Community anchor institutions (CAIs), such as libraries, schools, and community centers, are critical for providing Internet access to un- or under-served individuals and communities. Because many of these institutions are themselves under-provisioned, analyzing the reliability and quality of their Internet service is important. Doing so at scale requires knowing the IP addresses of these institutions so that broadband measurement and policy evaluation can occur. Unfortunately, these IPs are not systematically documented. As a first step towards widespread, scalable evaluation of CAI Internet connectivity, this paper presents Reverse IP Geolocation (RG), a new framework to infer IP addresses from physical address data. A key insight is that CAI street addresses are publicly known, which allows us to identify a candidate set of IPs from commercial geolocation that are likely serving the location associated with a CAI. In this paper, we focus on US public libraries, which offer both geographic diversity across thousands of locations, and some publicly available institutional records (WHOIS registrations) that enable systematic validation of our approach. Our approach offers a novel integration of IP geolocation databases, DNS PTR records, WHOIS registrations, broadband provider data, and active measurements to identify IPs likely assigned to libraries and validate them. Based on evaluations, our approach can map a library to its IP prefix approx. half of the time, with coverage across all US states, as well as urban and rural areas. Our results highlight the feasibility of mapping CAI presence in IP space and offer a foundation for large-scale, remote broadband infrastructure evaluation.
The end-to-end principle that limits on-path devices to simple tasks such as forwarding and routing has been one of the backbones of the Internet’s architecture. This is, however, being challenged as Internet paths now contain devices that inspect, filter, modify, or even discard packets. Some of these carry out benign and positive undertakings such as balancing resources and thwarting attacks, while others interfere with packets in unexpected ways leading to broken paths, thus inhibiting the deployment of new protocols or even extensions. While Internet ossification has already been studied in prior work, we propose to address new research questions enabled by recent Internet-scale middlebox mapping techniques. Combining Internet-scale measurements, measurements towards popular domains, repeated measurements, and longitudinal measurements, both in IPv6 and IPv4, we provide a multi-dimensional study on path-impairing middleboxes in the Internet. Our findings reveal that six times fewer IPv6 prefixes are affected than IPv4 prefixes by path-impairing middleboxes, and that there is an opportunity to switch between IPv4 and IPv6 to evade path-impairing middleboxes. Looking into the nature of path-impairments, we find that up to 87
DNS is one of the cornerstones of the Internet. Nowadays, a substantial fraction of DNS queries are handled by public resolvers (e.g., Google Public DNS and Cisco's OpenDNS) rather than ISP nameservers. This behavior makes it difficult for authoritative nameservers to provide answers based on the requesting resolver. The impact is especially important for entities that make client origin inferences to perform DNS-based load balancing (e.g., CDNS). The EDNS0 Client Subnet (ECS) option adds the client's IP prefix to DNS queries, which allows authoritative nameservers to provide prefix-based responses. Previous work showed the potential of data collected during ECS scans. Infrastructure can be uncovered, and operators' subnet-specific behavior can be observed. In this study, we introduce a new method for conducting ECS scans. Our method significantly reduces the required number of queries by up to 97% compared to state-of-the-art techniques and allows us to provide new insights into ECS behavior. Our approach is also the first to facilitate ECS scans for IPv6. Due to its vast address space, we have developed and analyzed different IPv6 scanning approaches. We conduct a comprehensive evaluation of the ECS landscape, examining the usage and implementation of ECS across various services. Overall, 53% of all nameservers support prefix-based responses. Furthermore, we find that Google nameservers do not comply with the Google Public DNS guidelines. Additionally, we observe that certain operators (e.g., AWS Route53) exclusively employ a single specific scope prefix length without aggregation, potentially affecting resolver cache efficiency. Lastly, we make our tool and data publicly available to foster further research in the area.
Clouds provide latency-sensitive services to clients at geographically distributed sites. They need precise control of client-site mappings for performance and, if a site fails, fast failover to other sites without cascading failures due to failover-induced overload or risky routing reconfiguration. However, clouds today route clients to sites by anycast or unicast with DNS-based redirection--methods that compromise either control or availability. In fact, even beyond these existing techniques, we find that all general-purpose approaches for directing clients to sites face inevitable tradeoffs among control, availability, and routing stability. We then present new general-purpose routing techniques and demonstrate via Internet-scale experiments that they provide much better tradeoffs among these three goals than existing techniques. One of our techniques achieves anycast's advantages with much better control, and another speeds up unicast's failover while preserving its advantages. Our techniques establish a new Pareto frontier for cloud routing.
Routing is essential to the Internet functioning. However, more and more functions are added to BGP, the inter-AS routing protocol. In addition to providing connectivity for best effort service, it carries flow specification rules and blackholing signals to react to DDoS, routes for virtual private networks, IGP link-state database information among other uses. One such addition is the tweaking of BGP advertisements to engineer the traffic, to direct it on some preferred paths. In this paper we aim to estimate the impact of Traffic Engineering (TE) on the BGP ecosystem. We develop a method to detect the impact in space, that is, to find which traffic engineering technique impacts which prefix and which AS. We design a methodology to pinpoint TE events to quantify the impact on time. We find that on average, a BGP vantage point sees 35
The growing importance of network security is driven by two major challenges. First, the ever-increasing volume of network traffic, which exceeds human processing capabilities. Second, the rising frequency and sophistication of new attacks require advanced and intelligent analysis to detect. To make critical decisions, such as blocking traffic from a specific IP address, security analysts need to understand why network intrusion detection systems are raising alarms. This highlights the limitations of relying on machine learning models whose internal decision-making processes are not transparent, often referred to as "black boxes". The key issue is their lack of interpretability when justifying critical security actions. Consequently, this paper emphasizes the need for providing explainable machine learning solutions. To detect new attacks effectively, we focus on behavioral approaches-specifically, analyzing short time windows of aggregated traffic to identify abnormal patterns-by experimenting with various unsupervised machine learning detectors. We found that these detectors often provide complementary results: they do not always agree on the same detections, and in some cases, a globally less effective detector can be the only one capable of accurately identifying a specific attack. This underlines the importance of adopting an ensemble approach to combine the strengths and perspectives of different models. Our contributions are threefold. First, we introduce a stacking-based ensemble learning strategy that improves detection accuracy by incorporating minority reports, going beyond standard majority-voting methods. Second, we present a visual representation technique that converts anomaly scores into heatmaps, making the system's outputs more interpretable to human analysts. Third, we leverage convolutional neural networks to process these visual representations, simulating human reasoning and enhancing pattern recognition while maintaining transparency. Overall, we develop and evaluate an unsupervised, explainable system capable of detecting even previously unknown network attacks, combining the strengths of ensemble learning and visual interpretability.
Despite prior efforts, the vast majority of the AS-level topology of the Internet remains hidden from BGP and traceroute vantage points. In this work, we introduce metAScritic, a novel system inspired by recommender system literature, designed to infer interconnections within a given metro. metAScritic uses the intuition that the connectivity matrix at a given metro is a low-rank system, since ASes employ similar peering strategies according to their infrastructures, traffic profiles, and business models. This approach allows metAScritic to accurately reconstruct the complete peering connectivity by measuring a strategic subset of interconnections that capture ASes' underlying peering strategies. We evaluate metAScritic's performance across six large metropolitan areas, achieving an average F-score of 0.88 on various validation datasets, including ground truth. metAScritic measures more than 86K edges and infers more than 368K edges, compared to the 13K edges observed for this subset of ASes in public BGP feeds -- an increase of (24X) what is currently seen. We study the impact of our inferred links on Internet properties, illustrating the extent of the Internet's flattening and demonstrating our ability to better predict the impact of route leaks and prefix hijacks, compared to relying only on the existing public view.
Today's Internet is dominated by a small number of companies which are responsible for a large fraction of Internet traffic. These so called "hypergiants" make use of off-nets to deploy parts of their infrastructure in ISP networks. Off-nets ensure that clients from these ISPs get lower latencies and the ISP needs to send less traffic to its upstream providers. They have been relatively well studied in the IPv4 Internet, although their footprint in IPv6 remains unclear. In this paper, we take a first look at the IPv6 hypergiant infrastructure. We perform a first-of-its-kind study of IPv6 off-nets for 14 hypergiants and compare their deployment to IPv4. We find IPv6 off-nets in 2k ASes, compared to the more than 6k off-net ASes for IPv4. Moreover, the majority of IPv6 off-nets deployments are seen in ASes which already deploy IPv4 off-nets. Interestingly, we also see some hypergiants such as Disney and Hulu not making use of any IPv6 off-nets at all. We also uncover the phenomenon of cross-hypergiant deployments, where one hypergiant deploys its infrastructure in another hypergiant's network. Finally, we use latency measurements to compare IPv6 vs. IPv4 latency to off-net prefixes within off-net ASes and find similar results for both protocol versions. We make all our code and data available to encourage replicability.
Despite more than twenty years of efforts, the research community is still looking for a publicly available Internet-scale IP geolocation dataset with an explainable methodology. Recently, a new hope has appeared, with the emergence of geofeeds. Geofeeds are a self published IP geolocation dataset where operators give the geolocation of their IP addresses, with the underlying idea being that other network providers can tune their services to better serve the IP address depending on its geolocation. In this paper, we analyze whether the hope of finally obtaining the golden geolocation dataset is a real possibility or a mirage. Two years after the standardization of geofeeds, we look at how they are adopted by operators, and what is their accuracy, and how we can use them for operational and research scenarios. First, geofeeds are in the early adoption process with 1.50% and 0.70% of the allocated IPv4 and IPv6 prefixes covering the geofeed prefixes. Second, even if we cannot use geofeeds as ground truth as we found 0.9%, 4.0%, and 8.5% of the client, router, and server IP addresses with an erroneous geofeed, most of them look correct and provide at least a geolocation hint for building an internet scale IP geolocation dataset. Finally, we provide some recommendations on how to use geofeeds and how we could improve the format and the process of sharing geofeeds to improve their quality.
Obtaining an accurate, explainable and Internet scale IP geolocation dataset has been a longstanding goal of the research community. Despite decades of research on IP geolocation, no current technique can provide such a dataset. In particular, latency-based geolocation techniques do not scale, because, on one hand, we have thousands of available vantage points to perform measurements, but on the other hand, we have no way to select the right ones for each IP address. In this paper, we present GeoResolver, which is a serious step towards our goal, by using the idea that when multiple operators redirect two prefixes to the same servers, these prefixes should be close to each other. With this intuition, we define a methodology to measure and compare the redirection of prefixes to servers using ECS DNS measurements, and select the prefixes with the smallest redirection distance to a target prefix to issue the latency measurements to targets in that prefix. GeoResolver performs nearly as well as a brute force approach, geolocating 94% of the targets that could actually be geolocated at metro level, while using 4.3% of the probing budget compared to the state of the art. On the Internet scale CAIDA ITDK dataset, GeoResolver geolocates 16% of the IP addresses at metro level, 3.4 times more than the state of the art. In addition, GeoResolver is robust to public resolvers or hypergiants stopping supporting ECS.
Google, Netflix, Meta, and Akamai serve content to users from offnet servers in thousands of ISPs. These offnets benefit both services and ISPs, via better performance and reduced interdomain and WAN traffic. We argue that this widespread distribution of servers leads to a concentration of traffic and a previously unacknowledged risk, as many ISPs colocate offnets from multiple providers. This trend contributes to many Internet users likely accessing multiple popular services and fetching the majority of their Internet traffic from a single facility -- perhaps even a single rack -- creating shared resources and a correlated risk in cases of failures, attacks, and overload. Alternate ways to access the services often lack sufficient capacity and share resources with more services, creating the potential for cascading failures.
Machine learning (ML) is a promising technology for network intrusion detection systems. There is a wide range of ML algorithms that are potential candidates for network intrusion detection systems, as they exhibit very good detection accuracy in average. However, significant detection differences appear when facing different kinds of attacks, some being prone to better detect some particular attack types. They then often appear to complement each other. The challenge then lies in determining the accurate result when several ML models provide different results, and this without any explanation about their decision. To address this challenge, our system aims to reconstruct attack patterns from the outputs of these ML models and presenting them in an interpretable manner. For that, we propose an approach combining ensemble learning and stacking with a meta-learner that works on graphical representation of traffic flows, that then provides the required explainability level for the decisions made. The evaluation of our system, using the CSE-CIC-IDS2018 dataset, demonstrates a significant improvement achieved through the combination of multiple ML algorithms. Furthermore, we emphasize the importance of explainability in network intrusion detection systems and the need for accurate and interpretable models. Our system goes beyond traditional detection methods by reporting anomalous feature pairs and providing visual representations of attack patterns, empowering analysts to better understand and respond to network threats.
Google, Netflix, Meta, and Akamai serve content to users from offnet servers in thousands of ISPs. These offnets benefit both services and ISPs, via better performance and reduced interdomain andWAN traffic. We argue that this widespread distribution of servers leads to a concentration of traffic and a previously unacknowledged risk, as many ISPs colocate offnets from multiple providers. This trend contributes to many Internet users likely accessing multiple popular services and fetching the majority of their Internet traffic from a single facility - perhaps even a single rack - creating shared resources and a correlated risk in cases of failures, attacks, and overload. Alternate ways to access the services often lack sufficient capacity and share resources with more services, creating the potential for cascading failures.
As RPKI is becoming part of ISPs' daily operations and Route Origin Validation is getting widely deployed, one wonders how long it takes for the effect of RPKI changes to appear in the data plane. Does an operator that adds, fixes, or removes a Route Origin Authorization (ROA) have time to brew coffee or rather enjoy a long meal before the Internet routing infrastructure integrates the new information and the operator can assess the changes and resume work? The chain of ROA publication, from creation at Certification Authorities all the way to the routers and the effect on the data plane involves a large number of players, is not instantaneous, and is often dominated by ad hoc administrative decisions. This is the first comprehensive study to measure the entire ecosystem of ROA manipulation by all five Regional Internet Registries (RIRs), propagation on the management plane to Relying Parties (RPs) and to routers; measure the effect on BGP as seen by global control plane monitors; and finally, measure the effects on data plane latency and reachability. We found that RIRs usually publish new RPKI information within five minutes, except APNIC which averages ten minutes slower. At least one national CA is said to publish daily. We observe significant disparities in ISPs' reaction time to new RPKI information, ranging from a few minutes to one hour. The delay for ROA deletion is significantly longer than for ROA creation as RPs and BGP strive to maintain reachability. Incidentally, we found and reported significant issues in the management plane of two RIRs and a Tier1 network.
What if tomorrow, hundreds, thousands, or even more people start sending 100,000 packets per second into the network using high speed probing? It is reasonable to think that this would not be a desirable scenario for the Internet. However, this might already be taking place, as high speed probing techniques such as ZMap [3] and Yarrp [ 1], the high speed evolution of Ping and Traceroute, are extensively used by the network research community and beyond. If they can definitely help for improving our understanding of the Internet, very little work has been done to examine their potential negative impact, i.e., their potential harm to the Internet's infrastructure, or their harm to the quality of measurement results. In this paper, we quantify the risks of those techniques, and provide recommendations on how to put in place high-speed ethical probing methods