EDBT 2026 Demo / reviewers in the wild / expert
Christian Doerr
dblp:d/ChristianDoerr
· DBLP profile ↗
41ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0002-7913-2692ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 8 since 2021Computer networks · 14 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond the Device: A Security Analysis of Children's Smartwatches and Their EcosystemabstractThe omnipresence of expensive high-end smartwatches has sparked demand for cheaper alternatives targeted at children. Equipped with parental control apps, they are not only a desirable product for children to own, but create an incentive for parents to buy them as they can limit what children may do or track where they go. However, these low-cost children's smartwatches are often built atop a supply chain with little regulatory scrutiny. In this paper, we present the first comprehensive security analysis covering firmware, companion apps, backend APIs, and their supply chain. We reveal previously undocumented attack vectors including command injection, passive message decryption, and unauthorized device enrollment. We validate them with proof-of-concept attacks across multiple market dominant platforms. Huancheng Hu, Christian Doerr |
AsiaCCS | 2 |
| 2026 | LotBoNC: Novel Botnet Traffic Classification under Long-tailed DistributionsabstractBotnets are a persistent cyber threat, leveraging global infrastructures to launch large-scale attacks. Yet, most existing classification methods are evaluated under balanced and closed-set assumptions, which fail to capture real-world conditions. In practice, botnet traffic is both long-tailed and open-world: unknown variants continually emerge, and rare threats are buried under dominant traffic, often evading detection. To reflect real-world conditions, we define a deployment-oriented setting where unlabeled traffic follows a long-tailed distribution, with dominant known classes in the head and rare novel botnet variants in the tail. We propose LotBoNC, a unified framework for encrypted traffic classification under long-tailed open-world conditions. LotBoNC first performs self-supervised pre-training to learn transferable representations, then applies entropy-regularized optimal transport to assign pseudo-labels aligned with estimated class priors. An EM-style loop iteratively refines prototypes and priors, improving class separation between frequent and rare categories. We evaluate LotBoNC on three public encrypted traffic datasets with diverse long-tailed scenarios. LotBoNC consistently outperforms prior state-of-the-art methods and accurately classifies known botnets and discovers unseen botnet variants in diverse, umbalanced open-world scenarios. Huancheng Hu, Ziyun Li 0002, Christian Doerr |
AsiaCCS | 3 |
| 2025 | Opening a Can of Worms: A Comprehensive View into the Android Debug Bridge MalwareabstractThe proliferation of affordable Android-based IoT devices has led to their widespread integration into residential environments. However, Android Debug Bridge (ADB), the official developer tool that provides root-level access, is often misconfigured on low-end Android devices, with the port left open by default. This exposure enables remote compromise and turns devices into tools for cryptomining and botnet attacks, fueling large-scale malware campaigns. Despite years of widespread exploitation, there has been no systematic and quantitative understanding of how ADB-based worms exploit, propagate, and persist at scale. We present the first comprehensive study of ADB-targeting worms, analyzing over seven years of real-world data encompassing 1.7 million infected IPs and more than 6 billion compromise attempts. Our analysis uncovers three distinct propagation phases and shows that infections are disproportionately concentrated among residential devices. Through device firmware analysis, we reveal that ADB access is factory-enabled on several market-leading low-end Android TV boxes. We further show that infection patterns are tightly coupled with human activity cycles. To further explore the infection behavior quantitatively, we introduce a Graph Neural Network (GNN)-based simulation framework which is built and validated from real-world data. The model reveals how synchronized user behavior accelerates propagation and shows that timely mitigation can significantly reduce infection scale. Huancheng Hu, Christian Doerr |
TrustCom | 2 |
| 2024 | Dealing with Bad Apples: Organizational Awareness and Protection for Bit-flip and Typo-Squatting AttacksabstractThe domain name system (DNS) maps human-readable service names to IP addresses used by the network. As it exerts control over where users are directed to, domain names have been targets of abuse ever since the Internet become a success. Over the past twenty years, adversaries have repeatedly invented new strategies to trick users and our findings reveal a continuous increase in the exploitation of domain names. Huancheng Hu, Afshin Zivi, Christian Doerr |
ARES | 3 |
| 2024 | Have you SYN me? Characterizing Ten Years of Internet ScanningabstractPort scanning is the de-facto method to enumerate active hosts and potentially exploitable services on the Internet. Over the last years, several studies have quantified the ecosystem of port scanning. Each work has found drastic changes in the threat landscape compared to the previous one, and since the advent of high-performance scanning tools and botnets a lot has changed in this highly volatile ecosystem. Harm Griffioen, Georgios Koursiounis, Georgios Smaragdakis, Christian Doerr |
IMC | 4 |
| 2024 | The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS AssessmentsabstractMotivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best available macroscopic views of the relative trends in two dominant classes of attacks - direct-path attacks and reflection-amplification attacks. We first analyze 24 industry reports to extract trends and (in)consistencies across observations by commercial stakeholders in 2022. We then analyze ten data sets spanning industry and academic sources, across four years (2019-2023), to find and explain discrepancies based on data sources, vantage points, methods, and parameters. Our method includes a new approach: we share an aggregated list of DDoS targets with industry players who return the results of joining this list with their proprietary data sources to reveal gaps in visibility of the academic data sources. We use academic data sources to explore an industry-reported relative drop in spoofed reflection-amplification attacks in 2021-2022. Our study illustrates the value, but also the challenge, in independent validation of security-related properties of Internet infrastructure. Finally, we reflect on opportunities to facilitate greater common understanding of the DDoS landscape. We hope our results inform not only future academic and industry pursuits but also emerging policy efforts to reduce systemic Internet security vulnerabilities. Raphael Hiesgen, Marcin Nawrocki, Marinho P. Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky K. P. Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, K. C. Claffy |
IMC | 8 |
| 2023 | How to Count Bots in Longitudinal Datasets of IP Addresses
Leon Bock, Dave Levin, Ramakrishna Padmanabhan, Christian Doerr, Max Mühlhäuser |
NDSS | 4 |
| 2023 | Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet wormsabstractBotnets often spread through massive Internet-wide scanning, identifying and infecting vulnerable Internet-facing devices to grow their network. Taking down these networks is often hard for law enforcement, and some people have proposed tarpits as a defensive method because it does not require seizing infrastructure or rely on device owners to make sure their devices are well-configured and protected. These tarpits are network services that aim to keep a malware-infected device busy and slow down or eradicate the malicious behavior.This paper identifies a network-based tarpit vulnerability in stateless-scanning malware and develops a tarpitting exploit. We apply this technique against malware based on the Mirai scanning routine to identify whether tarpitting at scale is effective in containing the spread of self-propagating malware. We demonstrate that we can effectively trap thousands of devices even in a single tarpit and that this significantly slows down botnet spreading across the Internet and provide a framework to simulate malware spreading under various network conditions to apriori evaluate the effect of tarpits on a particular malware. We show that the self-propagating malware could be contained with the help of a few thousand tarpits without any measurable adverse impact on compromised routers or Internet Service Providers, and we release our tarpitting solution as an open platform to the community to realize this. Harm Griffioen, Christian Doerr |
SP | 2 |
| 2021 | Analysis and Takeover of the Bitcoin-Coordinated Pony MalwareabstractMalware, like all products and services, evolves with bursts of innovation. These advances usually happen whenever security controls get ''good enough'' to significantly impact the revenue stream of malicious actors, and in the past we have seen the malware ecosystem to adopt concepts such as code obfuscation, polymorphism, domain-generation algorithms (DGAs), as well as virtual machine and sandbox evasion whenever defenses were able to perform consistent and pervasive suppression of these threats. Tsuyoshi Taniguchi, Harm Griffioen, Christian Doerr |
AsiaCCS | 3 |
| 2021 | Inside the Matrix: CTI Frameworks as Partial Abstractions of Complex ThreatsabstractThe Cyber Threat Intelligence (CTI) field has evolved rapidly and most of its reporting is now fairly stan-dardized. Where the Cyber Kill Chain was its sole reference framework 5 years ago, today ATT&CK is the de facto standard for reporting adversary tactics, techniques and procedures (TTPs). CTI frameworks are effectively abstraction layers of malicious behavior and thus effective CTI dissemination hinges on their ability to accurately represent this behavior. We argue that this is an area with significant opportunity for improvement. The aforementioned models are attacker- and intrusion-centric, while much of the CTI reporting currently is artifact- and malware-centric. In other words, most analysis is performed using artifacts of adversary tools, while in-the-wild evidence of adversary techniques and procedures is limited or lacking. Applying an intrusion model to artifact-based analysis leads to information loss, affecting and potentially misleading CTI-based decision-making. Intelligence analysis naturally builds on imperfect information, but CTI frameworks should be oriented more towards this key premise. In this conceptual work we compare the intrusion-centric ATT&CK with Malware Behavior Catalog (MBC), which is malware-centric. We compare how their application affects reporting of analysis outcomes. For this we reverse a piece of APT malware, replicating how many CTI reports are produced. We find that compared to ATT&CK, the abstraction offered by MBC enhances the information density of our reporting. While currently in most industry malware reports ATT&CK is applied, our analysis shows that on these occasions using MBC, potentially in tandem with ATT&CK, improves reporting. With the daily amount of new malware samples only increasing, accurate behavior labeling is key to the success of CTI sharing and dissemination. Kris Oosthoek, Christian Doerr |
IEEE BigData | 2 |
| 2021 | Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksabstractAmplification attacks generate an enormous flood of unwanted traffic towards a victim and are generated with the help of open, unsecured services, to which an adversary sends spoofed service requests that trigger large answer volumes to a victim. However, the actual execution of the packet flood is only one of the activities necessary for a successful attack. Adversaries need, for example, to develop attack tools, select open services to abuse, test them, and adapt the attacks if necessary, each of which can be implemented in myriad ways. Thus, to understand the entire ecosystem and how adversaries work, we need to look at the entire chain of activities. Harm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian Doerr |
CCS | 4 |
| 2021 | SIP Bruteforcing in the Wild - An Assessment of Adversaries, Techniques and ToolsabstractOver the last two decades, Voice-over-IP (VoIP) and specifically SIP have become standard solutions to realize voice telephony in residential, commercial, and telecom environments. As by now, an abundance of SIP endpoints exist, it has become financially lucrative for cybercriminals to systematically search for VoIP installations, with for example the aim to abuse them for billing fraud or to hide their criminal activities behind a legitimate connection and phone number. By now, this has made SIP one of the most scanned UDP protocols on the Internet. In this paper, we take a look at the actors behind these attacks. Using a large network telescope, we collect over 822 million SIP brute-forcing attempts from 5,691 sources over 187 countries and analyze who is searching for and attacking VoIP endpoints. As each tool and campaign exhibits specific implementation differences, we can relate individual attempts into campaigns and can thereby provide a detailed view into different actors in the ecosystem, different techniques and tooling, and how these are developing over 5 years. We show that we can fingerprint different SIP scanning tools, show that actors hardly ever change their toolkit, and identify an increase in highly distributed and coordinated scanning. Harm Griffioen, Huancheng Hu, Christian Doerr |
Networking | 3 |
| 2021 | Cyber Security Threats to Bitcoin Exchanges: Adversary Exploitation and Laundering TechniquesabstractBitcoin is gaining traction as an alternative store of value. Its market capitalization transcends all other cryptocurrencies in the market. But its high monetary value also makes it an attractive target to cyber criminal actors. Hacking campaigns usually target an ecosystem’s weakest points. In Bitcoin, the exchange platforms are one of them. Each exchange breach is a threat not only to direct victims, but to the credibility of Bitcoin’s entire ecosystem. Based on an extensive analysis of 36 breaches of Bitcoin exchanges, we show the attack patterns used to exploit Bitcoin exchange platforms using an industry standard for reporting intelligence on cyber security breaches. Based on this we are able to provide an overview of the most common attack vectors, showing that all except three hacks were possible due to relatively lax security. We show that while the security regimen of Bitcoin exchanges is subpar compared to other financial service providers, the use of stolen credentials, which does not require any hacking, is decreasing. We also show that the amount of BTC taken during a breach is decreasing, as well as the exchanges that terminate after being breached. Furthermore we show that overall security posture has improved, but still has major flaws. To discover adversarial methods post-breach, we have analyzed two cases of BTC laundering. Through this analysis we provide insight into how exchange platforms with lax cyber security even further increase the intermediary risk introduced by them into the Bitcoin ecosystem. Kris Oosthoek, Christian Doerr |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Quantifying autonomous system IP churn using attack traffic of botnetsabstractTo connect to the Internet, hosts are assigned an IP address by their network provider by which they exchange data. As such, IP addresses are frequently used as a proxy metric to count the number of hosts on a network, or to quantify particular phenomena such as the size of botnets or the infection statistics of malware. Although a single host is typically linked to a single IP address at a given moment, this relationship is frequently not stable over time due to IP churn. As network operators dynamically assign IP addresses to clients for a specific lease duration, after expiry of this lease a host obtains a new IP address, thereby leading to overestimations of active host counts or malware infections. Harm Griffioen, Christian Doerr |
ARES | 2 |
| 2020 | Quality Evaluation of Cyber Threat Intelligence Feeds
Harm Griffioen, Tim M. Booij, Christian Doerr |
ACNS (2) | 3 |
| 2020 | Examining Mirai's Battle over the Internet of ThingsabstractUsing hundreds of thousands of compromised IoT devices, the Mirai botnet emerged in late 2016 as a game changing threat actor, capable of temporarily taking down major Internet service providers and Internet infrastructure. Since then, dozens of variants of IoT-based botnets have sprung up, and in today's Internet distributed denial-of-service attacks from IoT devices have become a major attack vector. This proliferation was significantly driven by the public distribution of the Mirai source code, which other actors used to create their own, customized version of the original Mirai botnet. In this paper we provide a comprehensive view into the ongoing battle over the Internet of Things fought by Mirai and its many siblings. Using 7,500 IoT honeypots, we show that we can use 300,000,000 compromisation attempts from infected IoT devices as well as a design flaw in Mirai's random number generator to obtain insights into Mirai infections worldwide. We find that networks and the particular malware strains that plague them are tightly connected, and malware authors over time take over strategies from their competitors. The most surprising finding is that epidemiologically, IoT botnets are not self-sustaining: were it not for continuous pushes from bootstrapping, Mirai and its variants would die out. Harm Griffioen, Christian Doerr |
CCS | 2 |
| 2020 | Scaling website fingerprinting
Vincent Ghiëtte, Christian Doerr |
Networking | 2 |
| 2020 | Quantifying TCP SYN DDoS Resilience: A Longitudinal Study of Internet Services
Harm Griffioen, Christian Doerr |
Networking | 2 |
| 2020 | Discovering Collaboration: Unveiling Slow, Distributed Scanners based on Common Header Field PatternsabstractTo compromise a computer, it is first necessary to discover which hosts are active and which services they run. This reconnaissance is typically accomplished through port scanning. Defense systems monitor for these unsolicited packets and raise an alarm if a predefined threshold is exceeded. To remain undetected, adversaries can either slow down the scan, and/or distribute it over multiple hosts. With each source below the threshold, the combination of all may still complete the scan efficiently. It is especially this group that is of concern: with enough resources and knowledge to execute such a coordinated activity, they will pose a more potent threat than the noisy "script kiddie". Correlating which out of 4 billion IPs potentially collaborate is however a challenging task, hence today’s systems do not consider coordination beyond basic subnet aggregation.In this paper, we propose a method to identify and fingerprint distributed scanners based on commonalities in header fields, which are an artifact of the way fast port scanning software is built. We demonstrate that this method can effectively locate groups, and based on the monitoring logs we report on a number of new groups and tools, which have previously not been reported in the academic literature.Fingerprints generated can ultimately be used as Indicators of Compromise to detect and mitigate scanning behavior in order to deny adversaries the possibility to learn about weaknesses of a system. Harm Griffioen, Christian Doerr |
NOMS | 2 |
| 2020 | A different cup of TI? The added value of commercial threat intelligence
Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, Michel van Eeten |
USENIX Security Symposium | 4 |
| 2019 | Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for CryptojackingabstractThe release of an efficient browser-based cryptominer, as introduced by Coinhive in 2017, has quickly spread throughout the web either as a new source of revenue for websites or exploited within the context of hacks and malicious advertisements. Several studies have analyzed the Alexa Top 1M and found 380 - 3,200 (0.038% - 0.32%) to be actively mining, with an estimated $41,000 per month revenue for the top 10 perpetrators. While placing a cryptominer on a popular website supplies considerable returns from its visitors' web browsers, it only generates revenue while a client is visiting the page. Even though large popular websites attract millions of visitors, the relatively low number of exploiting websites limits the total revenue that can be made. In this paper, we report on a new attack vector that drastically overshadows all existing cryptojacking activity discovered to date. Through a firmware vulnerability in MikroTik routers, cyber criminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing web connection. Thus, every web page visited by any user behind an infected router would mine to profit the criminals. Based on NetFlows recorded in a Tier 1 network, semiweekly crawls and telescope traffic, we followed their activities over a period of 10 months, and report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, approximately 70% of all MikroTik devices deployed worldwide. We observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. Our results show that cryptojacking through MITM attacks is highly lucrative, a factor of 30 more than previous attack vectors. Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr |
CCS | 3 |
| 2019 | The Curious Case of Port 0abstractIn order to direct network traffic towards applications, transport layer protocols such as TCP and UDP add the notion of a port number. A share of these numbers is registered for well-known services such as a web or mail, while some is left to be dynamically assigned by the OS to client connections. A special case is port 0 which is reserved but was never assigned. Traffic from and to port 0 is unusual, because it should not occur in the wild. As port 0 is unassigned, there is no common service listing for connections here. Furthermore, operating systems usually interpret the request to open port 0 as the request to allocate and open any currently unused port. Thus, traffic from and to port 0 should not occur, because no application should listen there and applications cannot send from port 0. In practice, we do however see traffic from and to port 0, which indicates that someone makes the effort to bypass the normal operating system network stack to create these unusual packets. As a corner case of network protocols, the aspect of port 0 has basically never been thoroughly investigated. In this paper, we analyze network traffic collected through a /15 network telescope over a period of 3 years to characterize these curious data flows. We find that port 0 traffic seems to be used in the wild by a select few for a variety of purposes, from DDoS attacks to system fingerprinting, and that some of these actors possess a surprisingly sophisticated knowledge of OS behavior. Mark Luchs, Christian Doerr |
Networking | 2 |
| 2019 | Fingerprinting Tooling used for SSH Compromisation Attempts
Vincent Ghiëtte, Harm Griffioen, Christian Doerr |
RAID | 3 |
| 2019 | SoK: ATT&CK Techniques and Trends in Windows Malware
Kris Oosthoek, Christian Doerr |
SecureComm (1) | 2 |
| 2019 | Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale
Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr |
USENIX Security Symposium | 3 |
| 2018 | A data reduction strategy and its application on scan and backscatter detection using rule-based classifiers
Vitali Herrera-Semenets, Osvaldo Andrés Pérez-García, Raudel Hernández-León, Jan van den Berg, Christian Doerr |
Expert Syst. Appl. | 5 |
| 2017 | Popularity-based Detection of Domain Generation AlgorithmsabstractIn order to stay undetected and keep their operations alive, cyber criminals are continuously evolving their methods to stay ahead of current best defense practices. Over the past decade, botnets have developed from using statically hardcoded IP addresses and domain names to randomly-generated ones, so-called domain generation algorithms (DGA). Malicious software coordinated via DGAs leaves however a distinctive signature in network traces of high entropy domain names, and a variety of algorithms have been introduced to detect certain aspects about currently used DGAs. Jasper Abbink, Christian Doerr |
ARES | 2 |
| 2017 | Quantifying the Spectrum of Denial-of-Service Attacks through Internet BackscatterabstractDenial of Service (DoS) attacks are a major threat currently observable in computer networks and especially the Internet. In such an attack a malicious party tries to either break a service, running on a server, or exhaust the capacity or bandwidth of the victim to hinder customers to effectively use the service. Recent reports show that the total number of Distributed Denial of Service (DDoS) attacks is steadily growing with "mega-attacks" peaking at hundreds of gigabit/s (Gbps). Norbert Blenn, Vincent Ghiëtte, Christian Doerr |
ARES | 3 |
| 2017 | Discovering Bitcoin Mixing Using Anomaly Detection
Mario Alfonso Prado-Romero, Christian Doerr, Andrés Gago Alonso |
CIARP | 2 |
| 2017 | Side-Channel Based Intrusion Detection for Industrial Control Systems
Pol Van Aubel, Kostas Papagiannopoulos, Lukasz Chmielewski, Christian Doerr |
CRITIS | 4 |
| 2017 | Last Line of Defense: A Novel IDS Approach Against Advanced Threats in Industrial Control Systems
Mark Luchs, Christian Doerr |
DIMVA | 2 |
| 2014 | OpenNetMon: Network monitoring in OpenFlow Software-Defined NetworksabstractWe present OpenNetMon, an approach and open-source software implementation to monitor per-flow metrics, especially throughput, delay and packet loss, in OpenFlow networks. Currently, ISPs over-provision capacity in order to meet QoS demands from customers. Software-Defined Networking and OpenFlow allow for better network control and flexibility in the pursuit of operating networks as efficiently as possible. Where OpenFlow provides interfaces to implement fine-grained Traffic Engineering (TE), OpenNetMon provides the monitoring necessary to determine whether end-to-end QoS parameters are actually met and delivers the input for TE approaches to compute appropriate paths. OpenNetMon polls edge switches, i.e. switches with flow end-points attached, at an adaptive rate that increases when flow rates differ between samples and decreases when flows stabilize to minimize the number of queries. The adaptive rate reduces network and switch CPU overhead while optimizing measurement accuracy. We show that not only local links serving variable bit-rate video streams, but also aggregated WAN links benefit from an adaptive polling rate to obtain accurate measurements. Furthermore, we verify throughput, delay and packet loss measurements for bursty scenarios in our experiment testbed. Niels L. M. van Adrichem, Christian Doerr, Fernando A. Kuipers |
NOMS | 2 |
| 2012 | Context-Sensitive Sentiment Classification of Short Colloquial Text
Norbert Blenn, Kassandra Charalampidou, Christian Doerr |
Networking (1) | 3 |
| 2012 | Crawling and Detecting Community Structure in Online Social Networks Using Local Information
Norbert Blenn, Christian Doerr, Bas Van Kester, Piet Van Mieghem |
Networking (1) | 2 |
| 2012 | Are friends overrated? A study for the social news aggregator Digg.com
Christian Doerr, Norbert Blenn, Siyu Tang 0002, Piet Van Mieghem |
Comput. Commun. | 1 |
| 2011 | Are Friends Overrated? A Study for the Social Aggregator Digg.com
Christian Doerr, Siyu Tang 0002, Norbert Blenn, Piet Van Mieghem |
Networking (2) | 1 |
| 2011 | Digging in the Digg Social News WebsiteabstractThe rise of social media aggregating websites provides platforms where users can actively publish, evaluate, and disseminate content in a collaborative way. In this paper, we present a large-scale empirical study about “Digg.com”, one of the biggest social media aggregating websites. Our analysis is based on crawls of 1.5 million users and 10 million published stories on Digg. We study the distinct network structure, the collaborative user characteristics, and the content dissemination process on Digg. We empirically illustrate that friendship relations are used effectively in disseminating half of the content, although there exists a high overlap between the interests of friends. A successful content dissemination process can also be performed by random users who are browsing and digging stories. Since 88% of the published content on Digg is defined as news, it is important for the content to obtain sufficient votes in a short period of time before becoming obsolete. Finally, we show that the synchronization of users' activities in time is the key to a successful content dissemination process. The dynamics between users' voting activities consequently decrease the efficiency of friendship relations during content dissemination. The results presented in this paper define basic observations and measurements to understand the underlying mechanism of disseminating content in current online social news aggregators. These findings are helpful to understand the influence of service interfaces and user behaviors on content dissemination. Siyu Tang 0002, Norbert Blenn, Christian Doerr, Piet Van Mieghem |
IEEE Trans. Multim. | 3 |
| 2008 | Dynamic Control Channel Assignment in Cognitive Radio Networks Using Swarm IntelligenceabstractIn recent years, a variety of algorithms for cognitive radio networks have been proposed. Many of these algorithms rely on the exchange of control information among the cognitive radio nodes and often require the presence of a globally available control channel. This requirement however poses a problem in a practical deployment: First, due to spectrum fluctuations such common control channel may be unknown at deployment stage. Second, when designating a fixed, dedicated control channel (for example in licensed spectrum), this will increase costs and expose vulnerability to the operation of the cognitive radio network. Thus, to overcome this difficulty, control channels should be dynamically assigned and managed in cognitive radio networks. In this paper, we propose the use of swarm intelligence as a way to dynamically find and manage such control channels in cognitive radio networks. The system we describe is able to independently identify viable control channels and adapt in presence of changing spectrum. We formalize the problem of control channel assignments to the multi-commodity flow problem, measure the performance of our approach in a hardware implementation and software simulation and compare the results against the theoretically optimal solution. Christian Doerr, Douglas C. Sicker, Dirk Grunwald |
GLOBECOM | 1 |
| 2008 | Enhancing Cognitive Radio Algorithms Through Efficient, Automatic Adaptation ManagementabstractIn recent years, cognitive radios that follow dynamic spectrum access policies have been proposed to overcome spectrum scarcity and to make better use of spectrum opportunities while avoiding interference to other users. The central component of such a cognitive radio is the control algorithm driving its sensing, learning and adaptation process. These three tasks however are both computationally expensive and resource intensive and it is therefore in the cognitive radio's best interest to minimize the time spent to sense, learn and adapt to its surroundings while still meeting its operational targets. In this paper, we present the rapid adaptation architecture, a statistical system that can be used in conjunction with existing cognitive radio control algorithms to speed up the learning and adaptation process without loosing significant accuracy. Through this system, control algorithms can be made more efficient by a factor of 2 or more, thus providing the cognitive radio with faster, more resource saving adaptations without major changes to the algorithm's inner workings or the overall cognitive radio. Christian Doerr, Dirk Grunwald, Douglas C. Sicker |
VTC Fall | 1 |
| 2007 | Experiences Implementing Cognitive Radio Control AlgorithmsabstractIn recent years, several algorithms for controlling cognitive radio platforms have been proposed. In this paper, we review the existing approaches that have been developed for cognitive radio control algorithms and extract the common sensing and control requirements for those algorithms. We also briefly discuss the challenges of defining representative testing scenarios. We then synthesize our experience implementing cognitive radio control algorithms and extract a set of pragmatic issues challenging researchers in cognitive radios. We conclude with a set of open questions and problems and discuss implications for future research. Christian Doerr, Douglas C. Sicker, Dirk Grunwald |
GLOBECOM | 1 |
| 2006 | MOJO: a distributed physical layer anomaly detection system for 802.11 WLANsabstractDeployments of wireless LANs consisting of hundreds of 802.11 access points with a large number of users have been reported in enterprises as well as college campuses. However, due to the unreliable nature of wireless links, users frequently encounter degraded performance and lack of coverage. This problem is even worse in unplanned networks, such as the numerous access points deployed by homeowners. Existing approaches that aim to diagnose these problems are inefficient because they troubleshoot at too high a level, and are unable to distinguish among the root causes of degradation. This paper designs, implements, and tests fine-grained detection algorithms that are capable of distinguishing between root causes of wireless anomalies at the depth of the physical layer. An important property that emerges from our system is that diagnostic observations are combined from multiple sources over multiple time instances for improved accuracy and efficiency. Anmol Sheth, Christian Doerr, Dirk Grunwald, Richard Han 0001, Douglas C. Sicker |
MobiSys | 2 |