Network Security
135 publications
-
A Call to Reconsider Certification Authority AuthorizationIEEE Security & Privacy, 24(1), pp. 35–43, 2026
-
Secrets Best Not Shared: DNS Privacy Enhancements for the Constrained IoTIn: Proc. of the 11th IEEE European Symposium on Security and Privacy (EuroS&P), pp. 1476–1495, IEEE, 2026accepted for publication
-
DNS over CoAP (DoC)RFC 9953, RFC Editor, IETF, 2026
-
Contrastive Learning and Correlation Clustering for Sequences of Network Telescope DataTechnical Report arXiv:2606.04733, Open Archive: arXiv.org, 2026
-
Scanning the IPv6 Internet Using Subnet-Router Anycast ProbingProceedings of the ACM on Networking, 3(CoNEXT4), pp. 50:1–50:15, 2025
-
Waiting for QUIC: Passive Measurements to Understand QUIC DeploymentsProceedings of the ACM on Networking, 3(CoNEXT4), pp. 41:1–41:26, 2025
-
A Detailed Measurement View on IPv6 Scanners and Their Adaption to BGP SignalsProceedings of the ACM on Networking, 3(CoNEXT3), pp. 15:1–:15:23, 2025
-
Toward a Better Understanding of IoT Domain Names: A Study of IoT BackendIEEE Access, 13, pp. 68871–68890, 2025
-
Forward to Hell? On the Potentials of Misusing Transparent DNS Forwarders in Reflective Amplification AttacksIn: Proc. of ACM CCS, pp. 3915–3929, ACM, 2025
-
Lessons Learned from Operating a Large Network TelescopeIn: Proc. of ACM SIGCOMM, pp. 826–841, ACM, 2025
-
POSTER: Towards a Complete View of Encrypted Client Hello DeploymentsIn: Proc. of ACM SIGCOMM: Posters and Demos, pp. 22–24, ACM, 2025
-
DEMO: Hilby – Hilbert Interactive Prefix PlotsIn: Proc. of ACM SIGCOMM: Posters and Demos, pp. 134–136, ACM, 2025
-
DEMO: Privacy-Preserving Payments on Constrained End-User DevicesIn: Proc. of ACM SIGCOMM: Posters and Demos, pp. 152–154, ACM, 2025
-
POSTER: Challenges in VM Scheduling and Placement: Insights from a Real-World SAP Cloud DatasetIn: Proc. of ACM SIGCOMM: Posters and Demos, pp. 124–126, ACM, 2025
-
POSTER: Two-Phase Scanning in IPv6 – First Observations from a Reactive IPv6 Network TelescopeIn: Proc. of ACM SIGCOMM: Posters and Demos, pp. 103–105, ACM, 2025
-
A Leaner and Faster Web: How CBOR Can Improve Dynamic Content Encoding in JSON and DNS over HTTPSTechnical Report arXiv:2512.12067, Open Archive: arXiv.org, 2025
-
Combating the Effects of Cyber-Psychosis: Using Object Security to Facilitate Critical ThinkingTechnical Report arXiv:2503.16510, Open Archive: arXiv.org, 2025
-
A Concise Binary Object Representation (CBOR) of DNS MessagesIETF Internet Draft – work in progress 08, individual, 2024
-
DNS over CoAP (DoC)IETF Internet Draft – work in progress 08, IETF, 2024
-
Proceedings of the 8th Network Traffic Measurement and Analysis Conference (TMA)Proceedings of the 8th Network Traffic Measurement and Analysis Conference (TMA), IEEE Press, 2024
-
A Security Model for Web-Based CommunicationCommunications of the ACM, 67(10), pp. 83–90, 2024
-
The Log4j Incident: A Comprehensive Measurement Study of a Critical VulnerabilityIEEE Transactions on Network and Service Management, 21(6), pp. 5921–5934, 2024
-
PUF for the Commons: Enhancing Embedded Security on the OS LevelIEEE Transactions on Dependable and Secure Computing, 21(4), pp. 2194–2210, 2024
-
The Resource Public Key Infrastructure (RPKI): A Survey on Measurements and Future ProspectsIEEE Transactions on Network and Service Management, 21(2), pp. 2353–2373, 2024
-
ReACKed QUICer: Measuring the Performance of Instant Acknowledgments in QUIC HandshakesIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 389–400, ACM, 2024
-
The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS AssessmentsIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 259–279, ACM, 2024
-
Poster: Towards a Digital Payment System for the Constrained Internet of ThingIn: Proc. of the 2024 Poster Session of the 8th IEEE European Symposium on Security and Privacy, pp. 14–16, Zenodo, 2024
-
Transparent DNS Forwarders: A (Still) Unnoticed Component of the Open DNS InfrastructureIn: Proc. of Workshop on DNS and Internet Naming Research (DINR2024), Information Science Institut (USC), Los Angeles, 2024
-
Secure Name Resolution in the IoTIn: Proc. of Workshop on DNS and Internet Naming Research (DINR2024), Information Science Institut (USC), Los Angeles, 2024
-
Do CAA, CT, and DANE Interlink in Certificate Deployments? A Web PKI Measurement StudyIn: Proc. of 8th Network Traffic Measurement and Analysis Conference (TMA), IEEE, 2024
-
How to Measure TLS, X.509 Certificates, and Web PKI: A Tutorial and Brief SurveyTechnical Report arXiv:2401.18053, Open Archive: arXiv.org, 2024
-
Securing Name Resolution in the IoT: DNS over CoAPProceedings of the ACM on Networking, 1(CoNEXT2), pp. 6:1–6:25, 2023
-
SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using HoneypotsIn: Proc. of IEEE Euro Security & Privacy, pp. 576–591, IEEE, 2023
-
DDoS Attacks: Coverage, Mitigation, and PreventionPh.D. thesis, Department of Mathematics and Computer Science, Freie Universität Berlin, 2023
-
On Information-centric Resiliency and System-level Security in Constrained, Wireless CommunicationPh.D. thesis, Department of Mathematics and Computer Science, Freie Universität Berlin, 2023
-
SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using HoneypotsTechnical Report arXiv:2302.04614, Open Archive: arXiv.org, 2023
-
PUF for the Commons: Enhancing Embedded Security on the OS LevelTechnical Report 2301.07048, Open Archive: arXiv.org, 2023
-
DNS over CoAP (DoC)IETF Internet Draft – work in progress 04, individual, 2022
-
From the Beginning: Key Transitions in the First 15 Years of DNSSECIEEE Transactions on Network and Service Management, 19(4), pp. 5265–5283, 2022
-
Content Object Security in the Internet of Things: Challenges, Prospects, and Emerging SolutionsIEEE Transactions on Network and Service Management, 19(1), pp. 538–553, 2022
-
Industrial Control Protocols in the Internet Core: Dismantling Operational PracticesWiley International Journal of Network Management, 32(1), pp. e2158:1–e2158:20, 2022
-
A Guideline on Pseudorandom Number Generation (PRNG) in the IoTACM Computing Surveys, 54(6), pp. 112:1–112:38, 2022
-
★ Best Paper Award, Best Community Contribution AwardOn the Interplay between TLS Certificates and QUIC PerformanceIn: Proc. of 18th International Conference on emerging Networking EXperiments and Technologies (CoNEXT), pp. 204–213, ACM, 2022
-
Spoki: Unveiling a New Wave of Scanners through a Reactive Network TelescopeIn: Proc. of 31st USENIX Security Symposium, pp. 431–448, USENIX Association, 2022
-
Zero-Knowledge Age Restriction for GNU TalerIn: Computer Security – ESORICS 2022, pp. 110–129, Springer International Publishing, 2022
-
SoK: Public Key and Namespace Management in NDNIn: Proc. of 9th ACM Conference on Information-Centric Networking (ICN), pp. 67–79, ACM, 2022
-
Usable Security for an IoT OS: Integrating the Zoo of Embedded Crypto Components Below a Common APIIn: Proc. of 19th International Conference on Embedded Wireless Systems and Networks (EWSN), pp. 84–95, ACM, 2022accepted for publication
-
The Race to the Vulnerable: Measuring the Log4j Shell IncidentIn: Proc. of Network Traffic Measurement and Analysis Conference (TMA), IFIP, 2022
-
Secure and Authorized Client-to-Client Communication for LwM2MIn: Proc. of 21st ACM/IEEE International Conference on Information Processing in Sensor Networks (IPSN), pp. 146–158, IEEE, 2022
-
Poster Abstract: Offloading Crypto Processing with RIOTIn: Proc. of 21st ACM/IEEE International Conference on Information Processing in Sensor Networks (IPSN), pp. 535–536, IEEE, 2022
-
Information-centric Networking for the Constrained Internet of ThingsPh.D. thesis, Department of Mathematics and Computer Science, Freie Universität Berlin, 2022
-
Waiting for QUIC: On the Opportunities of Passive Measurements to Understand QUIC DeploymentsTechnical Report arXiv:2209.00965, Open Archive: arXiv.org, 2022
-
Securing name resolution in the IoT: DNS over CoAPTechnical Report arXiv:2207.07486, Open Archive: arXiv.org, 2022
-
Auslandsverbindungen und CDN-Kompetenz (ZwIBACK). Zweite Internet Backbone-StudieTechnical Report, BSI, 2022
-
The Impact of Networking Protocols on Massive M2M Communication in the Industrial IoTIEEE Transactions on Network and Service Management, 18(4), pp. 4814–4828, 2021
-
Transparent Forwarders: An Unnoticed Component of the Open DNS InfrastructureIn: Proc. of 17th International Conference on emerging Networking EXperiments and Technologies (CoNEXT), pp. 454–462, ACM, 2021
-
The Far Side of DNS Amplification: Tracing the DDoS Attack Ecosystem from the Internet CoreIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 419–434, ACM, 2021
-
QUICsand: Quantifying QUIC Reconnaissance Scans and DoS Flooding EventsIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 283–291, ACM, 2021
-
On the Deployment of Default Routes in Inter-domain RoutingIn: Proc. of ACM SIGCOMM Workshop on Technologies, Applications, and Uses of a Responsible Internet (TAURIN'21), pp. 14–20, ACM, 2021
-
Revisiting RPKI Route Origin Validation on the Data PlaneIn: Proc. of Network Traffic Measurement and Analysis Conference (TMA), IFIP, 2021
-
Security of Alerting Authorities in the WWW: Measuring Namespaces, DNSSEC, and Web PKIIn: Proc. of 30th The Web Conference (WWW), pp. 2709–2720, ACM, 2021
-
Poster Abstract: Third Party Authorization of LwM2M ClientsIn: Proc. of ACM/IEEE Int. Conf. on Internet of Things Design and Implementation (IoTDI), pp. 263–264, ACM, 2021
-
A Performance Study of Crypto-Hardware in the Low-end IoTIn: Proc. of 18th International Conference on Embedded Wireless Systems and Networks (EWSN), ACM, 2021
-
From the Beginning: Key Transitions in the First 15 Years of DNSSECTechnical Report arXiv:2109.08783, Open Archive: arXiv.org, 2021
-
Networking Group Content: RESTful Multiparty Access to a Data-centric Web of ThingsTechnical Report arXiv:2104.01587, Open Archive: arXiv.org, 2021
-
A Performance Study of Crypto-Hardware in the Low-end IoTTechnical Report 2021/058, Cryptology ePrint Archive, 2021
-
On Measuring RPKI Relying PartiesIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 484–491, ACM, 2020
-
BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap DampingIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 492–505, ACM, 2020
-
Toward a RESTful Information-Centric Web of Things: A Deeper Look at Data Orientation in CoAPIn: Proc. of 7th ACM Conference on Information-Centric Networking (ICN), pp. 77–88, ACM, 2020
-
★ Best Paper AwardIoT Content Object Security with OSCORE and NDN: A First Experimental ComparisonIn: Proc. of 19th IFIP Networking Conference, pp. 19–27, IEEE, 2020
-
Uncovering Vulnerable Industrial Control Systems from the Internet CoreIn: Proc. of 17th IEEE/IFIP Network Operations and Management Symposium (NOMS), IEEE Press, 2020
-
Who ya gonna call? (Alerting Authorities): Measuring Namespaces, Web Certificates, and DNSSECTechnical Report arXiv:2008.10497, Open Archive: arXiv.org, 2020
-
A Guideline on Pseudorandom Number Generation (PRNG) in the IoTTechnical Report arXiv:2007.11839, Open Archive: arXiv.org, 2020
-
IoT Content Object Security with OSCORE and NDN: A First Experimental ComparisonTechnical Report arXiv:2001.08023, Open Archive: arXiv.org, 2020
-
Secure Routing for the Internet (Dagstuhl Seminar 18242)Secure Routing for the Internet (Dagstuhl Seminar 18242), Schloss Dagstuhl–Leibniz-Zentrum fuer Informatik, 2019
-
Authenticated Communication in Crises: Toward an Infrastructureless Trust Model for Challenged NetworksIn: Proc. of International Conference on Information and Communication Technologies for Disaster Management (ICT-DM), IEEE, 2019
-
Down the Black Hole: Dismantling Operational Practices of BGP Blackholing at IXPsIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 435–448, ACM, 2019
-
The Missing Piece: On Namespace Management in NDN and How DNSSEC Might HelpIn: Proc. of 6th ACM Conference on Information-Centric Networking (ICN), pp. 37–43, ACM, 2019
-
NDNSSEC: Namespace Management in NDN with DNSSECIn: Proc. of 6th ACM Conference on Information-Centric Networking (ICN), Demo Session, pp. 171–172, ACM, 2019
-
Security for the Industrial IoT: The Case for Information-Centric NetworkingIn: Proc. of IEEE 5th World Forum on Internet of Things (WF-IoT), pp. 424–429, IEEE, 2019
-
A Reproducibility Study of “IP Spoofing Detection in Inter-Domain Traffic”Technical Report arXiv:1911.05164, Open Archive: arXiv.org, 2019
-
Uncovering Vulnerable Industrial Control Systems from the Internet CoreTechnical Report arXiv:1901.04411, Open Archive: arXiv.org, 2019
-
★ Best of SIGCOMM CCRThe Dagstuhl Beginners Guide to Reproducibility for Experimental Networking ResearchACM SIGCOMM Computer Communication Review, 49(1), pp. 24–30, 2019Editorial note
-
★ Best of ACM SIGCOMM CCRTowards a Rigorous Methodology for Measuring Adoption of RPKI Route Validation and FilteringACM SIGCOMM Computer Communication Review, 48(1), pp. 19–27, 2018
-
The Rise of Certificate Transparency and Its Implications on the Internet EcosystemIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 343–349, ACM, 2018
-
On the Potential of BGP Flowspec for DDoS Mitigation at Two Sources: ISP and IXPIn: Proc. of ACM SIGCOMM. Poster Session, pp. 57–59, ACM, 2018
-
A Survey on Artifacts from CoNEXT, ICN, IMC, and SIGCOMM Conferences in 2017ACM SIGCOMM Computer Communication Review, 48(1), pp. 75–80, 2018Editorial note
-
Towards a Rigorous Methodology for Measuring Adoption of RPKI Route Validation and FilteringTechnical Report arXiv:1706.04263, Open Archive: arXiv.org, 2017
-
Can We Make a Cake and Eat It Too? A Discussion of ICN Security and PrivacyACM SIGCOMM Computer Communication Review, 47(1), pp. 49–54, 2017Editorial note
-
Towards Better Internet Citizenship: Reducing the Footprint of Internet-wide Scans by Topology Aware Prefix SelectionIn: Proc. of ACM Internet Measurement Conference (IMC), pp. 421–427, ACM, 2016
-
Let's Collect Names: How PANINI Limits FIB Tables in Name Based RoutingIn: Proc. of IFIP Networking, pp. 458–466, IEEE Press, 2016
-
TRAIL: Topology Authentication in RPLIn: Proc. of ACM International Conference on Embedded Wireless Systems and Networks (EWSN), pp. 59–64, ACM, 2016
-
Measuring and Implementing Internet Backbone Security: Current Challenges, Upcoming Deployment, and Future TrendsPh.D. thesis, Department of Mathematics and Computer Science, Freie Universität Berlin, 2016
-
A Survey on Honeypot Software and Data AnalysisTechnical Report arXiv:1608.06249, Open Archive: arXiv.org, 2016
-
Towards Better Internet Citizenship: Reducing the Footprint of Internet-wide Scans by Topology Aware Prefix SelectionTechnical Report arXiv:1605.05856, Open Archive: arXiv.org, 2016
-
CAIR: Using Formal Languages to Study Routing, Leaking, and Interception in BGPTechnical Report arXiv:1605.00618, Open Archive: arXiv.org, 2016
-
RiPKI: The Tragic Story of RPKI Deployment in the Web EcosystemIn: Proc. of Fourteenth ACM Workshop on Hot Topics in Networks (HotNets), ACM, 2015
-
Revisiting Countermeasures Against NDN Interest FloodingIn: Proc. of 2nd ACM Conference on Information-Centric Networking (ICN). Poster Session, pp. 195–196, ACM, 2015
-
Partial Adaptive Name Information in ICN: PANINI Routing Limits FIB Table SizesIn: Proc. of 2nd ACM Conference on Information-Centric Networking (ICN). Poster Session, pp. 193–194, ACM, 2015
-
Cashing out the Great Cannon? On Browser-Based DDoS Attacks and EconomicsIn: Proc. of 9th USENIX Security Workshop on Offensive Technologies (WOOT), USENIX Assoc., 2015
-
See How ISPs Care: An RPKI Validation Extension for Web BrowsersIn: Proc. of ACM SIGCOMM, Demo Session, pp. 115–116, ACM, 2015
-
RPKI MIRO: Monitoring and Inspection of RPKI ObjectsIn: Proc. of ACM SIGCOMM, Demo Session, pp. 107–108, ACM, 2015
-
Federated End-to-End Authentication for the Constrained Internet of Things using IBC and ECCIn: Proc. of ACM SIGCOMM, Poster Session, pp. 603–604, ACM, 2015
-
The Abandoned Side of the Internet: Hijacking Internet Resources When Domain Names ExpireIn: Proc. of 7th International Workshop on Traffic Monitoring and Analysis (TMA), pp. 188–201, Springer-Verlag, 2015
-
Amplification and DRDoS Attack Defense – A Survey and New PerspectivesTechnical Report arXiv:1505.07892, Open Archive: arXiv.org, 2015
-
Native Actors: How to Scale Network ForensicsIn: Proc. of ACM SIGCOMM. Demo session, pp. 141–142, ACM, 2014
-
Spontaneous Wireless Networking to Counter Pervasive MonitoringIn: Proc. of W3C/IAB workshop on Strengthening the Internet Against Pervasive Monitoring (STRINT), 2014
-
Resource Public Key Infrastructure (RPKI) Router Implementation ReportRFC 7128, RFC Editor, IETF, 2014
-
The Abandoned Side of the Internet: Hijacking Internet Resources When Domain Names ExpireTechnical Report arXiv:1412.5052, Open Archive: arXiv.org, 2014
-
When BGP Security Meets Content Deployment: Measuring and Analysing RPKI-Protection of WebsitesTechnical Report arXiv:1408.0391, Open Archive: arXiv.org, 2014
-
RPKI Router Implementation ReportIETF Internet Draft – work in progress 05, SIDR Working Group, 2013
-
Backscatter from the Data Plane – Threats to Stability and Security in Information-Centric Network InfrastructureComputer Networks, 57(16), pp. 3192–3206, 2013
-
On Name-based Group Communication: Challenges, Concepts, and Transparent DeploymentComputer Communications, 36(15–16), pp. 1657–1664, 2013
-
RTRlib: An Open-Source Library in C for RPKI-based Prefix Origin ValidationIn: Proc. of 7th USENIX Security Workshop on Cyber Security Experimentation and Test (CSET), USENIX Assoc., 2013
-
Lessons from the Past: Why Data-driven States Harm Future Information-Centric NetworkingIn: Proc. of IFIP Networking, IEEE Press, 2013
-
Topology Authentication in RPLIn: Proc. of the 32nd IEEE INFOCOM. Poster Session, pp. 2447–2448, IEEE Press, 2013
-
Topology Authentication in RPLTechnical Report arXiv:1312.0984, Open Archive: arXiv.org, 2013
-
Conference Reports. Sec '13: 22nd USENIX Security Symposium. Large Scale Systems Security III;login:, 38(6), pp. 29–31, 2013Electronic supplement
-
Design, Implementation, and Operation of a Mobile HoneypotTechnical Report arXiv:1301.7257, Open Archive: arXiv.org, 2013
-
RPKI Router Implementation ReportIETF Internet Draft – work in progress 01, individual, 2012
-
Vitamin C for your Smartphone: The SKIMS Approach for Cooperative and Lightweight Security at MobilesIn: Proc. of ACM SIGCOMM. Demo, pp. 271–272, ACM, 2012
-
First Insights from a Mobile HoneypotIn: Proc. of ACM SIGCOMM. Poster, pp. 305–306, ACM, 2012
-
Bulk of Interest: Performance Measurement of Content-Centric RoutingIn: Proc. of ACM SIGCOMM. Poster, pp. 99–100, ACM, 2012
-
Towards Detecting BGP Route Hijacking using the RPKIIn: Proc. of ACM SIGCOMM. Poster, pp. 103–104, ACM, 2012
-
SAFEST: A Framework for Early Security Triggers in Public SpacesIn: Proc. of WISG 2012 – Workshop Interdisciplinaire sur la Securite Globale, 2012
-
Bridge the Gap: Measuring and Analyzing Technical Data for Social Trust between SmartphonesTechnical Report arXiv:1205.3068, Open Archive: arXiv.org, 2012
-
Short Paper: Can Your Phone Trust Your Friend Selection?In: Proc. of the 1st ACM CCS Workshop on Security and Privacy in Mobile Devices (SPSM), pp. 69–74, ACM, 2011
-
WiSec 2011 Poster: Context-adaptive Entropy Analysis as a Lightweight Detector of Zero-day Shellcode Intrusion for MobilesACM SIGMOBILE Mobile Computing and Communications Review (MC2R), 15(3), pp. 47–48, 2011
-
One Day in the Life of RPKICommunity note, RIPE Labs, 2011
-
Beta Version of the RPKI RTR Client C Library ReleasedCommunity note, RIPE Labs, 2011
-
Connecting the Worlds: Multipoint Videoconferencing Integrating H.323 and IPv4, SIP and IPv6 with Autonomous Sender AuthenticationIn: 13th IEEE International Symposium on Consumer Electronics (ISCE'09), pp. 890–893, IEEE Press, 2009
-
Overlay AuthoCast: Distributed Sender Authentication in Overlay MulticastIn: Proceedings of the 28th IEEE INFOCOM. Student Workshop, IEEE Press, 2009Extended abstract
-
AuthoCast — a mobility-compliant protocol framework for multicast sender authenticationSecurity and Communication Networks, 1(6), pp. 495–509, 2008
-
AuthoCast – A Protocol for Mobile Multicast Sender AuthenticationIn: Proceedings of the 6th International Conference on Advances in Mobile Computing & Multimedia (MoMM 2008), pp. 142–149, ACM, 2008