are not subject to legal constraints prescribing permissible content. Each platform has thus developed bespoke content moderation policies, but there is little work towards a comparative understanding of these policies across platforms and topics. This paper presents the first systematic study of these policies from the 43 largest online platforms hosting user-generated content, focusing on policies around copyright infringement, harmful speech, and misleading content. We build a custom web-scraper to obtain policy text and develop a unified annotation scheme to analyze the text for the presence of critical components. We find significant structural and compositional variation in policies across topics and platforms, with some variation attributable to disparate legal groundings. We lay the groundwork for future studies of ever-evolving content moderation policies and their impact on users. Brennan Schaffner, Arjun Nitin Bhagoji, Siyuan Cheng 0018, Jacqueline Mei, Jay L. Shen, Marshini Chetty, Nick Feamster, Genevieve Lakier, Chenhao Tan |
CHI | 8 |
| 2024 | Measuring Compliance with the California Consumer Privacy Act Over Space and TimeabstractThe widespread sharing of consumers’ personal information with third parties raises significant privacy concerns. The California Consumer Privacy Act (CCPA) mandates that online businesses offer consumers the option to opt out of the sale and sharing of personal information. Our study automatically tracks the presence of the opt-out link longitudinally across multiple states after the California Privacy Rights Act (CPRA) went into effect. We categorize websites based on whether they are subject to CCPA and investigate cases of potential non-compliance. We find a number of websites that implement the opt-out link early and across all examined states but also find a significant number of CCPA-subject websites that fail to offer any opt-out methods even when CCPA is in effect. Our findings can shed light on how websites are reacting to the CCPA and identify potential gaps in compliance and opt-out method designs that hinder consumers from exercising CCPA opt-out rights. Van Hong Tran, Aarushi Mehrotra, Marshini Chetty, Nick Feamster, Jens Frankenreiter, Lior Jacob Strahilevitz |
CHI | 4 |
| 2024 | Can Allowlists Capture the Variability of Home IoT Device Network Behavior?abstractHome Internet of Things (IoT) devices can be difficult for users to secure. Prior work has suggested measuring these devices' network behaviors and using these characterizations to create allowlists of permitted endpoints. Unfortunately, previous studies have typically been conducted in controlled lab settings, with one or two devices per product. In this paper, we examine whether popular home IoT products' network behaviors generalize via both in-lab experiments of 24 devices and a large, crowdsourced dataset of IoT devices in the wild. We find that observing traffic from one device in one lab is often insufficient to fully characterize an IoT product's network behaviors. For example, specifying which endpoints a device may contact based on initial measurements in our lab led 25% of products to stop functioning later, and even more when using a VPN. We then used the crowdsourced dataset to better understand this traffic's heterogeneity and pinpoint how to create more generalizable allowlists. We identified causes of failure, such as regionalization, CDN usage, third-party integrations, and API changes. Finally, we used the crowdsourced data in numerous configurations to specify which endpoints each product in our lab could contact. We found that domain-level allowlists enabled the majority of devices to function in our lab using data collected years in the past. For the remaining devices, we characterize how to mitigate the failures observed and pave the way to creating more generalizable allowlists. Weijia He, Kevin Bryson 0002, Ricardo Calderon, Nick Feamster, Danny Yuxing Huang, Blase Ur |
EuroS&P | 5 |
| 2024 | A Longitudinal Study of the Prevalence of WiFi Bottlenecks in Home Access NetworksabstractAlthough home wireless networks (WiFi) are increasingly becoming performance bottlenecks, there are no research studies based on long-running field deployments that document this phenomenon. Given both public and private investment in broadband Internet infrastructure, a rigorous study of this phenomenon---and accompanying public data, based on open-source methods, is critical. To this end, this study pioneers a system and measurement technique to directly assess WiFi and access network performance. This study is first to continuously and contemporaneously measure Internet performance along two segments---the wireless client to the access point, and from the access point to the ISP access network. It is also the largest and longest-running study of its kind, with public data spanning more than two years (and counting), and, to our knowledge, the first such study in nearly a decade. Our study is based on data from over 22,000 joint measurements across more than 50 broadband access networks. Our findings have important implications for both the development of access technologies and Internet policy. Notably, for users with access links that exceed 800~Mbps, the user's wireless network was the performance bottleneck 100% of the time. Such inflection points will continue to evolve, yet the contributions of this paper include not only the results, but also open-source tools, data, and ongoing continuous measurements. Ranya Sharma, Nick Feamster, Marc Richardson |
IMC | 2 |
| 2024 | Acoustic Keystroke Leakage on Smart Televisions
Tejas Kannan, Qia Wang 0001, Max Sunog, Abraham Bueno de Mesquita, Nick Feamster, Henry Hoffmann |
NDSS | 5 |
| 2024 | GRACE: Loss-Resilient Real-Time Video through Neural Codecs
Yihua Cheng, Hanchen Li, Anton Arapin, Qizheng Zhang, Yuhan Liu 0004, Kuntai Du, Francis Y. Yan, Amrita Mazumdar, Nick Feamster, Junchen Jiang |
NSDI | 12 |
| 2024 | GFWeb: Measuring the Great Firewall's Web Censorship at Scale
Nguyen Phong Hoang, Jakub Dalek, Masashi Crete-Nishihata, Nicolas Christin, Vinod Yegneswaran, Michalis Polychronakis, Nick Feamster |
USENIX Security Symposium | 7 |
| 2023 | Prediction Privacy in Distributed Multi-Exit Neural Networks: Vulnerabilities and SolutionsabstractDistributed Multi-exit Neural Networks (MeNNs) use partitioning and early exits to reduce the cost of neural network inference on low-power sensing systems. Existing MeNNs exhibit high inference accuracy using policies that select when to exit based on data-dependent prediction confidence. This paper presents a side-channel attack against distributed MeNNs employing data-dependent early exit policies. We find that an adversary can observe when a distributed MeNN exits early using encrypted communication patterns. An adversary can then use these observations to discover the MeNN's predictions with over 1.85× the accuracy of random guessing. In some cases, the side-channel leaks over 80% of the model's predictions. This leakage occurs because prior policies make decisions using a single threshold on varying prediction confidence distributions. We address this problem through two new exit policies. The first method, Per-Class Exiting (PCE), uses multiple thresholds to balance exit rates across predicted classes. This policy retains high accuracy and lowers prediction leakage, but we prove it has no privacy guarantees. We obtain these guarantees with a second policy, Confidence-Guided Randomness (CGR), which randomly selects when to exit using probabilities biased toward PCE's decisions. CGR provides statistically equivalent privacy with consistently higher inference accuracy than exiting early uniformly at random. Both PCE and CGR have low overhead, making them viable security solutions in resource-constrained settings. Tejas Kannan, Nick Feamster, Henry Hoffmann |
CCS | 2 |
| 2023 | Discovery Testbed: An Observational Instrument for Broadband ResearchabstractInvestigating phenomena that require continuous collection of data from a large and widely distributed array of hard-to-reach sources – such as understanding the performance of end-user broadband – has traditionally been hard. The opportunities in this sphere are now changing with easy availability of single board computers (SBCs), that are reliable and cheap, and thus can in principle be deployed in places of interest at large scales to gain coverage yielding statistically significant results. The challenge that this idea raises is how to create, deploy, an operate this type of infrastructure, given that its makup and deployment properties are very different from hardware deployed in datacenters. This paper presents the design of FLOTO, an observational instrument that supports the deployment and operation of mainstream SBCs to collect data through large-scale deployments in the field. FLOTO allows users to deploy devices to collect data of interest; operate those devices securely in remote locations without physical access to device; supports multi-tenant sharing of devices between different data collecting applications and user groups, that makes it possible to adapt or re-purpose the observational function of the instrument; and provides data collection and sharing functionality allowing user communities to benefit from the collected data. We describe the design of FLOTO and present a case study of its deployment as an observational instrument to collect broadband data. We conclude by discussing the possible adaptations of this instrument to study different scientific questions. Kate Keahey, Nick Feamster, Guilherme Martins, Mark Powers, Marc Richardson, Alexis Schrubbe |
e-Science | 2 |
| 2023 | Generative, High-Fidelity Network TracesabstractRecently, much attention has been devoted to the development of generative network traces and their potential use in supplementing real-world data for a variety of data-driven networking tasks. Yet, the utility of existing synthetic traffic approaches are limited by their low fidelity: low feature granularity, insufficient adherence to task constraints, and subpar class coverage. As effective network tasks are increasingly reliant on raw packet captures, we advocate for a paradigm shift from coarse-grained to fine-grained traffic generation compliant to constraints. We explore this path employing controllable diffusion-based methods. Our preliminary results suggest its effectiveness in generating realistic and fine-grained network traces that mirror the complexity and variety of real network traffic required for accurate service recognition. We further outline the challenges and opportunities of this approach, and discuss a research agenda towards text-to-traffic synthesis. Xi Jiang 0007, Shinan Liu, Aaron Gember, Paul Schmitt, Francesco Bronzino, Nick Feamster |
HotNets | 6 |
| 2023 | Estimating WebRTC Video QoE Metrics Without Using Application HeadersabstractThe increased use of video conferencing applications (VCAs) has made it critical to understand and support end-user quality of experience (QoE) by all stakeholders in the VCA ecosystem, especially network operators, who typically do not have direct access to client software. Existing VCA QoE estimation methods use passive measurements of application-level Real-time Transport Protocol (RTP) headers. However, a network operator does not always have access to RTP headers in all cases, particularly when VCAs use custom RTP protocols (e.g., Zoom) or due to system constraints (e.g., legacy measurement systems). Given this challenge, this paper considers the use of more standard features in the network traffic, namely, IP and UDP headers, to provide per-second estimates of key VCA QoE metrics such as frames rate and video resolution. We develop a method that uses machine learning with a combination of flow statistics (e.g., throughput) and features derived based on the mechanisms used by the VCAs to fragment video frames into packets. We evaluate our method for three prevalent VCAs running over WebRTC: Google Meet, Microsoft Teams, and Cisco Webex. Our evaluation consists of 54,696 seconds of VCA data collected from both (1), controlled in-lab network conditions, and (2) real-world networks from 15 households. We show that the ML-based approach yields similar accuracy compared to the RTP-based methods, despite using only IP/UDP data. For instance, we can estimate FPS within 2 FPS for up to 83.05% of one-second intervals in the real-world data, which is only 1.76% lower than using the application-level RTP headers. Taveesh Sharma, Tarun Mangla, Arpit Gupta, Junchen Jiang, Nick Feamster |
IMC | 5 |
| 2023 | Augmenting Rule-based DNS Censorship Detection at Scale with Machine LearningabstractThe proliferation of global censorship has led to the development of a plethora of measurement platforms to monitor and expose it. Censorship of the domain name system (DNS) is a key mechanism used across different countries. It is currently detected by applying heuristics to samples of DNS queries and responses (probes) for specific destinations. These heuristics, however, are both platform-specific and have been found to be brittle when censors change their blocking behavior, necessitating a more reliable automated process for detecting censorship. Jacob Alexander Markson Brown, Xi Jiang 0007, Van Hong Tran, Arjun Nitin Bhagoji, Nguyen Phong Hoang, Nick Feamster, Prateek Mittal, Vinod Yegneswaran |
KDD | 6 |
| 2023 | User Awareness and Behaviors Concerning Encrypted DNS Settings in Web Browsers
Alexandra Nisenoff, Ranya Sharma, Nick Feamster |
USENIX Security Symposium | 3 |
| 2023 | Measuring and Evading Turkmenistan's Internet Censorship: A Case Study in Large-Scale Measurements of a Low-Penetration CountryabstractSince 2006, Turkmenistan has been listed as one of the few Internet enemies by Reporters without Borders due to its extensively censored Internet and strictly regulated information control policies. Existing reports of filtering in Turkmenistan rely on a handful of vantage points or test a small number of websites. Yet, the country’s poor Internet adoption rates and small population can make more comprehensive measurement challenging. With a population of only six million people and an Internet penetration rate of only 38%, it is challenging to either recruit in-country volunteers or obtain vantage points to conduct remote network measurements at scale. Sadia Nourin, Van Hong Tran, Xi Jiang 0007, Kevin Bock 0001, Nick Feamster, Nguyen Phong Hoang, Dave Levin |
WWW | 5 |
| 2022 | Poster: Investigating QUIC's Potential Impact on Censorship CircumventionabstractAlthough not yet ubiquitous, censors and censorship-resistors have been eyeing QUIC as the next avenue for censorship-circumvention. In this poster, we highlight three QUIC features that are avenues for potential improvements to both Pluggable Transports and decoy routing: streams, connections identifiers, and congestion control. We also examine how traffic splitting can be used. We then discuss how these features can be integrated into Pluggable Transports and decoy routing. We close with providing guidance for future work on integrating QUIC into Pluggable Transports and decoy routing. Anna Harbluk Lorimer, Nick Feamster, Prateek Mittal |
CCS | 2 |
| 2022 | GPS-Based Geolocation of Consumer IP Addresses
James Saxon, Nick Feamster |
PAM | 2 |
| 2022 | How and Why People Use Virtual Private Networks
Agnieszka Dutkowska-Zuk, Austin Hounsel, Amy Morrill, Andre Xiong, Marshini Chetty, Nick Feamster |
USENIX Security Symposium | 6 |
| 2022 | Software-Supported Audits of Decision-Making Systems: Testing Google and Facebook's Political Advertising PoliciesabstractHow can society understand and hold accountable complex human and algorithmic decision-making systems whose systematic errors are opaque to the public? These systems routinely make decisions on individual rights and well-being, and on protecting society and the democratic process. Practical and statistical constraints on external audits--such as dimensional complexity--can lead researchers and regulators to miss important sources of error in these complex decision-making systems. In this paper, we design and implement a software-supported approach to audit studies that auto-generates audit materials and coordinates volunteer activity. We implemented this software in the case of political advertising policies enacted by Facebook and Google during the 2018 U.S. election. Guided by this software, a team of volunteers posted 477 auto-generated ads and analyzed the companies' actions, finding systematic errors in how companies enforced policies. We find that software can overcome some common constraints of audit studies, within limitations related to sample size and volunteer capacity. J. Nathan Matias, Austin Hounsel, Nick Feamster |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | You, Me, and IoT: How Internet-connected Consumer Devices Affect Interpersonal RelationshipsabstractInternet-connected consumer devices have rapidly increased in popularity; however, relatively little is known about how these technologies are affecting interpersonal relationships in multi-occupant households. In this study, we conduct 13 semi-structured interviews and survey 508 individuals from a variety of backgrounds to discover and categorize how consumer IoT devices are affecting interpersonal relationships in the United States. We highlight several themes, providing exploratory data about the pervasiveness of interpersonal costs and benefits of consumer IoT devices. These results inform follow-up studies and design priorities for future IoT technologies to amplify positive and reduce negative interpersonal effects. Noah J. Apthorpe, Pardis Emami Naeini, Arunesh Mathur, Marshini Chetty, Nick Feamster |
ACM Trans. Internet Things | 5 |
| 2022 | Alexa, Who Am I Speaking To?: Understanding Users' Ability to Identify Third-Party Apps on Amazon AlexaabstractMany Internet of Things devices have voice user interfaces. One of the most popular voice user interfaces is Amazon’s Alexa, which supports more than 50,000 third-party applications (“skills”). We study how Alexa’s integration of these skills may confuse users. Our survey of 237 participants found that users do not understand that skills are often operated by third parties, that they often confuse third-party skills with native Alexa functions, and that they are unaware of the functions that the native Alexa system supports. Surprisingly, users who interact with Alexa more frequently are more likely to conclude that a third-party skill is a native Alexa function. The potential for misunderstanding creates new security and privacy risks: attackers can develop third-party skills that operate without users’ knowledge or masquerade as native Alexa functions. To mitigate this threat, we make design recommendations to help users better distinguish native functionality and third-party skills, including audio and visual indicators of native and third-party contexts, as well as a consistent design standard to help users learn what functions are and are not possible on Alexa. David J. Major, Danny Yuxing Huang, Marshini Chetty, Nick Feamster |
ACM Trans. Internet Techn. | 4 |
| 2021 | New Directions in Automated Traffic AnalysisabstractMachine learning is leveraged for many network traffic analysis tasks in security, from application identification to intrusion detection. Yet, the aspects of the machine learning pipeline that ultimately determine the performance of the model---feature selection and representation, model selection, and parameter tuning---remain manual and painstaking. This paper presents a method to automate many aspects of traffic analysis, making it easier to apply machine learning techniques to a wider variety of traffic analysis tasks. We introduce nPrint, a tool that generates a unified packet representation that is amenable for representation learning and model training. We integrate nPrint with automated machine learning (AutoML), resulting in nPrintML, a public system that largely eliminates feature extraction and model tuning for a wide variety of traffic analysis tasks. We have evaluated nPrintML on eight separate traffic analysis tasks and released nPrint, nPrintML and the corresponding datasets from our evaluation to enable future work to extend these methods. Jordan Holland, Paul Schmitt, Nick Feamster, Prateek Mittal |
CCS | 3 |
| 2021 | Designing for Tussle in Encrypted DNSabstractRecent concerns over the privacy implications of the Domain Name System (DNS) have led to encrypting DNS queries and responses through protocols like DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT). Although the trend towards encryption is a positive development, the accompanying centralization of the DNS has fomented tussles involving ISPs, browser and device vendors, content delivery networks, and users. This paper articulates several current DNS tussles and offers principles to guide system design and implementation such that all stakeholders in the space could participate. We argue that refactoring name resolution in a stub resolver that is separate from devices and applications can preserve the benefits of encrypted DNS while satisfying other architectural desiderata, including performance, resilience, and privacy. Austin Hounsel, Paul Schmitt, Kevin Borgolte, Nick Feamster |
HotNets | 4 |
| 2021 | Measuring the performance and network utilization of popular video conferencing applicationsabstractVideo conferencing applications (VCAs) have become a critical Internet application during the COVID-19 pandemic, as users worldwide now rely on them for work, school, and telehealth. It is thus increasingly important to understand the resource requirements of different VCAs and how they perform under different network conditions, including: how do application-layer performance metrics (e.g., resolution or frames per second) vary under different link capacity; how VCAs perform under temporary reductions in available capacity; how they compete with themselves, with each other, and with other applications; and how usage modality (e.g., gallery vs. speaker mode) affects utilization. We study three modern VCAs: Zoom, Google Meet, and Microsoft Teams. Answers to these questions differ substantially depending on VCA. First, the average utilization on an unconstrained link varies between 0.8 Mbps and 1.9 Mbps. Given temporary reduction of capacity, some VCAs can take as long as 50 seconds to recover to steady state. Differences in proprietary congestion control algorithms also result in unfair bandwidth allocations: in constrained bandwidth settings, one Zoom video conference can consume more than 75% of the available bandwidth when competing with another VCA (e.g., Meet, Teams). For some VCAs, client utilization can decrease as the number of participants increases, due to the reduced video resolution of each participant's video stream given a larger number of participants. Finally, one participant's viewing mode (e.g., pinning a speaker) can affect the upstream utilization of other participants. Kyle MacMillan, Tarun Mangla, James Saxon, Nick Feamster |
Internet Measurement Conference | 4 |
| 2021 | Can Encrypted DNS Be Fast?abstractAbstract In this paper, we study the performance of encrypted DNS protocols and conventional DNS from thousands of home networks in the United States, over one month in 2020. We perform these measurements from the homes of 2,693 participating panelists in the Federal Communications Commission’s (FCC) Measuring Broadband America program. We found that clients do not have to trade DNS performance for privacy. For certain resolvers, DoT was able to perform faster than DNS in median response times, even as latency increased. We also found significant variation in DoH performance across recursive resolvers. Based on these results, we recommend that DNS clients (e.g., web browsers) should periodically conduct simple latency and response time measurements to determine which protocol and resolver a client should use. No single DNS protocol nor resolver performed the best for all clients. Austin Hounsel, Paul Schmitt, Kevin Borgolte, Nick Feamster |
PAM | 4 |
| 2021 | Characterizing Service Provider Response to the COVID-19 Pandemic in the United States
Shinan Liu, Paul Schmitt, Francesco Bronzino, Nick Feamster |
PAM | 4 |
| 2020 | A Public Option for the CoreabstractThis paper is focused not on the Internet architecture - as defined by layering, the narrow waist of IP, and other core design principles - but on the Internet infrastructure, as embodied in the technologies and organizations that provide Internet service. In this paper we discuss both the challenges and the opportunities that make this an auspicious time to revisit how we might best structure the Internet's infrastructure. Currently, the tasks of transit-between-domains and last-mile-delivery are jointly handled by a set of ISPs who interconnect through BGP. In this paper we propose cleanly separating these two tasks. For transit, we propose the creation of a "public option" for the Internet's core backbone. This public option core, which complements rather than replaces the backbones used by large-scale ISPs, would (i) run an open market for backbone bandwidth so it could leverage links offered by third-parties, and (ii) structure its terms-of-service to enforce network neutrality so as to encourage competition and reduce the advantage of large incumbents. Yotam Harchol, Dirk Bergemann, Nick Feamster, Eric J. Friedman, Arvind Krishnamurthy, Aurojit Panda, Sylvia Ratnasamy, Michael Schapira, Scott Shenker |
SIGCOMM | 3 |
| 2020 | Understanding the Performance Costs and Benefits of Privacy-focused Browser ExtensionsabstractAdvertisements and behavioral tracking have become an invasive nuisance on the Internet in recent years. Indeed, privacy advocates and expert users consider the invasion significant enough to warrant the use of ad blockers and anti-tracking browser extensions. At the same time, one of the largest advertisement companies in the world, Google, is developing the most popular browser, Google Chrome. This conflict of interest, that is developing a browser (a user agent) and being financially motivated to track users’ online behavior, possibly violating their privacy expectations, while claiming to be a ”user agent,” did not remain unnoticed. As a matter of fact, Google recently sparked an outrage when proposing changes to Chrome how extensions can inspect and modify requests to ”improve extension performance and privacy,” which would render existing privacy-focused extensions inoperable. Kevin Borgolte, Nick Feamster |
WWW | 2 |
| 2020 | Comparing the Effects of DNS, DoT, and DoH on Web PerformanceabstractNearly every service on the Internet relies on the Domain Name System (DNS), which translates a human-readable name to an IP address before two endpoints can communicate. Today, DNS traffic is unencrypted, leaving users vulnerable to eavesdropping and tampering. Past work has demonstrated that DNS queries can reveal a user’s browsing history and even what smart devices they are using at home. In response to these privacy concerns, two new protocols have been proposed: DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT). Instead of sending DNS queries and responses in the clear, DoH and DoT establish encrypted connections between users and resolvers. By doing so, these protocols provide privacy and security guarantees that traditional DNS (Do53) lacks. Austin Hounsel, Kevin Borgolte, Paul Schmitt, Jordan Holland, Nick Feamster |
WWW | 5 |
| 2020 | Elmo: Source Routed Multicast for Public CloudsabstractWe present Elmo, a system that addresses the multicast scalability problem in multi-tenant datacenters. Modern cloud applications frequently exhibit one-to-many communication patterns and, at the same time, require sub-millisecond latencies and high throughput. IP multicast can achieve these requirements but has control- and data-plane scalability limitations that make it challenging to offer it as a service for hundreds of thousands of tenants, typical of cloud environments. Tenants, therefore, must rely on unicast-based approaches (e.g., application-layer or overlay-based) to support multicast in their applications, imposing bandwidth and end-host CPU overheads, with higher and unpredictable latencies. Elmo scales network multicast by taking advantage of emerging programmable switches and the unique characteristics of data-center networks; specifically, the hypervisor switches, symmetric topology, and short paths in a datacenter. Elmo encodes multicast group information inside packets themselves, reducing the need to store the same information in network switches. In a three-tier data-center topology with 27,000 hosts, Elmo supports a million multicast groups using an average packet-header size of 114 bytes (max. 325 bytes), requiring as few as 1,100 multicast group-table entries on average in leaf switches, and having a traffic overhead as low as 5% over ideal multicast. Muhammad Shahbaz 0001, Lalith Suresh 0001, Jennifer Rexford, Nick Feamster, Ori Rottenstreich, Mukesh Hira |
IEEE/ACM Trans. Netw. | 4 |
| 2019 | Watching You Watch: The Tracking Ecosystem of Over-the-Top TV Streaming DevicesabstractThe number of Internet-connected TV devices has grown significantly in recent years, especially Over-the-Top ("OTT") streaming devices, such as Roku TV and Amazon Fire TV. OTT devices offer an alternative to multi-channel television subscription services, and are often monetized through behavioral advertising. To shed light on the privacy practices of such platforms, we developed a system that can automatically download OTT apps (also known as channels), and interact with them while intercepting the network traffic and performing best-effort TLS interception. We used this smart crawler to visit more than 2,000 channels on two popular OTT platforms, namely Roku and Amazon Fire TV. Our results show that tracking is pervasive on both OTT platforms, with traffic to known trackers present on 69% of Roku channels and 89% of Amazon Fire TV channels. We also discover widespread practice of collecting and transmitting unique identifiers, such as device IDs, serial numbers, WiFi MAC addresses and SSIDs, at times over unencrypted connections. Finally, we show that the countermeasures available on these devices, such as limiting ad tracking options and adblocking, are practically ineffective. Based on our findings, we make recommendations for researchers, regulators, policy makers, and platform/app developers. Hooman Mohajeri Moghaddam, Gunes Acar, Ben Burgess, Arunesh Mathur, Danny Yuxing Huang, Nick Feamster, Edward W. Felten, Prateek Mittal, Arvind Narayanan |
CCS | 6 |
| 2019 | Going against the (Appropriate) Flow: A Contextual Integrity Approach to Privacy Policy AnalysisabstractWe present a method for analyzing privacy policies using the framework of contextual integrity (CI). This method allows for the systematized detection of issues with privacy policy statements that hinder readers’ ability to understand and evaluate company data collection practices. These issues include missing contextual details, vague language, and overwhelming possible interpretations of described information transfers. We demonstrate this method in two different settings. First, we compare versions of Facebook’s privacy policy from before and after the Cambridge Analytica scandal. Our analysis indicates that the updated policy still contains fundamental ambiguities that limit readers’ comprehension of Facebook’s data collection practices. Second, we successfully crowdsourced CI annotations of 48 excerpts of privacy policies from 17 companies with 141 crowdworkers. This indicates that regular users are able to reliably identify contextual information in privacy policy statements and that crowdsourcing can help scale our CI analysis method to a larger number of privacy policy statements. Yan Shvartzshnaider, Noah J. Apthorpe, Nick Feamster, Helen Nissenbaum |
HCOMP | 3 |
| 2019 | Elmo: source routed multicast for public cloudsabstractWe present Elmo, a system that addresses the multicast scalability problem in multi-tenant datacenters. Modern cloud applications frequently exhibit one-to-many communication patterns and, at the same time, require sub-millisecond latencies and high throughput. IP multicast can achieve these requirements but has control- and data-plane scalability limitations that make it challenging to offer it as a service for hundreds of thousands of tenants, typical of cloud environments. Tenants, therefore, must rely on unicast-based approaches (e.g., application-layer or overlay-based) to support multicast in their applications, imposing bandwidth and end-host CPU overheads, with higher and unpredictable latencies. Muhammad Shahbaz 0001, Lalith Suresh 0001, Jennifer Rexford, Nick Feamster, Ori Rottenstreich, Mukesh Hira |
SIGCOMM | 4 |
| 2019 | Evaluating the Contextual Integrity of Privacy Regulation: Parents' IoT Toy Privacy Norms Versus COPPA
Noah J. Apthorpe, Sarah Varghese, Nick Feamster |
USENIX Security Symposium | 3 |
| 2019 | Selling a Single Item with Negative ExternalitiesabstractWe consider the problem of regulating products with negative externalities to a third party that is neither the buyer nor the seller, but where both the buyer and seller can take steps to mitigate the externality. The motivating example to have in mind is the sale of Internet-of-Things (IoT) devices, many of which have historically been compromised for DDoS attacks that disrupted Internet-wide services such as Twitter [5, 26]. Neither the buyer (i.e., consumers) nor seller (i.e., IoT manufacturers) was known to suffer from the attack, but both have the power to expend effort to secure their devices. We consider a regulator who regulates payments (via fines if the device is compromised, or market prices directly), or the product directly via mandatory security requirements. Matheus V. X. Ferreira, S. Matthew Weinberg, Danny Yuxing Huang, Nick Feamster, Tithi Chattopadhyay |
WWW | 4 |
| 2019 | Security and Privacy Analyses of Internet of Things Children's ToysabstractThis paper investigates the security and privacy of Internet-connected children's smart toys through case studies of three commercially available products. We conduct network and application vulnerability analyses of each toy using static and dynamic analysis techniques, including application binary decompilation and network monitoring. We discover several publicly undisclosed vulnerabilities that violate the Children's Online Privacy Protection Rule as well as the toys' individual privacy policies. These vulnerabilities, especially security flaws in network communications with first-party servers, are indicative of a disconnect between many Internet of Things toy developers and security and privacy best practices despite increased attention to Internet-connected toy hacking risks. Gordon Chu, Noah J. Apthorpe, Nick Feamster |
IEEE Internet Things J. | 3 |
| 2019 | Keeping the Smart Home Private with Smart(er) IoT Traffic ShapingabstractAbstract The proliferation of smart home Internet of things (IoT) devices presents unprecedented challenges for preserving privacy within the home. In this paper, we demonstrate that a passive network observer (e.g., an Internet service provider) can infer private in-home activities by analyzing Internet traffic from commercially available smart home devices even when the devices use end-to-end transport-layer encryption. We evaluate common approaches for defending against these types of traffic analysis attacks, including firewalls, virtual private networks, and independent link padding, and find that none sufficiently conceal user activities with reasonable data overhead. We develop a new defense, “stochastic traffic padding” (STP), that makes it difficult for a passive network adversary to reliably distinguish genuine user activities from generated traffic patterns designed to look like user interactions. Our analysis provides a theoretical bound on an adversary’s ability to accurately detect genuine user activities as a function of the amount of additional cover traffic generated by the defense technique. Noah J. Apthorpe, Danny Yuxing Huang, Dillon Reisman, Arvind Narayanan, Nick Feamster |
Proc. Priv. Enhancing Technol. | 5 |
| 2019 | Oblivious DNS: Practical Privacy for DNS QueriesabstractAbstract Virtually every Internet communication typically involves a Domain Name System (DNS) lookup for the destination server that the client wants to communicate with. Operators of DNS recursive resolvers—the machines that receive a client’s query for a domain name and resolve it to a corresponding IP address—can learn significant information about client activity. Past work, for example, indicates that DNS queries reveal information ranging from web browsing activity to the types of devices that a user has in their home. Recognizing the privacy vulnerabilities associated with DNS queries, various third parties have created alternate DNS services that obscure a user’s DNS queries from his or her Internet service provider. Yet, these systems merely transfer trust to a different third party. We argue that no single party ought to be able to associate DNS queries with a client IP address that issues those queries. To this end, we present Oblivious DNS (ODNS), which introduces an additional layer of obfuscation between clients and their queries. To do so, ODNS uses its own authoritative namespace; the authoritative servers for the ODNS namespace act as recursive resolvers for the DNS queries that they receive, but they never see the IP addresses for the clients that initiated these queries. We present an initial deployment of ODNS; our experiments show that ODNS introduces minimal performance overhead, both for individual queries and for web page loads. We design ODNS to be compatible with existing DNS protocols and infrastructure, and we are actively working on an open standard with the IETF. Paul Schmitt, Anne Edmundson, Allison Mankin, Nick Feamster |
Proc. Priv. Enhancing Technol. | 4 |
| 2018 | Preserving Privacy at IXPsabstractAutonomous systems (ASes) on the Internet increasingly rely on Internet Exchange Points (IXPs) for peering. A single IXP may interconnect several 100s or 1000s of participants (ASes) all of which might peer with each other through BGP sessions. IXPs have addressed this scaling challenge through the use of route servers. However, route servers require participants to trust the IXP and reveal their policies, a drastic change from the accepted norm where all policies are kept private. In this paper we look at techniques to build route servers which provide the same functionality as existing route servers without requiring participants to reveal their policies thus preserving the status quo and enabling wider adoption of IXPs. Prior work has looked at secure multiparty computation (SMPC) as a means of implementing such route servers however this affects performance and reduces policy flexibility. In this paper we take a different tack and build on trusted execution environments (TEEs) such as Intel SGX to keep policies private and flexible. We present results from an initial route server implementation that runs under Intel SGX and show that our approach has 20x better performance than SMPC based approaches. Furthermore, we demonstrate that the additional privacy provided by our approach comes at minimal cost and our implementation is at worse 2.1x slower than a current route server implementation (and in some situations up to 2x faster). Xiaohe Hu, Arpit Gupta, Nick Feamster, Aurojit Panda, Scott Shenker |
APNet | 3 |
| 2018 | Nation-State Hegemony in Internet RoutingabstractWhile the growth of the Internet has fostered more efficient communications around the world, there is a large digital divide between Western countries and the rest of the world. Countries such as Brazil, China, and Saudi Arabia have questioned and criticized America's Internet hegemony. This paper studies the extent to which various countries rely on the United States and other Western countries to connect to popular Internet destinations in those countries. Unfortunately, our measurements reveal that underserved regions are dependent on North American and Western European regions for two reasons: local content is often hosted in foreign countries (such as the United States and the Netherlands), and networks within a country often fail to peer with one another. Fortunately, we also find that routing traffic through strategically placed relay nodes can in some cases reduce the number of transnational routing detours by more than a factor of two, which subsequently reduces the dependence of underserved regions on other regions. Based on these findings, we design and implement Region-Aware Networking, RAN, a lightweight system that routes a client's web traffic around specified countries with no modifications to client software (and in many cases with little performance overhead). Anne Edmundson, Roya Ensafi, Nick Feamster, Jennifer Rexford |
COMPASS | 3 |
| 2018 | Sonata: query-driven streaming network telemetryabstractManaging and securing networks requires collecting and analyzing network traffic data in real time. Existing telemetry systems do not allow operators to express the range of queries needed to perform management or scale to large traffic volumes and rates. We present Sonata, an expressive and scalable telemetry system that coordinates joint collection and analysis of network traffic. Sonata provides a declarative interface to express queries for a wide range of common telemetry tasks; to enable real-time execution, Sonata partitions each query across the stream processor and the data plane, running as much of the query as it can on the network switch, at line rate. To optimize the use of limited switch memory, Sonata dynamically refines each query to ensure that available resources focus only on traffic that satisfies the query. Our evaluation shows that Sonata can support a wide range of telemetry tasks while reducing the workload for the stream processor by as much as seven orders of magnitude compared to existing telemetry systems. Arpit Gupta, Rob Harrison, Marco Canini, Nick Feamster, Jennifer Rexford, Walter Willinger |
SIGCOMM | 4 |
| 2018 | How Do Tor Users Interact With Onion Services?
Philipp Winter, Anne Edmundson, Laura M. Roberts, Agnieszka Dutkowska-Zuk, Marshini Chetty, Nick Feamster |
USENIX Security Symposium | 6 |
| 2018 | User Perceptions of Smart Home IoT PrivacyabstractSmart home Internet of Things (IoT) devices are rapidly increasing in popularity, with more households including Internet-connected devices that continuously monitor user activities. In this study, we conduct eleven semi-structured interviews with smart home owners, investigating their reasons for purchasing IoT devices, perceptions of smart home privacy risks, and actions taken to protect their privacy from those external to the home who create, manage, track, or regulate IoT devices and/or their data. We note several recurring themes. First, users' desires for convenience and connectedness dictate their privacy-related behaviors for dealing with external entities, such as device manufacturers, Internet Service Providers, governments, and advertisers. Second, user opinions about external entities collecting smart home data depend on perceived benefit from these entities. Third, users trust IoT device manufacturers to protect their privacy but do not verify that these protections are in place. Fourth, users are unaware of privacy risks from inference algorithms operating on data from non-audio/visual devices. These findings motivate several recommendations for device designers, researchers, and industry standards to better match device privacy features to the expectations and preferences of smart home owners. Serena Zheng, Noah J. Apthorpe, Marshini Chetty, Nick Feamster |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2017 | The Effect of DNS on Tor's Anonymity
Benjamin Greschbach, Tobias Pulls, Laura M. Roberts, Philipp Winter, Nick Feamster |
NDSS | 5 |
| 2017 | Augur: Internet-Wide Detection of Connectivity DisruptionsabstractAnecdotes, news reports, and policy briefings collectively suggest that Internet censorship practices are pervasive. The scale and diversity of Internet censorship practices makes it difficult to precisely monitor where, when, and how censorship occurs, as well as what is censored. The potential risks in performing the measurements make this problem even more challenging. As a result, many accounts of censorship begin-and end-with anecdotes or short-term studies from only a handful of vantage points. We seek to instead continuously monitor information about Internet reachability, to capture the onset or termination of censorship across regions and ISPs. To achieve this goal, we introduce Augur, a method and accompanying system that utilizes TCP/IP side channels to measure reachability between two Internet locations without directly controlling a measurement vantage point at either location. Using these side channels, coupled with techniques to ensure safety by not implicating individual users, we develop scalable, statistically robust methods to infer network-layer filtering, and implement a corresponding system capable of performing continuous monitoring of global censorship. We validate our measurements of Internet-wide disruption in nearly 180 countries over 17 days against sites known to be frequently blocked, we also identify the countries where connectivity disruption is most prevalent. Paul Pearce, Roya Ensafi, Frank Li 0001, Nick Feamster, Vern Paxson |
IEEE Symposium on Security and Privacy | 4 |
| 2017 | Counter-RAPTOR: Safeguarding Tor Against Active Routing AttacksabstractTor is vulnerable to network-level adversaries who can observe both ends of the communication to deanonymize users. Recent work has shown that Tor is susceptible to the previously unknown active BGP routing attacks, called RAPTOR attacks, which expose Tor users to more network-level adversaries. In this paper, we aim to mitigate and detect such active routing attacks against Tor. First, we present a new measurement study on the resilience of the Tor network to active BGP prefix attacks. We show that ASes with high Tor bandwidth can be less resilient to attacks than other ASes. Second, we present a new Tor guard relay selection algorithm that incorporates resilience of relays into consideration to proactively mitigate such attacks. We show that the algorithm successfully improves the security for Tor clients by up to 36% on average (up to 166% for certain clients). Finally, we build a live BGP monitoring system that can detect routing anomalies on the Tor network in real time by performing an AS origin check and novel detection analytics. Our monitoring system successfully detects simulated attacks that are modeled after multiple known attack types as well as a real-world hijack attack (performed by us), while having low false positive rates. Yixin Sun 0004, Anne Edmundson, Nick Feamster, Mung Chiang, Prateek Mittal |
IEEE Symposium on Security and Privacy | 3 |
| 2017 | Global Measurement of DNS Manipulation
Paul Pearce, Ben Jones, Frank Li 0001, Roya Ensafi, Nick Feamster, Nicholas Weaver, Vern Paxson |
USENIX Security Symposium | 5 |
| 2016 | PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-RegistrationabstractMiscreants register thousands of new domains every day to launch Internet-scale attacks, such as spam, phishing, and drive-by downloads. Quickly and accurately determining a domain's reputation (association with malicious activity) provides a powerful tool for mitigating threats and protecting users. Yet, existing domain reputation systems work by observing domain use (e.g., lookup patterns, content hosted) often too late to prevent miscreants from reaping benefits of the attacks that they launch. As a complement to these systems, we explore the extent to which features evident at domain registration indicate a domain's subsequent use for malicious activity. We develop PREDATOR, an approach that uses only time-of-registration features to establish domain reputation. We base its design on the intuition that miscreants need to obtain many domains to ensure profitability and attack agility, leading to abnormal registration behaviors (e.g., burst registrations, textually similar names). We evaluate PREDATOR using registration logs of second-level .com and .net domains over five months. PREDATOR achieves a 70% detection rate with a false positive rate of 0.35%, thus making it an effective and early first line of defense against the misuse of DNS domains. It predicts malicious domains when they are registered, which is typically days or weeks earlier than existing DNS blacklists. Shuang Hao 0001, Alex Kantchelian, Brad Miller 0002, Vern Paxson, Nick Feamster |
CCS | 5 |
| 2016 | Half-Baked Cookies: Hardening Cookie-Based Authentication for the Modern WebabstractModern websites use multiple authentication cookies to allow visitors to the site different levels of access. The complexity of modern web applications can make it difficult for a web application programmer to ensure that the use of authentication cookies does not introduce vulnerabilities. Even when a programmer has access to all of the source code, this analysis can be challenging; the problem becomes even more vexing when web programmers cobble together off-the-shelf libraries to implement authentication. We have assembled a checklist for modern web programmers to verify that the cookie based authentication mechanism is securely implemented. Then, we developed a tool, Newton, to help a web application programmer to identify authentication cookies for specific parts of the website and to verify that they are securely implemented according to the checklist. We used Newton to analyze 149 sites, including the Alexa top-200 and many other popular sites across a range of categories including search, shopping, and finance. We found that 113 of them---including high-profile sites such as Yahoo, Amazon, and Fidelity---were vulnerable to hijacking attacks. Many websites have already acknowledged and fixed the vulnerabilities that we found using Newton and reported to them. Yogesh Mundada, Nick Feamster, Balachander Krishnamurthy |
AsiaCCS | 2 |
| 2016 | Network Monitoring as a Streaming Analytics ProblemabstractProgrammable switches potentially make it easier to perform flexible network monitoring queries at line rate, and scalable stream processors make it possible to fuse data streams to answer more sophisticated queries about the network in real-time. However, processing such network monitoring queries at high traffic rates requires both the switches and the stream processors to filter the traffic iteratively and adaptively so as to extract only that traffic that is of interest to the query at hand. While the realization that network monitoring is a streaming analytics problem has been made earlier, our main contribution in this paper is the design and implementation of Sonata, a closed-loop system that enables network operators to perform streaming analytics for network monitoring applications at scale. To achieve this objective, Sonata allows operators to express a network monitoring query by considering each packet as a tuple. More importantly, Sonata allows them to partition the query across both the switches and the stream processor, and through iterative refinement, Sonata's runtime attempts to extract only the traffic that pertains to the query, thus ensuring that the stream processor can scale to satisfy a large number of queries for traffic at very high rates. We show with a simple example query involving DNS reflection attacks and traffic traces from one of the world's largest IXPs that Sonata can capture 95% of all traffic pertaining to the query, while reducing the overall data rate by a factor of about 400 and the number of required counters by four orders of magnitude. Arpit Gupta, Rüdiger Birkner, Marco Canini, Nick Feamster, Chris Mac-Stoker, Walter Willinger |
HotNets | 4 |
| 2016 | An Industrial-Scale Software Defined Internet Exchange Point
Arpit Gupta, Robert MacDavid, Rüdiger Birkner, Marco Canini, Nick Feamster, Jennifer Rexford, Laurent Vanbever |
NSDI | 5 |
| 2016 | A Case Study of Traffic Demand Response to Broadband Service-Plan Upgrades
Sarthak Grover, Roya Ensafi, Nick Feamster |
PAM | 3 |
| 2016 | Detecting DNS Root Manipulation
Ben Jones, Nick Feamster, Vern Paxson, Nicholas Weaver, Mark Allman |
PAM | 2 |
| 2016 | Home Network or Access Link? Locating Last-Mile Downstream Throughput Bottlenecks
Srikanth Sundaresan, Nick Feamster, Renata Teixeira |
PAM | 2 |
| 2016 | A First Look into Transnational Routing DetoursabstractAn increasing number of countries are passing laws that facilitate the mass surveillance of their citizens. In response, governments and citizens are increasingly paying attention to the countries that their Internet traffic traverses. In some cases, countries are taking extreme steps, such as building new IXPs and encouraging local interconnection to keep local traffic local. We find that although many of these efforts are extensive, they are often futile, due to the inherent lack of hosting and route diversity for many popular sites. We investigate how the use of overlay network relays and the DNS open resolver infrastructure can prevent traffic from traversing certain jurisdictions. Anne Edmundson, Roya Ensafi, Nick Feamster, Jennifer Rexford |
SIGCOMM | 3 |
| 2016 | PISCES: A Programmable, Protocol-Independent Software SwitchabstractHypervisors use software switches to steer packets to and from virtual machines (VMs). These switches frequently need upgrading and customization—to support new protocol headers or encapsulations for tunneling and overlays, to improve measurement and debugging features, and even to add middlebox-like functions. Software switches are typically based on a large body of code, including kernel code, and changing the switch is a formidable undertaking requiring domain mastery of network protocol design and developing, testing, and maintaining a large, complex codebase. Changing how a software switch forwards packets should not require intimate knowledge of its implementation. Instead, it should be possible to specify how packets are processed and forwarded in a high-level domain-specific language (DSL) such as P4, and compiled to run on a software switch. We present PISCES, a software switch derived from Open vSwitch (OVS), a hard-wired hypervisor switch, whose behavior is customized using P4. PISCES is not hard-wired to specific protocols; this independence makes it easy to add new features. We also show how the compiler can analyze the high-level specification to optimize forwarding performance. Our evaluation shows that PISCES performs comparably to OVS and that PISCES programs are about 40 times shorter than equivalent changes to OVS source code. Muhammad Shahbaz 0001, Sean Choi, Ben Pfaff, Changhoon Kim, Nick Feamster, Nick McKeown, Jennifer Rexford |
SIGCOMM | 5 |
| 2016 | An Industrial-Scale Software Defined Internet Exchange Point
Arpit Gupta, Robert MacDavid, Rüdiger Birkner, Marco Canini, Nick Feamster, Jennifer Rexford, Laurent Vanbever |
USENIX ATC | 5 |
| 2016 | Identifying and Characterizing Sybils in the Tor Network
Philipp Winter, Roya Ensafi, Karsten Loesing, Nick Feamster |
USENIX Security Symposium | 4 |
| 2015 | uCap: An Internet Data Management Tool For The HomeabstractInternet Service Providers (ISPs) have introduced "data caps", or quotas on the amount of data that a customer can download during a billing cycle. Under this model, Internet users who reach a data cap can be subject to degraded performance, extra fees, or even temporary interruption of Internet service. For this reason, users need better visibility into and control over their Internet usage to help them understand what uses up data and control how these quotas are reached. In this paper, we present the design and implementation of a tool, called uCap, to help home users manage Internet data. We conducted a field trial of uCap in 21 home networks in three countries and performed an in-depth qualitative study of ten of these homes. We present the results of the evaluation and implications for the design of future Internet data management tools. Marshini Chetty, Hyojoon Kim, Srikanth Sundaresan, Sam Burnett, Nick Feamster, W. Keith Edwards |
CHI | 5 |
| 2015 | Can Censorship Measurements Be Safe(r)?abstractUnderstanding censorship requires performing widespread, continuous measurements "on the ground". Yet, measuring censorship is potentially dangerous, due to the threat of retaliation against citizens who perform measurements. We must balance measurement accuracy, reliability, and scalability with user safety which leads us to the question: Can we design censorship measurements that mitigate risk to the users who consent to perform them? Although it is almost certainly impossible to eliminate risk (or even determine if we have succeeded in doing so), we posit that we may be able to reduce risk with measurement techniques that are difficult to observe or distinguish from innocuous network activity. We observe that surveillance and censorship systems have different goals, and thus certain types of measurement techniques may be able to characterize a censorship system without triggering a surveillance system. We design and implement several techniques for measuring censorship that controlled tests suggest might be less risky than existing methods; we also highlight potential pitfalls, limitations, and avenues for future work. Ben Jones, Nick Feamster |
HotNets | 2 |
| 2015 | Examining How the Great Firewall Discovers Hidden Circumvention ServersabstractRecently, the operators of the national censorship infrastructure of China began to employ "active probing" to detect and block the use of privacy tools. This probing works by passively monitoring the network for suspicious traffic, then actively probing the corresponding servers, and blocking any that are determined to run circumvention servers such as Tor. Roya Ensafi, David Fifield, Philipp Winter, Nick Feamster, Nicholas Weaver, Vern Paxson |
Internet Measurement Conference | 4 |
| 2015 | Kinetic: Verifiable Dynamic Network Control
Hyojoon Kim, Joshua Reich, Arpit Gupta, Muhammad Shahbaz 0001, Nick Feamster, Russell J. Clark 0001 |
NSDI | 5 |
| 2015 | Measuring the Performance of User Traffic in Home Wireless Networks
Srikanth Sundaresan, Nick Feamster, Renata Teixeira |
PAM | 2 |
| 2015 | Encore: Lightweight Measurement of Web Censorship with Cross-Origin RequestsabstractDespite the pervasiveness of Internet censorship, we have scant data on its extent, mechanisms, and evolution. Measuring censorship is challenging: it requires continual measurement of reachability to many target sites from diverse vantage points. Amassing suitable vantage points for longitudinal measurement is difficult; existing systems have achieved only small, short-lived deployments. We observe, however, that most Internet users access content via Web browsers, and the very nature of Web site design allows browsers to make requests to domains with different origins than the main Web page. We present Encore, a system that harnesses cross-origin requests to measure Web filtering from a diverse set of vantage points without requiring users to install custom software, enabling longitudinal measurements from many vantage points. We explain how Encore induces Web clients to perform cross-origin requests that measure Web filtering, design a distributed platform for scheduling and collecting these measurements, show the feasibility of a global-scale deployment with a pilot study and an analysis of potentially censored Web content, identify several cases of filtering in six months of measurements, and discuss ethical concerns that would arise with widespread deployment. Sam Burnett, Nick Feamster |
SIGCOMM | 2 |
| 2015 | Alternative Trust Sources: Reducing DNSSEC Signature Verification Operations with TLSabstractDNSSEC has been in development for 20 years. It provides for provable security when retrieving domain names through the use of a public key infrastructure (PKI). Unfortunately, there is also significant overhead involved with DNSSEC: verifying certificate chains of signed DNS messages involves extra computation, queries to remote resolvers, additional transfers, and introduces added latency into the DNS query path. We pose the question: is it possible to achieve practical security without always verifying this certificate chain if we use a different, outside source of trust between resolvers? We believe we can. Namely, by using a long-lived, mutually authenticated TLS connection between pairs of DNS resolvers, we suggest that we can maintain near-equivalent levels of security with very little extra overhead compared to a non-DNSSEC enabled resolver. By using a reputation system or probabilistically verifying a portion of DNSSEC responses would allow for near-equivalent levels of security to be reached, even in the face of compromised resolvers. Sean Patrick Donovan, Nick Feamster |
SIGCOMM | 2 |
| 2015 | ASwatch: An AS Reputation System to Expose Bulletproof Hosting ASesabstractBulletproof hosting Autonomous Systems (ASes)-malicious ASes fully dedicated to supporting cybercrime-provide freedom and resources for a cyber-criminal to operate.Their services include hosting a wide range of illegal content, botnet C&C servers, and other malicious resources.Thousands of new ASes are registered every year, many of which are often used exclusively to facilitate cybercrime.A natural approach to squelching bulletproof hosting ASes is to develop a reputation system that can identify them for takedown by law enforcement and as input to other attack detection systems (e.g., spam filters, botnet detection systems).Unfortunately, current AS reputation systems rely primarily on data-plane monitoring of malicious activity from IP addresses (and thus can only detect malicious ASes after attacks are underway), and are not able to distinguish between malicious and legitimate but abused ASes.As a complement to these systems, in this paper, we explore a fundamentally different approach to establishing AS reputation.We present ASwatch, a system that identifies malicious ASes using exclusively the control-plane (i.e., routing) behavior of ASes.ASwatch's design is based on the intuition that, in an attempt to evade possible detection and remediation efforts, malicious ASes exhibit "agile" control plane behavior (e.g., short-lived routes, aggressive re-wiring).We evaluate our system on known malicious ASes; our results show that ASwatch detects up to 93% of malicious ASes with a 5% false positive rate, which is reasonable to effectively complement existing defense systems. CCS Concepts• Security and privacy → Maria Konte, Roberto Perdisci, Nick Feamster |
SIGCOMM | 3 |
| 2014 | Deniable LiaisonsabstractPeople sometimes need to communicate directly with one another while concealing the communication itself. Existing systems can allow users to achieve this level of privacy in the wide-area Internet, but parties who are in close proximity (e.g., a public square or coffee shop) may want a lightweight communications channel with similar properties. Today, covert exchanges in local settings typically require the exchange of physical media or involve other forms of direct communication (e.g., conversations, blind drops); most, if not all, of these exchanges are observable: in other words, even if the message exchanges are confidential, they are not covert or deniable. We construct a local communications channel that is unobservable to everyone except the parties exchanging messages. To do so, we take advantage of the ubiquitous phenomenon of packet corruption in wireless networks, which provide deniable cover for message exchange between parties within radio range. The communicating parties use a shared secret to differentiate truly corrupted frames from those that hide messages; to other parties, messages appear as corrupted wireless frames. We tackle the challenge of designing the observable corruption patterns to ensure that an observer can neither link sender and receiver of a hidden message(unlinkability), nor determine so much as the existence of any hidden message (deniability). We present the design and implementation of a prototype system that achieves these properties using off-the-shelf 802.11 hardware, evaluate its performance, and assess its resilience to various attacks. Abhinav Narain, Nick Feamster, Alex C. Snoeren |
CCS | 2 |
| 2014 | Intentional Network Monitoring: Finding the Needle without Capturing the HaystackabstractMonitoring network traffic serves many purposes, from security to accounting, yet current mechanisms for collecting network traffic are typically based on low-level features of network traffic (e.g., IP addresses, port numbers), rather than characteristics that more closely map to intent (e.g., people, applications, or devices). In this paper, we present the case for intentional network monitoring---the practice of capturing the minimal set of traffic that satisfies the operator's monitoring intent or goal---and a preliminary design and implementation for NetAssay, a system that enables intentional monitoring. A significant challenge in developing NetAssay is developing a runtime that can maintain a mapping between stable abstractions that an operator or programmer might use to express intent (e.g., a username) and the dynamic, heterogeneous data that establishes these associations (e.g., information from a login server or DNS record). We present examples that show how the NetAssay runtime can perform late binding between these mappings and network flow space and discuss the research and technical challenges associated with establishing more general late-binding mechanisms. Sean Patrick Donovan, Nick Feamster |
HotNets | 2 |
| 2014 | PEERING: An AS for UsabstractInternet routing suffers from persistent and transient failures, circuitous routes, oscillations, and prefix hijacks. A major impediment to progress is the lack of ways to conduct impactful interdomain research. Most research is based either on passive observation of existing routes, keeping researchers from assessing how the Internet will respond to route or policy changes; or simulations, which are restricted by limitations in our understanding of topology and policy. Brandon Schlinker, Kyriakos Zarifis, Ítalo S. Cunha, Nick Feamster, Ethan Katz-Bassett |
HotNets | 4 |
| 2014 | Automated Detection and Fingerprinting of Censorship Block PagesabstractOne means of enforcing Web censorship is to return a block page, which informs the user that an attempt to access a webpage is unsuccessful. Detecting block pages can provide a more complete picture of Web censorship, but automatically identifying block pages is difficult because Web content is dynamic, personalized, and may even be in different languages. Previous work has manually detected and identified block pages, which is difficult to reproduce; it is also time-consuming, which makes it difficult to perform continuous, longitudinal studies of censorship. This paper presents an automated method both to detect block pages and to fingerprint the filtering products that generate them. Our automated method enables continuous measurements of block pages; we found that our methods successfully detect 95% of block pages and identify five filtering tools, including a tool that had not been previously identified "in the wild". Ben Jones, Tzu-Wen Lee, Nick Feamster, Phillipa Gill |
Internet Measurement Conference | 3 |
| 2014 | Peering at the Internet's Frontier: A First Look at ISP Interconnectivity in Africa
Arpit Gupta, Matt Calder, Nick Feamster, Marshini Chetty, Enrico Calandro, Ethan Katz-Bassett |
PAM | 3 |
| 2014 | Exposing Inconsistent Web Search Results with Bobble
Xinyu Xing 0001, Wei Meng 0001, Dan Doozan, Nick Feamster, Wenke Lee, Alex C. Snoeren |
PAM | 4 |
| 2014 | NetAssay: providing new monitoring primitives for network operatorsabstractHome and business network operators have limited network statistics available over which management decisions can be made. Similarly, there are few triggered behaviors, such as usage or bandwidths cap for individual users, that are available. By looking at sources of traffic, based on Domain Name System (DNS) cues for content of particular web addresses or source Autonomous System (AS) of the traffic, network operators could create new and interesting rules for their network. NetAssay is a Software-Defined Networking (SDN)-based, network-wide monitoring and reaction framework. By integrating information from Border Gateway Protocol (BGP) and the Domain Name System, NetAssay is able to integrate formerly disparate sources of control information, and use it to provide better monitoring, more useful triggered events, and security benefits for network operators. Sean Patrick Donovan, Nick Feamster |
SIGCOMM | 2 |
| 2014 | SDX: a software defined internet exchangeabstractBGP severely constrains how networks can deliver traffic over the Internet. Today's networks can only forward traffic based on the destination IP prefix, by selecting among routes offered by their immediate neighbors. We believe Software Defined Networking (SDN) could revolutionize wide-area traffic delivery, by offering direct control over packet-processing rules that match on multiple header fields and perform a variety of actions. Internet exchange points (IXPs) are a compelling place to start, given their central role in interconnecting many networks and their growing importance in bringing popular content closer to end users. Arpit Gupta, Laurent Vanbever, Muhammad Shahbaz 0001, Sean Patrick Donovan, Brandon Schlinker, Nick Feamster, Jennifer Rexford, Scott Shenker, Russell J. Clark 0001, Ethan Katz-Bassett |
SIGCOMM | 6 |
| 2014 | SDX: a software defined internet exchangeabstractBGP severely constrains how networks can deliver traffic over the Internet. Today's networks can only forward traffic based on the destination IP prefix, by selecting among routes offered by their immediate neighbors. We believe Software Defined Networking (SDN) could revolutionize wide-area traffic delivery, by offering direct control over packet-processing rules that match on multiple header fields and perform a variety of actions. Internet exchange points (IXPs) are a compelling place to start, given their central role in interconnecting many networks and their growing importance in bringing popular content closer to end users. To realize a Software Defined IXP (an "SDX"), we need new programming abstractions that allow participating networks to create and run these applications and a runtime that both behaves correctly when interacting with BGP and ensures that applications do not interfere with each other. We must also ensure that the system scales, both in rule-table size and computational overhead. In this demo, we show how we tackle these challenges demonstrating the flexibility and scalability of our SDX platform. The paper also appears in the main program. Arpit Gupta, Laurent Vanbever, Muhammad Shahbaz 0001, Sean Patrick Donovan, Brandon Schlinker, Nick Feamster, Jennifer Rexford, Scott Shenker, Russell J. Clark 0001, Ethan Katz-Bassett |
SIGCOMM | 6 |
| 2014 | Locating throughput bottlenecks in home networksabstractWe present a demonstration of WTF (Where's The Fault?), a system that localizes performance problems in home and access networks. We implement WTF as custom firmware that runs in an off-the-shelf home router. WTF uses timing and buffering information from passively monitored traffic at home routers to detect both access link and wireless network bottlenecks. Srikanth Sundaresan, Nick Feamster, Renata Teixeira |
SIGCOMM | 2 |
| 2014 | BISmark: A Testbed for Deploying Measurements and Applications in Broadband Access Networks
Srikanth Sundaresan, Sam Burnett, Nick Feamster, Walter de Donato |
USENIX ATC | 3 |
| 2013 | SilverLine: preventing data leaks from compromised web applicationsabstractWeb applications can have vulnerabilities that result in server-side data leaks. Securing sensitive data from Web applications while ensuring reasonable performance and without requiring developers to rewrite entire applications is challenging. We present SilverLine, which prevents bulk data leaks caused due to code injection in Web applications as well as compromised user-level processes on the application server. SilverLine uses login information to associate a user with each Web session; it then taints each file and database record and applies information-flow tracking to the data associated with each session to ensure that application data is released only to sessions of authorized users. SilverLine focuses on isolating data between user sessions and is thus most suitable to applications that involve single user sessions (e.g., banking, e-commerce). We have implemented SilverLine on Linux; our implementation demonstrates that SilverLine can protect a PHP-based Web application from many of the most common server-side Web application attacks by modifying only about 60 lines of code from the original application. Our evaluation shows that SilverLine incurs a performance overhead of about 20-30% over unmodified applications. Yogesh Mundada, Anirudh Ramachandran, Nick Feamster |
ACSAC | 3 |
| 2013 | Architecture for an open source network testerabstractTo make networks more reliable, enormous resources are poured into all phases of the network-equipment lifecycle. The process starts early in the design phase when simulation is used to verify the correctness of a design, and continues through manufacturing and perhaps months of rigorously trials. With over 7,000 Internet RFCs and hundreds of IEEE standards, a typical piece of networking equipment undergoes hundreds of conformance tests before being deployed. Finally, when deployed in a production network, the equipment is tested regularly. Throughout the process, a relentless battery of tests and measurement help ensure the correct operation of the equipment. Muhammad Shahbaz 0001, Gianni Antichi, Yilong Geng, Noa Zilberman, G. Adam Covington, Marc Bruyere, Nick Feamster, Nick McKeown, Bob Felderman, Michaela Blott, Andrew W. Moore 0002, Philippe Owezarski |
ANCS | 7 |
| 2013 | Peeking behind the NAT: an empirical study of home networksabstractWe present the first empirical study of home network availability, infrastructure, and usage, using data collected from home networks around the world. In each home, we deploy a router with custom firmware to collect information about the availability of home broadband network connectivity, the home network infrastructure (including the wireless connectivity in each home network and the number of devices connected to the network), and how people in each home network use the network. Downtime is more frequent and longer in developing countries---sometimes due to the network, and in other cases because they simply turn their home router off. We also find that some portions of the wireless spectrum are extremely crowded, that diurnal patterns are more pronounced during the week, and that most traffic in home networks is exchanged over a few connections to a small number of domains. Our study is both a preliminary view into many home networks and an illustration of how measurements from a home router can yield significant information about home networks. Sarthak Grover, Mi Seon Park, Srikanth Sundaresan, Sam Burnett, Hyojoon Kim, Bharath Ravi, Nick Feamster |
Internet Measurement Conference | 7 |
| 2013 | Understanding the domain registration behavior of spammersabstractSpammers register a tremendous number of domains to evade blacklisting and takedown efforts. Current techniques to detect such domains rely on crawling spam URLs or monitoring lookup traffic. Such detection techniques are only effective after the spammers have already launched their campaigns, and thus these countermeasures may only come into play after the spammer has already reaped significant benefits from the dissemination of large volumes of spam. In this paper we examine the registration process of such domains, with a particular eye towards features that might indicate that a given domain likely has a malicious purpose at registration time, before it is ever used for an attack. Our assessment includes exploring the characteristics of registrars, domain life cycles, registration bursts, and naming patterns. By investigating zone changes from the .com TLD over a 5-month period, we discover that spammers employ bulk registration, that they often re-use domains previously registered by others, and that they tend to register and host their domains over a small set of registrars. Our findings suggest steps that registries or registrars could use to frustrate the efforts of miscreants to acquire domains in bulk, ultimately reducing their agility for mounting large-scale attacks. Shuang Hao 0001, Matthew Thomas, Vern Paxson, Nick Feamster, Christian Kreibich, Chris Grier, Scott Hollenbeck |
Internet Measurement Conference | 4 |
| 2013 | Community contribution award - Measuring and mitigating web performance bottlenecks in broadband access networksabstractWe measure Web performance bottlenecks in home broadband access networks and evaluate ways to mitigate these bottlenecks with caching within home networks. We first measure Web performance bottlenecks to nine popular Web sites from more than 5,000 broadband access networks and demonstrate that when the downstream throughput of the access link exceeds about 16 Mbits/s, latency is the main bottleneck for Web page load time. Next, we use a router-based Web measurement tool, Mirage, to deconstruct Web page load time into its constituent components (DNS lookup, TCP connection setup, object download) and show that simple latency optimizations can yield significant improvements in overall page load times. We then present a case for placing a cache in the home network and deploy three common optimizations: DNS caching, TCP connection caching, and content caching. We show that caching only DNS and TCP connections yields significant improvements in page load time, even when the user's browser is already performing similar independent optimizations. Finally, we use traces from real homes to demonstrate how prefetching DNS and TCP connections for popular sites in a home-router cache can achieve faster page load times. Srikanth Sundaresan, Nick Feamster, Renata Teixeira, Nazanin Magharei |
Internet Measurement Conference | 2 |
| 2013 | Characterizing correlated latency anomalies in broadband access networksabstractThe growing prevalence of broadband Internet access around the world has made understanding the performance and reliability of broadband access networks extremely important. To better understand the performance anomalies that arise in broadband access networks, we have deployed hundreds of routers in home broadband access networks around the world and are studying the performance of these networks. One of the performance pathologies that we have observed is correlated, sudden latency increases simultaneously and to multiple destinations. In this work, we provide an preliminary glimpse into these sudden latency increases and attempt to understand their causes. Although we do not isolate root cause in this study, observing the sets of destinations that experience correlated latency increases can provide important clues as to the locations in the network that may be inducing these pathologies. We present an algorithm to better identify the network locations that are likely responsible for these pathologies. We then analyze latency data from one month across our home router deployment to determine where in the network latency issues are arising, and how those pathologies differ across regions, ISPs, and countries. Our preliminary analysis suggests that most latency pathologies are to a single destination and a relatively small percentage of these pathologies are likely in the last mile, suggesting that peering within the network may be a more likely culprit for these pathologies than access link problems. Swati Roy, Nick Feamster |
SIGCOMM | 2 |
| 2013 | Web performance bottlenecks in broadband access networksabstractWe present the first large-scale analysis of Web performance bottlenecks as measured from broadband access networks, using data collected from extensive home router deployments. We analyze the limits of throughput on improving Web performance and identify the contribution of critical factors such as DNS lookups and TCP connection establishment to Web page load times. We find that, as broadband speeds continue to increase, other factors such as TCP connection setup time, server response time, and network latency are often dominant performance bottlenecks. Thus, realizing a "faster Web" requires not only higher download throughput, but also optimizations to reduce both client and server-side latency. Srikanth Sundaresan, Nazanin Magharei, Nick Feamster, Renata Teixeira, Sam Crawford |
SIGMETRICS | 3 |
| 2013 | Quantifying the benefits of joint content and network routingabstractOnline service providers aim to provide good performance for an increasingly diverse set of applications and services. One of the most effective ways to improve service performance is to replicate the service closer to the end users. Replication alone, however, has its limits: while operators can replicate static content, wide-scale replication of dynamic content is not always feasible or cost effective. To improve the latency of such services many operators turn to Internet traffic engineering. In this paper, we study the benefits of performing replica-to-end-user mappings in conjunction with active Internet traffic engineering. We present the design of PECAN, a system that controls both the selection of replicas ("content routing") and the routes between the clients and their associated replicas ("network routing"). We emulate a replicated service that can perform both content and network routing by deploying PECAN on a distributed testbed. In our testbed, we see that jointly performing content and network routing can reduce round-trip latency by 4.3% on average over performing content routing alone (potentially reducing service response times by tens of milliseconds or more) and that most of these gains can be realized with no more than five alternate routes at each replica. Vytautas Valancius, Bharath Ravi, Nick Feamster, Alex C. Snoeren |
SIGMETRICS | 3 |
| 2013 | Take This Personally: Pollution Attacks on Personalized Services
Xinyu Xing 0001, Wei Meng 0001, Dan Doozan, Alex C. Snoeren, Nick Feamster, Wenke Lee |
USENIX Security Symposium | 5 |
| 2013 | Answering "What-If" Deployment and Configuration Questions With WISE: Techniques and Deployment ExperienceabstractDesigners of content distribution networks (CDNs) often need to determine how changes to infrastructure deployment and configuration affect service response times when they deploy a new data center, change ISP peering, or change the mapping of clients to servers. Today, the designers use coarse, back-of-the-envelope calculations or costly field deployments; they need better ways to evaluate the effects of such hypothetical “what-if” questions before the actual deployments. This paper presents What-If Scenario Evaluator (WISE), a tool that predicts the effects of possible configuration and deployment changes in content distribution networks. WISE makes three contributions: 1) an algorithm that uses traces from existing deployments to learn causality among factors that affect service response time distributions; 2) an algorithm that uses the learned causal structure to estimate a dataset that is representative of the hypothetical scenario that a designer may wish to evaluate, and uses these datasets to predict hypothetical response-time distributions; 3) a scenario specification language that allows a network designer to easily express hypothetical deployment scenarios without being cognizant of the dependencies between variables that affect service response times. Our evaluation, both in a controlled setting and in a real-world field deployment on a large, global CDN, shows that WISE can quickly and accurately predict service response-time distributions for many practical what-if scenarios. Muhammad Mukarram Bin Tariq, Kaushik Bhandankar, Vytautas Valancius, Amgad Zeitoun, Nick Feamster, Mostafa H. Ammar |
IEEE/ACM Trans. Netw. | 5 |
| 2012 | CORONET: Fault tolerance for Software Defined NetworksabstractSoftware Defined Networking, or SDN, based networks are being deployed not only in testbed networks, but also in production networks. Although fault-tolerance is one of the most desirable properties in production networks, there are not much study in providing fault-tolerance to SDN-based networks. The goal of this work is to develop a fault tolerant SDN architecture that can rapidly recover from faults and scale to large network sizes. This paper presents CORONET, a SDN fault-tolerant system that recovers from multiple link failures in the data plane. We describe a prototype implementation based on NOX that demonstrates fault recovery for emulated topologies using Mininet. We also discuss possible extensions to handle control plane and controller faults. Hyojoon Kim, Mike Schlansker, Jose Renato Santos, Jean Tourrilhes, Yoshio Turner, Nick Feamster |
ICNP | 6 |
| 2012 | #bias: Measuring the Tweeting Behavior of Propagandists
Cristian Lumezanu, Nick Feamster, Hans Klein |
ICWSM | 2 |
| 2012 | Observing common spam in Twitter and emailabstractSpam is pervasive across many types of electronic communication, including email, instant messaging, and social networks. To reach more users and increase financial gain, many spammers now use multiple content-sharing platforms---including online social networks---to disseminate spam. In this paper, we perform a joint analysis of spam in email and social networks. We use spam data from Yahoo's web-based email service and from Twitter to characterize the publishing behavior and effectiveness of spam advertised across both platforms. We show that email spammers that also advertise on Twitter tend to send more email spam than those advertising exclusively through email. Further, we use DNS lookup information to show that sending spam on both email and Twitter correlates with a significant increase in coverage: spam domains appearing on both platforms are looked up by an order of magnitude more networks than domains using just one of the two platforms. Cristian Lumezanu, Nick Feamster |
Internet Measurement Conference | 2 |
| 2012 | Re-wiring Activity of Malicious Networks
Maria Konte, Nick Feamster |
PAM | 2 |
| 2012 | LIFEGUARD: practical repair of persistent route failuresabstractThe Internet was designed to always find a route if there is a policy-compliant path. However, in many cases, connectivity is disrupted despite the existence of an underlying valid path. The research community has focused on short-term outages that occur during route convergence. There has been less progress on addressing avoidable long-lasting outages. Our measurements show that long-lasting events contribute significantly to overall unavailability. Ethan Katz-Bassett, Colin Scott, David R. Choffnes, Ítalo S. Cunha, Vytautas Valancius, Nick Feamster, Harsha V. Madhyastha, Thomas E. Anderson, Arvind Krishnamurthy |
SIGCOMM | 6 |
| 2012 | Accelerating last-mile web performance with popularity-based prefetchingabstractNo abstract available. Srikanth Sundaresan, Nazanin Magharei, Nick Feamster, Renata Teixeira |
SIGCOMM | 3 |
| 2011 | Boosting the scalability of botnet detection using adaptive traffic samplingabstractBotnets pose a serious threat to the health of the Internet. Most current network-based botnet detection systems require deep packet inspection (DPI) to detect bots. Because DPI is a computational costly process, such detection systems cannot handle large volumes of traffic typical of large enterprise and ISP networks. In this paper we propose a system that aims to efficiently and effectively identify a small number of suspicious hosts that are likely bots. Their traffic can then be forwarded to DPI-based botnet detection systems for fine-grained inspection and accurate botnet detection. By using a novel adaptive packet sampling algorithm and a scalable spatial-temporal flow correlation approach, our system is able to substantially reduce the volume of network traffic that goes through DPI, thereby boosting the scalability of existing botnet detection systems. We implemented a proof-of-concept version of our system, and evaluated it using real-world legitimate and botnet-related network traces. Our experimental results are very promising and suggest that our approach can enable the deployment of botnet-detection systems in large, high-speed networks. Junjie Zhang 0004, Xiapu Luo, Roberto Perdisci, Guofei Gu, Wenke Lee, Nick Feamster |
AsiaCCS | 6 |
| 2011 | Monitoring the initial DNS behavior of malicious domainsabstractAttackers often use URLs to advertise scams or propagate malware. Because the reputation of a domain can be used to identify malicious behavior, miscreants often register these domains "just in time" before an attack. This paper explores the DNS behavior of attack domains, as identified by appearance in a spam trap, shortly after the domains were registered. We explore the behavioral properties of these domains from two perspectives: (1) the DNS infrastructure associated with the domain, as is observable from the resource records; and (2) the DNS lookup patterns from networks who are looking up the domains initially. Our analysis yields many findings that may ultimately be useful for early detection of malicious domains. By monitoring the infrastructure for these malicious domains, we find that about 55% of scam domains occur in attacks at least one day after registration, suggesting the potential for early discovery of malicious domains, solely based on properties of the DNS infrastructure that resolves those domains. We also find that there are a few regions of IP address space that host name servers and other types of servers for only malicious domains. Malicious domains have resource records that are distributed more widely across IP address space, and they are more quickly looked up by a variety of different networks. We also identify a set of "tainted" ASes that are used heavily by bad domains to host resource records. The features we observe are often evident before any attack even takes place; ultimately, they might serve as the basis for a DNS-based early warning system for attacks. Shuang Hao 0001, Nick Feamster, Ramakant Pandrangi |
Internet Measurement Conference | 2 |
| 2011 | The evolution of network configuration: a tale of two campusesabstractStudying network configuration evolution can improve our understanding of the evolving complexity of networks and can be helpful in making network configuration less error-prone. Unfortunately, the nature of changes that operators make to network configuration is poorly understood. Towards improving our understanding, we examine and analyze five years of router, switch, and firewall configurations from two large campus networks using the logs from version control systems used to store the configurations. We study how network configuration is distributed across different network operations tasks and how the configuration for each task evolves over time, for different types of devices and for different locations in the network. To understand the trends of how configuration evolves over time, we study the extent to which configuration for various tasks are added, modified, or deleted. We also study whether certain devices experience configuration changes more frequently than others, as well as whether configuration changes tend to focus on specific portions of the configuration (or on specific tasks). We also investigate when network operators make configuration changes of various types. Our results concerning configuration changes can help the designers of configuration languages understand which aspects of configuration might be more automated or tested more rigorously and may ultimately help improve configuration languages. Hyojoon Kim, Theophilus Benson, Aditya Akella, Nick Feamster |
Internet Measurement Conference | 4 |
| 2011 | Communicating with caps: managing usage caps in home networksabstractAs Internet service providers increasingly implement and impose "usage caps", consumers need better ways to help them understand and control how devices in the home use up the available network resources or available capacity. Towards this goal, we will demonstrate a system that allows users to monitor and manage their usage caps. The system uses the BISMark firmware running on network gateways to collect usage statistics and report them to a logically centralized controller, which displays usage information. The controller allows users to specify policies about how different people, devices, and applications should consume the usage cap; it implements and enforces these policies via a secure OpenFlow control channel to each gateway device. The demonstration will show various use cases, such as limiting the usage of a particular application, visualizing usage statistics, and allowing users within a single household to "trade" caps with one another. Hyojoon Kim, Srikanth Sundaresan, Marshini Chetty, Nick Feamster, W. Keith Edwards |
SIGCOMM | 4 |
| 2011 | Wide-area routing dynamics of malicious networksabstractThis paper studies the routing dynamics of malicious networks. We characterize the routing behavior of malicious networks on both short and long timescales. We find that malicious networks more consistently advertise prefixes with short durations and long inter- arrival times; over longer timescales, we find that malicious ASes connect with more upstream providers than legitimate ASes, and they also change upstream providers more frequently. Maria Konte, Nick Feamster |
SIGCOMM | 2 |
| 2011 | Broadband internet performance: a view from the gatewayabstractWe present the first study of network access link performance measured directly from home gateway devices. Policymakers, ISPs, and users are increasingly interested in studying the performance of Internet access links. Because of many confounding factors in a home network or on end hosts, however, thoroughly understanding access network performance requires deploying measurement infrastructure in users' homes as gateway devices. In conjunction with the Federal Communication Commission's study of broadband Internet access in the United States, we study the throughput and latency of network access links using longitudinal measurements from nearly 4,000 gateway devices across 8 ISPs from a deployment of over 4,200 devices. We study the performance users achieve and how various factors ranging from the user's choice of modem to the ISP's traffic shaping policies can affect performance. Our study yields many important findings about the characteristics of existing access networks. Our findings also provide insights into the ways that access network performance should be measured and presented to users, which can help inform ongoing broader efforts to benchmark the performance of access networks. Srikanth Sundaresan, Walter de Donato, Nick Feamster, Renata Teixeira, Sam Crawford, Antonio Pescapè |
SIGCOMM | 3 |
| 2011 | How many tiers?: pricing in the internet transit marketabstractISPs are increasingly selling "tiered" contracts, which offer Internet connectivity to wholesale customers in bundles, at rates based on the cost of the links that the traffic in the bundle is traversing. Although providers have already begun to implement and deploy tiered pricing contracts, little is known about how to structure them. While contracts that sell connectivity on finer granularities improve market efficiency, they are also more costly for ISPs to implement and more difficult for customers to understand. Our goal is to analyze whether current tiered pricing practices in the wholesale transit market yield optimal profits for ISPs and whether better bundling strategies might exist. In the process, we deliver two contributions: 1) we develop a novel way of mapping traffic and topology data to a demand and cost model, and 2) we fit this model on three large real-world networks: an European transit ISP, a content distribution network, and an academic research network, and run counterfactuals to evaluate the effects of different bundling strategies. Our results show that the common ISP practice of structuring tiered contracts according to the cost of carrying the traffic flows (e.g., offering a discount for traffic that is local) can be suboptimal and that dividing contracts based on both traffic demand and the cost of carrying it into only three or four tiers yields near-optimal profit for the ISP. Vytautas Valancius, Cristian Lumezanu, Nick Feamster, Ramesh Johari, Vijay V. Vazirani |
SIGCOMM | 3 |
| 2010 | Joint analysis of network incidents and intradomain routing changesabstractThis paper studies how intradomain routing instability relates to events in network trouble tickets for two networks: a VPN provider and the Internet2 backbone network. Our goal in performing this joint analysis of routing and trouble tickets is to better understand the likely underlying causes of intradomain routing instability. We develop a method to correlate trouble tickets with instability events and find that, although unplanned events last longer than scheduled maintenance, there is no single underlying cause for most instability, and that these causes differ across networks. In comparison to a similar study from Labovitz et al. from ten years ago, we find that, while certain causes of instability such as maintenance and circuit problems remain significant, power issues have become much less prevalent, and software-related problems have become more common. Amelie Medem Kuatse, Renata Teixeira, Nick Feamster, Mickael Meulle |
CNSM | 3 |
| 2010 | Decoupling policy from configuration in campus and enterprise networksabstractThis paper surveys our ongoing work on the use of software-defined networking to simplify two acute policy problems in campus and enterprise network operations: access control and information flow control. We describe how the current coupling of high-level policy with low-level configuration makes these problems challenging today. We describe the specific policy problems faced by campus and enterprise network operators; illustrate our approach, which leverages recent trends in separating the network's “control plane” from the data plane; and show how this approach can be applied to simplify these two enterprise network management tasks. We also describe our ongoing deployment efforts to build a campus network testbed where trial designs can be deployed and evaluated. We close with a summary of current and future research challenges for solving challenges within enterprise networks within the context of this new paradigm. Nick Feamster, Ankur Kumar Nayak, Hyojoon Kim, Russell J. Clark 0001, Yogesh Mundada, Anirudh Ramachandran, Muhammad Mukarram Bin Tariq |
LANMAN | 1 |
| 2010 | Behavioral Clustering of HTTP-Based Malware and Signature Generation Using Malicious Network Traces
Roberto Perdisci, Wenke Lee, Nick Feamster |
NSDI | 3 |
| 2010 | SwitchBlade: a platform for rapid deployment of network protocols on programmable hardwareabstractWe present SwitchBlade, a platform for rapidly deploying custom protocols on programmable hardware. SwitchBlade uses a pipeline-based design that allows individual hardware modules to be enabled or disabled on the fly, integrates software exception handling, and provides support for forwarding based on custom header fields. SwitchBlade's ease of programmability and wire-speed performance enables rapid prototyping of custom data-plane functions that can be directly deployed in a production network. SwitchBlade integrates common packet-processing functions as hardware modules, enabling different protocols to use these functions without having to resynthesize hardware. SwitchBlade's customizable forwarding engine supports both longest-prefix matching in the packet header and exact matching on a hash value. SwitchBlade's software exceptions can be invoked based on either packet or flow-based rules and updated quickly at runtime, thus making it easy to integrate more flexible forwarding function into the pipeline. SwitchBlade also allows multiple custom data planes to operate in parallel on the same physical hardware, while providing complete isolation for protocols running in parallel. We implemented SwitchBlade using NetFPGA board, but SwitchBlade can be implemented with any FPGA. To demonstrate SwitchBlade's flexibility, we use SwitchBlade to implement and evaluate a variety of custom network protocols: we present instances of IPv4, IPv6, Path Splicing, and an OpenFlow switch, all running in parallel while forwarding packets at line rate. Muhammad Bilal Anwer, Murtaza Motiwala, Muhammad Mukarram Bin Tariq, Nick Feamster |
SIGCOMM | 4 |
| 2010 | Circumventing censorship with collageabstractOppressive regimes and even democratic governments restrict Internet access. Existing anti-censorship systems often require users to connect through proxies, but these systems are relatively easy for a censor to discover and block. We explore a possible next step in the censorship arms race: rather than relying on a single system or set of proxies to circumvent censorship firewalls, we use the vast deployment of sites that host user-generated content to breach these firewalls. We have developed Collage, which allows users to exchange messages through hidden channels in sites that host user-generated content. To send a message, a user embeds it into cover traffic and posts the content on some site, where receivers retrieve this content. Collage makes it difficult for a censor to monitor or block these messages by exploiting the sheer number of sites where users can exchange messages and the variety of ways that a message can be hidden. Sam Burnett, Nick Feamster, Santosh S. Vempala |
SIGCOMM | 2 |
| 2010 | Autonomous traffic engineering with self-configuring topologiesabstractNetwork operators use traffic engineering (TE) to control the flow of traffic across their networks. Existing TE methods require manual configuration of link weights or tunnels, which is difficult to get right, or prior knowledge of traffic demands and hence may not be robust to link failures or traffic fluctuations. We present a self-configuring TE scheme, SculpTE, which automatically adapts the network-layer topology to changing traffic demands. SculpTE is responsive, stable, and achieves excellent load balancing. Srikanth Sundaresan, Cristian Lumezanu, Nick Feamster, Pierre François |
SIGCOMM | 3 |
| 2010 | Transit portal: BGP connectivity as a serviceabstractNo abstract available. Vytautas Valancius, Hyojoon Kim, Nick Feamster |
SIGCOMM | 3 |
| 2010 | Wide-Area Route Control for Distributed Services
Vytautas Valancius, Nick Feamster, Jennifer Rexford, Akihiro Nakao |
USENIX ATC | 2 |
| 2010 | Building a Dynamic Reputation System for DNS
Manos Antonakakis, Roberto Perdisci, David Dagon, Wenke Lee, Nick Feamster |
USENIX Security Symposium | 5 |
| 2010 | Chipping Away at Censorship Firewalls with User-Generated Content
Sam Burnett, Nick Feamster, Santosh S. Vempala |
USENIX Security Symposium | 2 |
| 2009 | Detecting network neutrality violations with causal inferenceabstractWe present NANO, a system that detects when ISPs apply policies that discriminate against specific classes of applications, users, or destinations. Existing systems for detecting discrimination are typically specific to an application or to a particular discrimination mechanism and rely on active measurement tests. Unfortunately, ISPs can change discrimination policies and mechanisms, and they can evade these tests by giving probe traffic higher priority. NANO detects ISP discrimination by passively collecting performance data from clients. To distinguish discrimination from other causes of degradation (e.g., overload, misconfiguration, failure), NANO establishes a causal relationship between an ISP and observed performance by adjusting for confounding factors. NANO agents deployed at participating clients across the Internet collect performance data for selected services and report this information to centralized servers, which analyze the measurements to establish causal relationship between an ISP and performance degradations. We have implemented NANO and deployed clients in a controlled environment on Emulab. We run a combination of controlled experiments on Emulab and wide-area experiments on PlanetLab that show that NANO can determine the extent and criteria for discrimination for a variety of discrimination policies and applications. Muhammad Mukarram Bin Tariq, Murtaza Motiwala, Nick Feamster, Mostafa H. Ammar |
CoNEXT | 3 |
| 2009 | Measurement methods for fast and accurate blackhole identification with binary tomographyabstractAbstract: Binary tomography—the process of identifying faulty network links through coordinated end-to-end probes—is a promising method for detecting failures that the network does not automatically mask (e.g., network “blackholes”). Because tomography is sensitive to the quality of the input, however, naive end-to-end measurements can introduce inaccuracies. This paper develops two methods for generating inputs to binary tomography algorithms that improve their inference speed and accuracy. Failure confirmation is a per-path probing technique to distinguish packet losses caused by congestion from persistent link or node failures. Aggregation strategies combine path measurements from unsynchronized monitors into a set of consistent observations. When used in conjunction with existing binary tomography algorithms, our methods identify all failures that are longer than two measurement cycles while inducing relatively few false alarms. In two wide-area networks, our techniques decrease the number of alarms by as much as two orders of magnitude. Compared to the state of the art in Ítalo S. Cunha, Renata Teixeira, Nick Feamster, Christophe Diot |
Internet Measurement Conference | 3 |
| 2009 | Characterizing VLAN-induced sharing in a campus networkabstractMany enterprise, campus, and data-center networks have complex layer-2 virtual LANs ("VLANs") below the IP layer. The interaction between layer-2 and IP topologies in these VLANs introduces hidden dependencies between IP level network and the physical infrastructure that has implications for network management tasks such as planning for capacity or reliability, and for fault diagnosis. This paper characterizes the extent and effect of these dependencies in a large campus network. We first present the design and implementation of EtherTrace, a tool that we make publicly available, which infers the layer-2 topology using data passively collected from Ethernet switches. Using this tool, we infer the layer-2 topology for a large campus network and compare it with the IP topology. We find that almost 70% of layer-2 edges are shared by 10 or more IP edges, and a single layer-2 edge may be shared by as many as 34 different IP edges. This sharing of layer-2 edges and switches among IP paths commonly results from trunking multiple VLANs to the same access router, or from colocation of academic departments that share layer-2 infrastructure, but have logically separate IP subnet and routers. We examine how this sharing affects the accuracy and specificity of fault diagnosis. For example, applying network tomography to the IP topology to diagnose failures caused by layer-2 devices results in only 54% accuracy, compared to 100% accuracy when our tomography algorithm takes input across layers. Muhammad Mukarram Bin Tariq, Ahmed Mansy, Nick Feamster, Mostafa H. Ammar |
Internet Measurement Conference | 3 |
| 2009 | Dynamics of Online Scam Hosting Infrastructure
Maria Konte, Nick Feamster, Jaeyeon Jung |
PAM | 2 |
| 2009 | Detecting Spammers with SNARE: Spatio-temporal Network-level Automatic Reputation Engine
Shuang Hao 0001, Nadeem Ahmed Syed, Nick Feamster, Alexander G. Gray, Sven Krasser |
USENIX Security Symposium | 3 |
| 2008 | Trellis: a platform for building flexible, fast virtual networks on commodity hardwareabstractWe describe Trellis, a platform for hosting virtual networks on shared commodity hardware. Trellis allows each virtual network to define its own topology, control protocols, and forwarding tables, while amortizing costs by sharing the physical infrastructure. Trellis synthesizes two container-based virtualization technologies, VServer and NetNS, as well as a new tunneling mechanism, EGRE, into a coherent platform that enables high-speed virtual networks. We describe the design and implementation of Trellis and evaluate its packet-forwarding rates relative to other virtualization technologies and native kernel forwarding performance. Sapan Bhatia, Murtaza Motiwala, Wolfgang Mühlbauer, Yogesh Mundada, Vytautas Valancius, Andy C. Bavier, Nick Feamster, Larry L. Peterson, Jennifer Rexford |
CoNEXT | 7 |
| 2008 | Distinguishing persistent failures from transient lossesabstractNetwork tomography is a promising technique to identify the location of of IP faults. The goal of tomography is to infer the status of network internal characteristics based on end-to-end observations. In particular, binary tomography identifies the set of failed links from end-to-end path meausrments. Upon detecting the failure of one or more of the monitored paths, a monitor sends its measurements to a central coordinator. The coordinator then runs the binary tomography algorithm, which takes as input the topology of the network and the status (i.e., up or down) of all monitored paths and finds the minimum set of links that explain the observations. Ítalo S. Cunha, Renata Teixeira, Nick Feamster, Christophe Diot |
CoNEXT | 3 |
| 2008 | MINT: a Market for INternet TransitabstractToday's Internet's routing paths are inefficient with respect to both connectivity and the market for interconnection. The former manifests itself via needlessly long paths, de-peering, etc. The latter arises because of a primitive market structure that results in unfulfilled demand and unused capacity. Today's networks make pairwise, myopic interconnection decisions based on business considerations that may not mirror considerations of the edge networks (or end systems) that would benefit from the existence of a particular interconnection. These bilateral contracts are also complex and difficult to enforce. Vytautas Valancius, Nick Feamster, Ramesh Johari, Vijay V. Vazirani |
CoNEXT | 2 |
| 2008 | NANO: Network Access Neutrality Observatory
Muhammad Mukarram Bin Tariq, Murtaza Motiwala, Nick Feamster |
HotNets | 3 |
| 2008 | Fast monitoring of traffic subpopulationsabstractNetwork accounting, forensics, security, and performance monitoring applications often need to examine detailed traces from subsets of flows ("subpopulations"), where the application desires flexibility in specifying the subpopulation (e.g., to detect a portscan, the application must observe many packets between a source and a destination with one packet to each port). However, the dynamism and volume of network traffic on many high-speed links necessitates traffic sampling, which adversely affects subpopulation monitoring: because many subpopulations of interest to operators are low-volume flows, conventional sampling schemes (e.g., uniform random sampling) miss much of the subpopulation's traffic. Today's routers and network devices provide scant support for monitoring specific traffic subpopulations. Anirudh Ramachandran, Srinivasan Seetharaman, Nick Feamster, Vijay V. Vazirani |
Internet Measurement Conference | 3 |
| 2008 | Accountable internet protocol (aip)abstractThis paper presents AIP (Accountable Internet Protocol), a network architecture that provides accountability as a first-order property. AIP uses a hierarchy of self-certifying addresses, in which each component is derived from the public key of the corresponding entity. We discuss how AIP enables simple solutions to source spoofing, denial-of-service, route hijacking, and route forgery. We also discuss how AIP's design meets the challenges of scaling, key management, and traffic engineering. David G. Andersen, Hari Balakrishnan, Nick Feamster, Teemu Koponen, Daekyeong Moon, Scott Shenker |
SIGCOMM | 3 |
| 2008 | Path splicingabstractWe present path splicing, a new routing primitive that allows network paths to be constructed by combining multiple routing trees ("slices") to each destination over a single network topology. Path splicing allows traffic to switch trees at any hop en route to the destination. End systems can change the path on which traffic is forwarded by changing a small number of additional bits in the packet header. We evaluate path splicing for intradomain routing using slices generated from perturbed link weights and find that splicing achieves reliability that approaches the best possible using a small number of slices, for only a small increase in latency and no adverse effects on traffic in the network. In the case of interdomain routing, where splicing derives multiple trees from edges in alternate backup routes, path splicing achieves near-optimal reliability and can provide significant benefits even when only a fraction of ASes deploy it. We also describe several other applications of path splicing, as well as various possible deployment paths. Murtaza Motiwala, Megan Elmore, Nick Feamster, Santosh S. Vempala |
SIGCOMM | 3 |
| 2008 | Answering what-if deployment and configuration questions with wiseabstractDesigners of content distribution networks often need to determine how changes to infrastructure deployment and configuration affect service response times when they deploy a new data center, change ISP peering, or change the mapping of clients to servers. Today, the designers use coarse, back-of-the-envelope calculations, or costly field deployments; they need better ways to evaluate the effects of such hypothetical "what-if" questions before the actual deployments. This paper presents What-If Scenario Evaluator (WISE), a tool that predicts the effects of possible configuration and deployment changes in content distribution networks. WISE makes three contributions: (1) an algorithm that uses traces from existing deployments to learn causality among factors that affect service response-time distributions; (2) an algorithm that uses the learned causal structure to estimate a dataset that is representative of the hypothetical scenario that a designer may wish to evaluate, and uses these datasets to predict future response-time distributions; (3) a scenario specification language that allows a network designer to easily express hypothetical deployment scenarios without being cognizant of the dependencies between variables that affect service response times. Our evaluation, both in a controlled setting and in a real-world field deployment at a large, global CDN, shows that WISE can quickly and accurately predict service response-time distributions for many practical What-If scenarios. Muhammad Mukarram Bin Tariq, Amgad Zeitoun, Vytautas Valancius, Nick Feamster, Mostafa H. Ammar |
SIGCOMM | 4 |
| 2008 | Can great research be taught?: independent research with cross-disciplinary thinking and broader impactabstractThis paper describes a course we have developed for preparing new Ph.D. students in computer science for a career in research. The course is intended to teach the skills needed for research and independent work, prepare students psychologically and socially for years lying before them, and help them find a good Ph.D. topic by providing principles and examples. In this course, we emphasize and encourage impact through cross-disciplinary research and broader societal outreach. To our knowledge, the course represents a first-of-its-kind systematic introduction to a graduate research career. This paper describes our high-level goals for this curricular initiative, the structure of the course (including lecture components and assignments), and the challenges we faced in developing this course. As we continue to develop this course, which is now in its second year, we hope it will serve as a model "introduction of Ph.D. research" course for other computer science departments. Nick Feamster, Alexander G. Gray |
SIGCSE | 1 |
| 2007 | Filtering spam with behavioral blacklistingabstractSpam filters often use the reputation of an IP address (or IP address range) to classify email senders. This approach worked well when most spam originated from senders with fixed IP addresses, but spam today is also sent from IP addresses for which blacklist maintainers have outdated or inaccurate information (or no information at all). Spam campaigns also involve many senders, reducing the amount of spam any particular IP address sends to a single domain; this method allows spammers to stay "under the radar". The dynamism of any particular IP address begs for blacklisting techniques that automatically adapt as the senders of spam change. Anirudh Ramachandran, Nick Feamster, Santosh S. Vempala |
CCS | 2 |
| 2007 | Multiplexing BGP sessions with BGP-MuxabstractThis paper describes a BGP-session multiplexer called BGP-Mux, which provides stable, on-demand access to global BGP route feeds. This gateway allows arbitrary and eventransientclientBGP connectionstobeprovisionedand Vytautas Valancius, Nick Feamster |
CoNEXT | 2 |
| 2007 | Measuring the Contributions of Routing Dynamics to Prolonged End-to-End Internet Path FailuresabstractThis paper studies the contributions of routing dynamics to the duration of long-lived end-to-end Internet path failures. Studies have shown that end-to-end Internet failures (periods of prolonged packet loss) are widespread. These failures are typically attributed to either congestion or routing dynamics. Unfortunately, the extent to which congestion and routing dynamics contribute to long-lasting path failures, and the effect of routing dynamics on end-to-end performance, are not well understood. This paper uses a joint analysis of active measurements and routing data to characterize end-to-end failures observed over one month on a topologically diverse Internet testbed. We find that routing dynamics coincide with most prolonged end-to-end failures, suggesting that routing dynamics contribute significantly to the duration of these failures. We also find that most long-lived end-to-end path failures that coincide with routing dynamics are caused by BGP convergence or instability. Our results provide new insights into the effects of routing instability on end-to-end Internet path performance. Feng Wang 0017, Nick Feamster, Lixin Gao 0001 |
GLOBECOM | 2 |
| 2007 | Holding the Internet Accountable
David G. Andersen, Hari Balakrishnan, Nick Feamster, Teemu Koponen, Daekyeong Moon, Scott Shenker |
HotNets | 3 |
| 2007 | Path Splicing: Reliable Connectivity with Rapid Recovery
Murtaza Motiwala, Nick Feamster, Santosh S. Vempala |
HotNets | 2 |
| 2007 | Usage-based dhcp lease time optimizationabstractThe Dynamic Host Configuration Protocol (DHCP) is used to dynamically allocate address space to hosts on a local area network. Despite its widespread usage, few studies exist on DHCP usage patterns, and even less is known about the importance of setting the lease time (the time that a client retains ownership over some IP address) to an appropriate value. Lease time can greatly affect the tradeoff between address space utilization and the number of both renewal messages and client session expirations. In this paper, using a DHCP trace for 5 weekdays from the Georgia Tech campus network, we present the largest known study of DHCP utilization. We also explore how various strategies for setting lease times can dramatically reduce the number of renewals and expirations without prohibitively increasing address space utilization. Manas Khadilkar, Nick Feamster, Matt Sanders, Russell J. Clark 0001 |
Internet Measurement Conference | 2 |
| 2007 | Diagnosing network disruptions with network-wide analysisabstractTo maintain high availability in the face of changing network conditions, network operators must quickly detect, identify, and react to events that cause network disruptions. One way to accomplish this goal is to monitor routing dynamics, by analyzing routing update streams collected from routers. Existing monitoring approaches typically treat streams of routing updates from different routers as independent signals, and report only the "loud" events (i.e., events that involve large volume of routing messages). In this paper, we examine BGP routing data from all routers in the Abilene backbone for six months and correlate them with a catalog of all known disruptions to its nodes and links. We find that many important events are not loud enough to be detected from a single stream. Instead, they become detectable only when multiple BGP update streams are simultaneously examined. This is because routing updates exhibit network-wide dependencies. Yiyi Huang, Nick Feamster, Anukool Lakhina, Jun (Jim) Xu |
SIGMETRICS | 2 |
| 2007 | MobCast: Overlay Architecture for Seamless IP Mobility using Scalable Anycast ProxiesabstractWe propose a routing overlay system, MobCast, for simple and efficient routing to mobile hosts. Mobcast nodes advertise the same address space at each proxy location, and each mobile host is assigned a "universal" IP address from this address space, so packets sent to a mobile host's universal IP address automatically go to the nearest proxy on the overlay. The overlay then delivers the packets to the mobile host. Our architecture enables seamless mobility for both micro and macro mobility. While our initial design is not as mature as Mobile IP, it shows great promise to solve the traditional problems of ingress routing, firewalls, NATs, and rapid mobility with much lower complexity. We present our design as a scalable and deployable alternative to mobile IP. In this paper, we focus on describing the MobCast system architecture. We form our arguments for scalability, handoff-speed, and simplicity, and give our initial results for scalability. We postpone a detailed discussion of MobCast's security model for future work. Christopher P. Lee 0001, Keshav Attrey, Carlos Caballero, Nick Feamster, Milena Mihail, John A. Copeland |
WCNC | 4 |
| 2007 | Implications of autonomy for the expressiveness of policy routing
Nick Feamster, Ramesh Johari, Hari Balakrishnan |
IEEE/ACM Trans. Netw. | 1 |
| 2007 | Network-wide prediction of BGP routes
Nick Feamster, Jennifer Rexford |
IEEE/ACM Trans. Netw. | 1 |
| 2006 | In VINI veritas: realistic and controlled network experimentationabstractThis paper describes VINI, a virtual network infrastructure that allows network researchers to evaluate their protocols and services in a realistic environment that also provides a high degree of control over network conditions. VINI allows researchers to deploy and evaluate their ideas with real routing software, traffic loads, and network events. To provide researchers flexibility in designing their experiments, VINI supports simultaneous experiments with arbitrary network topologies on a shared physical infrastructure. This paper tackles the following important design question: What set of concepts and techniques facilitate flexible, realistic, and controlled experimentation (e.g., multiple topologies and the ability to tweak routing algorithms) on a fixed physical infrastructure? We first present VINI's high-level design and the challenges of virtualizing a single network. We then present PL-VINI, an implementation of VINI on PlanetLab, running the "Internet In a Slice". Our evaluation of PL-VINI shows that it provides a realistic and controlled environment for evaluating new protocols and services. Andy C. Bavier, Nick Feamster, Mark Huang, Larry L. Peterson, Jennifer Rexford |
SIGCOMM | 2 |
| 2006 | Understanding the network-level behavior of spammersabstractThis paper studies the network-level behavior of spammers, including: IP address ranges that send the most spam, common spamming modes (e.g., BGP route hijacking, bots), how persistent across time each spamming host is, and characteristics of spamming botnets. We try to answer these questions by analyzing a 17-month trace of over 10 million spam messages collected at an Internet "spam sinkhole", and by correlating this data with the results of IP-based blacklist lookups, passive TCP fingerprinting information, routing information, and botnet "command and control" traces.We find that most spam is being sent from a few regions of IP address space, and that spammers appear to be using transient "bots" that send only a few pieces of email over very short periods of time. Finally, a small, yet non-negligible, amount of spam is received from IP addresses that correspond to short-lived BGP routes, typically for hijacked prefixes. These trends suggest that developing algorithms to identify botnet membership, filtering email messages based on network-level properties (which are less variable than email content), and improving the security of the Internet routing infrastructure, may prove to be extremely effective for combating spam. Anirudh Ramachandran, Nick Feamster |
SIGCOMM | 2 |
| 2005 | Geographic Locality of IP Prefixes
Michael J. Freedman, Mythili Vutukuru, Nick Feamster, Hari Balakrishnan |
Internet Measurement Conference | 3 |
| 2005 | Design and Implementation of a Routing Control Platform
Matthew Caesar 0001, Donald F. Caldwell, Nick Feamster, Jennifer Rexford, Aman Shaikh, Jacobus E. van der Merwe |
NSDI | 3 |
| 2005 | Detecting BGP Configuration Faults with Static Analysis (Awarded Best Paper)
Nick Feamster, Hari Balakrishnan |
NSDI | 1 |
| 2005 | Implications of autonomy for the expressiveness of policy routingabstractThousands of competing autonomous systems must cooperate with each other to provide global Internet connectivity. Each autonomous system (AS) encodes various economic, business, and performance decisions in its routing policy. The current interdomain routing system enables each AS to express policy using rankings that determine how each router inthe AS chooses among different routes to a destination, and filters that determine which routes are hidden from each neighboring AS. Because the Internet is composed of many independent, competing networks, the interdomain routing system should provide autonomy, allowing network operators to set their rankings independently, and to have no constraints on allowed filters. This paper studies routing protocol stability under these conditions. We first demonstrate that certain rankings that are commonly used in practice may not ensure routing stability. We then prove that, when providers can set rankings and filters autonomously, guaranteeing that the routing system will converge to a stable path assignment essentially requires ASes to rank routes based on AS-path lengths. We discuss the implications of these results for the future of interdomain routing. Nick Feamster, Ramesh Johari, Hari Balakrishnan |
SIGCOMM | 1 |
| 2004 | BorderGuard: detecting cold potatoes from peersabstractInternet Service Providers often establish contractual "peering" agreements, where they agree to forward traffic to each other's customers at no cost. Consistent route advertisement at all peering points is a common provision in these agreements, because it gives an AS the flexibility to select egress points for the traffic (e.g., performing "hot potato" routing). Verifying "consistent export" is challenging because route advertisements are exchanged at multiple peering points and may be modified by routing policies. In this paper, we propose two algorithms to detect inconsistent routes using routing and configuration data from an AS's border routers. The first algorithm requires access to all eBGP routes advertised by a peer. Because this data is often unavailable, we propose another algorithm that detects inconsistencies using readily available data. We have applied our algorithms to the routes advertised by the peers of AT&T's commercial IP backbone. Although a peer may intentionally send inconsistent advertisements to prevent its neighbor from performing hot-potato routing, we also discuss several configuration scenarios where a peer may inadvertently advertise inconsistent routes, despite having consistent export policies. Finally, we explain how simple modifications to the routers could make detection of inconsistent advertisements much easier than it is today. Nick Feamster, Z. Morley Mao, Jennifer Rexford |
Internet Measurement Conference | 1 |
| 2004 | A model of BGP routing for network engineeringabstractThe performance of IP networks depends on a wide variety of dynamic conditions. Traffic shifts, equipment failures, planned maintenance, and topology changes in other parts of the Internet can all degrade performance. To maintain good performance, network operators must continually reconfigure the routing protocols. Operators configure BGP to control how traffic flows to neighboring Autonomous Systems (ASes), as well as how traffic traverses their networks. However, because BGP route selection is distributed, indirectly controlled by configurable policies, and influenced by complex interactions with intradomain routing protocols, operators cannot predict how a particular BGP configuration would behave in practice. To avoid inadvertently degrading network performance, operators need to evaluate the effects of configuration changes before deploying them on a live network. We propose an algorithm that computes the outcome of the BGP route selection process for each router in a single AS, given only a static snapshot of the network state, without simulating the complex details of BGP message passing. We describe a BGP emulator based on this algorithm; the emulator exploits the unique characteristics of routing data to reduce computational overhead. Using data from a large ISP, we show that the emulator correctly computes BGP routing decisions and has a running time that is acceptable for many tasks, such as traffic engineering and capacity planning. Nick Feamster, Jared Winick, Jennifer Rexford |
SIGMETRICS | 1 |
| 2003 | Measuring the effects of internet path faults on reactive routingabstractEmpirical evidence suggests that reactive routing systems improve resilience to Internet path failures. They detect and route around faulty paths based on measurements of path performance. This paper seeks to understand why and under what circumstances these techniques are effective.To do so, this paper correlates end-to-end active probing experiments, loss-triggered traceroutes of Internet paths, and BGP routing messages. These correlations shed light on three questions about Internet path failures: (1) Where do failures appear? (2) How long do they last? (3) How do they correlate with BGP routing instability?Data collected over 13 months from an Internet testbed of 31 topologically diverse hosts suggests that most path failures last less than fifteen minutes. Failures that appear in the network core correlate better with BGP instability than failures that appear close to end hosts. On average, most failures precede BGP messages by about four minutes, but there is often increased BGP traffic both before and after failures. Our findings suggest that reactive routing is most effective between hosts that have multiple connections to the Internet. The data set also suggests that passive observations of BGP routing messages could be used to predict about 20% of impending failures, allowing re-routing systems to react more quickly to failures. Nick Feamster, David G. Andersen, Hari Balakrishnan, M. Frans Kaashoek |
SIGMETRICS | 1 |
| 2002 | Topology inference from BGP routing dynamicsabstractThis paper describes a method of inferring logical relationships between network prefixes within an Autonomous System (AS) using only passive monitoring of BGP messages. By clustering these prefixes based upon similarities between their update times, we create a hierarchy linking the prefixes within the larger AS. We can frequently identify groups of prefixes routed to the same ISP Point of Presence (POP), despite the lack of identifying information in the BGP messages. Similarly, we observe disparate prefixes under common organizational control, or with long shared network paths. In addition to discovering interesting network characteristics, our passive method facilitates topology discovery by potentially reducing the number of active probes required in traditional traceroute-based Internet mapping mechanisms. David G. Andersen, Nick Feamster, Steven J. Bauer, Hari Balakrishnan |
Internet Measurement Workshop | 2 |
| 2002 | Infranet: Circumventing Web Censorship and Surveillance
Nick Feamster, Magdalena Balazinska, Greg Harfst, Hari Balakrishnan, David R. Karger |
USENIX Security Symposium | 1 |
| 2001 | The Dos and Don'ts of Client Authentication on the Web
Kevin Fu, Emil Sit, Kendra Smith, Nick Feamster |
USENIX Security Symposium | 4 |
| 1999 | Field-To-Frame Transcoding with Spatial and Temporal DownsamplingabstractWe present an algorithm for transcoding high-rate compressed bitstreams containing field-coded interlaced video to lower-rate compressed bitstreams containing frame-coded progressive video. We focus on MPEG-2 to H.263 transcoding, however these results can be extended to other lower-rate video compression standards including MPEG-4 simple profile and MPEG-1. A conventional approach to the transcoding problem involves decoding the input bitstream, spatially and temporally downsampling the decoded frames, and re-encoding the result. The proposed transcoder achieves improved performance by exploiting the details of the MPEG-2 and H.263 compression standards when performing interlaced to progressive (or field to frame) conversion with spatial downsampling and frame-rate reduction. The transcoder reduces the MPEG-2 decoding requirements by temporally downsampling the data at the bitstream level and reduces the H.263 encoding requirements by largely bypassing H.263 motion estimation by reusing the motion vectors and coding modes given in the input bitstream. In software implementations, the proposed approach achieved a 5/spl times/ speedup over the conventional approach with only a 0.3 and 0.5 dB loss in PSNR for the Carousel and Bus sequences. Susie J. Wee, John G. Apostolopoulos, Nick Feamster |
ICIP (4) | 3 |