NetS&P studies the security and privacy of real-world networked and distributed systems. We focus on failures that emerge when protocol designs meet deployment realities, including routing structure, control logic, resource management, metadata exposure, and interactions across system layers.
Our research combines adversarial analysis, large-scale measurement, testbed experiments, and prototype system development. We aim to uncover security assumptions that do not hold in practice and to design defenses that operators can deploy in real systems.
· Internet Infrastructure and Programmable Network Security: Internet routing, routing-aware denial-of-service attacks, programmable switches, and adaptive data-plane defenses
· Tor and Anonymity Network Security: Onion-service availability, traffic analysis, deanonymization, and privacy-preserving defenses
· Blockchain Security and Privacy: Peer-to-peer networking, consensus implementations, transaction ordering, privacy, and blockchain forensics
· Cellular and Mobile Systems Security: 5G and 6G security, cellular signaling, device identification and localization, secure vRAN operation, and non-terrestrial network security
· Privacy in Online and Emerging Systems: Metadata leakage and privacy failures in encrypted protocols, communication platforms, IoT systems, and immersive platforms
We study the Internet as a distributed control system whose routing decisions, resource allocation, and defense mechanisms can themselves become attack surfaces. Our work examines how adversaries manipulate network structure and control state, and how operators can respond without disrupting legitimate traffic.
Selected research directions include:
· Interactive routing security. iROV extends Route Origin Validation with just-in-time authorization from prefix owners. It restores reachability for urgent routing changes, provides real-time feedback about invalid routes, and helps distinguish attacks from benign operational changes. (USENIX Security 2026)
· Security of programmable data-plane defenses. Heracles shows that the memory-adaptation mechanisms used by programmable-switch DoS defenses can be exploited to create coordinated resource contention. Shield separates memory operations across the control and data planes to preserve line-rate mitigation under these attacks. (NDSS 2026)
· Routing-aware denial-of-service attacks and defenses. Crossfire introduced a link-flooding attack that exploits routing structure to disconnect a target area without directly flooding it. Follow-up work developed collaborative defense with CoDef, active bottleneck discovery with SPIFFY, and practical verifiable in-network filtering. Together, these projects established routing structure and defense adaptation as central elements of the attack surface. (Crossfire: IEEE S&P 2013; CoDef: ACM CoNEXT 2013; SPIFFY: NDSS 2016; Verifiable Filtering: IEEE ICDCS 2019)
Evidence: Crossfire | CoDef | SPIFFY
· Agent-programmable data planes. We explore how AI agents can analyze network conditions and safely reconfigure programmable data-plane monitoring and mitigation modules at runtime, combining rapid response with longer-term strategic analysis while bounding the risks of autonomous reconfiguration. (Ongoing Project)
Tor must provide anonymity while remaining available under abuse and denial-of-service attacks. These goals are closely connected because a defense introduced to protect availability may create new attack surfaces or expose information about a hidden service.
Our Tor research includes:
· Onion-service denial-of-service attacks. OnionFlation demonstrates that an attacker can manipulate Tor's client-puzzle mechanism and inflate the puzzle difficulty faced by legitimate users, making an onion service largely unusable at low attack cost. The work identifies a fundamental tension between resistance to congestion and resistance to puzzle inflation and provides guidance for configuring practical defenses. (USENIX Security 2025)
· NetFlow-based deanonymization. On the Effectiveness of NetFlow-Based Deanonymization of Tor Onion Services shows that coarse operational telemetry, including minute-level sampled packet counts, can be sufficient to locate onion services. We study active attacks based on controlled downloads and introduction requests, as well as a passive attack that correlates publicly visible puzzle difficulty with NetFlow traces without sending traffic to the target service. (IEEE S&P 2027)
· Deployable anonymity defenses. We investigate mitigations such as traffic-signature detection, infrastructure and IP rotation, and redesigns of globally visible defense signals. Our goal is to strengthen availability without introducing new information that can be used for deanonymization. (Ongoing Project)
Blockchain security depends on more than cryptographic primitives and consensus algorithms. Peer discovery, network topology, propagation behavior, transaction ordering, implementation state, and economic semantics all affect the security of deployed blockchain systems.
Our work covers four main directions:
· Peer-to-peer network security. Erebus showed how an autonomous-system-level adversary can isolate Bitcoin nodes without BGP hijacking. Follow-up work studied routing-aware peering and the sustainability of Bitcoin partitioning attacks. Gethlighting then demonstrated that an Ethereum node can be partitioned for hours without fully eclipsing its peer connections. (Erebus: IEEE S&P 2020; Routing-aware Peering: USENIX Security 2021; Sustainability: Financial Cryptography 2023; Gethlighting: NDSS 2023)
Evidence: Erebus | Gethlighting
· Consensus implementation security. Forky introduces fork-state-aware differential fuzzing for blockchain consensus implementations. It explores protocol states that conventional testing can miss and compares implementations to identify divergent behavior. (ICSE 2025)
· Transaction ordering and fairness. Ambush shows that batch-order-fair systems can remain vulnerable to frontrunning even when they remove a sequencer's direct control over transaction ordering. This work examines how network latency and locally observed transaction sequences undermine expected ordering guarantees. (ACM CCS 2025)
· Blockchain privacy and forensics. Obscuro studied efficient Bitcoin mixing using trusted execution environments. More recently, Deniable Covert Asset Transfer (DCAT) studies a stronger privacy goal: concealing whether an asset transfer occurred at all. DCAT embeds transfers into ordinary loss-producing DeFi activities such as sandwich attacks and arbitrage, and develops statistical methods that prioritize economically unusual cases for forensic investigation without treating extreme but naturally occurring activity as conclusive evidence. (Ongoing Project)
Evidence: DCAT preprint
Cellular systems combine complex signaling protocols, closed implementations, shared radio resources, and strict real-time processing. We study how these properties create security and privacy risks, and we build mechanisms that make mobile infrastructure safer to operate and evolve.
Selected projects include:
· Cellular side channels and location privacy. SLIC showed that plaintext carrier-aggregation MAC control elements can reveal a target user's fine-grained walking path. Moba showed that the same family of low-layer side channels can reveal which YouTube video a user is watching by eavesdropping only on broadcast cellular messages. (SLIC: USENIX Security 2021; Moba: ACM IMWUT/UbiComp 2022)
· Fine-grained vRAN operation. Thor introduces per-user-equipment baseband routing in virtualized RANs. Standards-compliant middleboxes at the FAPI and O-RAN fronthaul interfaces allow multiple physical-layer implementations to run concurrently within one cell. This enables incremental L1 updates, controlled testing, and service differentiation while preserving shared cell context and strict processing deadlines. (ACM MobiCom 2026)
· Detection and localization of abusive devices. We developed device-fingerprinting methods for detecting SIM boxes and techniques for physically localizing uncooperative cellular devices. These projects study how protocol behavior and radio signals can support fraud detection and authorized investigations. (SIM Box Detection: NDSS 2023; Device Localization: ACM MobiCom 2024)
· Future mobile infrastructure. Our ongoing research explores operator-programmable security mechanisms for 5G Advanced, 6G, Open RAN, and non-terrestrial networks, including mechanisms that can deploy targeted fixes without waiting for ecosystem-wide software updates. (Ongoing Project)
Encryption does not eliminate privacy risks when metadata, deployment artifacts, or user-interface behavior remain observable. We study the gap between the privacy that users expect and the behavior that networked systems actually exhibit.
Our recent work includes:
· Encrypted DNS privacy. We study how DNS-over-HTTPS can be identified, interfered with, or downgraded in real deployments, and how clients and resolvers can detect and bypass such interference. (ACM CoNEXT 2024)
· Communication-platform privacy. Our research examines how users understand privacy features in videoconferencing systems and whether the network behavior of these systems matches what their interfaces communicate. This work has uncovered previously unknown privacy vulnerabilities and led to CVE assignments and vendor-coordinated fixes. (PETS 2025; Ongoing Project)
· IoT, VR, and immersive platforms. We investigate privacy-preserving monitoring of IoT security and metadata leakage from vertically integrated platforms. Our work shows that platform-level traffic can reveal application usage and in-application behavior even when individual applications generate little observable traffic. (Ongoing Project)
Our projects begin with real protocols, deployed systems, or operational constraints. We construct realistic adversary models, measure their impact, and develop prototypes or mitigations that can be evaluated on live networks, production software, programmable hardware, or standards-compliant testbeds.
We also value responsible disclosure and practical impact. Our research has resulted in coordinated vulnerability disclosures, CVE assignments, security bounties, vendor acknowledgments, and changes to deployed systems.
Please see our Publications page for a complete list of papers and project materials.
Our research is designed not only to identify security vulnerabilities, but also to improve the systems, protocols, and research practices that underpin today's digital infrastructure. The examples below document cases in which our findings led to deployed software changes, vendor patches, coordinated vulnerability response, standards activity, or new directions in security research.
Erebus revealed that an autonomous-system-level adversary could gradually take control of a Bitcoin node's peer connections and partition it from the network.
Bitcoin Core subsequently introduced ASN-aware peer bucketing through the -asmap option. Instead of relying only on IP-prefix groupings, the mechanism can map addresses to autonomous systems and limit concentration within a single AS. The merged implementation, pull request, and Bitcoin Core 0.20 release notes provide a direct record of the change.
Evidence: Erebus paper | Bitcoin Core implementation | PR 16702 | Bitcoin Core 0.20 release notes
Impact: Deployed mitigation in Bitcoin Core
System change: ASN-aware peer selection and improved connection diversity
Gethlighting demonstrated that an Ethereum node could be partitioned for hours without fully eclipsing all of its peer connections.
After responsible disclosure, a mitigation proposed in our work - throttling peers that repeatedly deliver invalid transactions - was accepted into Go Ethereum. The patch is recorded in Go Ethereum PR 25573 and was tracked for the Geth 1.11.0 milestone.
Evidence: Research paper | Go Ethereum PR 25573 | Geth 1.11.0 milestone
Impact: Deployed hotfix in the dominant Ethereum client
System change: Throttling peers that deliver large numbers of invalid transactions
Our research on inconsistencies between a videoconferencing interface and its underlying network behavior uncovered previously unknown privacy problems in Zoom. The work led to coordinated disclosure, CVE assignments, and vendor updates.
One publicly documented case, CVE-2024-45424, was an information-disclosure vulnerability caused by a business-logic error. Zoom's bulletin lists fixed versions across Workplace Apps, Rooms, VDI, and Meeting SDK product lines.
Evidence: Zoom bulletin ZSB-24036 | CVE-2024-45424 | NVD record
Impact: Vendor-confirmed vulnerability and product updates
System change: Patched Zoom clients and SDKs across multiple platforms
OnionFlation showed that Tor's proof-of-work defense could itself be manipulated to deny access to legitimate onion-service users. The attack can artificially inflate puzzle difficulty without producing the congestion signals that the defense was designed to detect.
We responsibly disclosed the findings to the Tor Project, shared test cases and attack traces, and worked with developers to support reproduction and mitigation. The Tor team imported the attack artifacts into its internal tracker and began evaluating a configurable difficulty-update algorithm proposed in our work. Public evidence supports acknowledgment and active remediation; it does not yet establish deployment in a Tor release.
Evidence: OnionFlation paper | Tor proof-of-work specification
Impact: Tor Project acknowledgment, internal testing, and mitigation review
Current status: Remediation in progress
SLIC showed that a passive adversary can track a target user by reading unencrypted flag bits in downlink carrier-aggregation MAC control elements. The work was disclosed through the GSMA Coordinated Vulnerability Disclosure program, which records it as CVD-2020-0040.
No complete fix has yet been incorporated into the relevant 3GPP specifications. The issue remained under active standards discussion in November 2025: 3GPP SA3 contributions S3-254157, S3-254352, and S3-254446 each proposed a key issue concerning MAC CE security or protection. This record makes the status clear: the vulnerability has been validated and repeatedly raised, while an ecosystem-wide remedy remains unsettled.
The gap also motivates Buckler, our ongoing framework for temporary, local, and reversible RAN hotfixes. A security-sensitive private operator could use this form of operator-controlled mitigation during the long interval before a standards- and vendor-led permanent repair becomes available.
Evidence: SLIC paper | GSMA CVD-2020-0040 | S3-254157 | S3-254352 | S3-254446 | Buckler
Impact: GSMA-coordinated disclosure and continuing standards activity
Current status: MAC CE protection remains an open standards problem; Buckler explores deployable interim mitigation
Crossfire introduced a new form of denial-of-service attack that disconnects a target area by congesting carefully selected network links rather than directly flooding the target.
The work helped establish link flooding as a distinct research problem and inspired sustained research on routing-aware detection, traffic-engineering defenses, software-defined-networking countermeasures, and adaptive attackers. Our own follow-up systems, including CoDef and SPIFFY, developed collaborative and active defenses against this class of attacks.
Modern carpet-bombing is a practical special case of the Crossfire paradigm: attackers distribute low-rate traffic across many destinations within a prefix so that flows converge on shared upstream links while individual destinations remain below conventional detection thresholds. This operational pattern reinforces Crossfire's central insight that the attack target may be a network bottleneck rather than the addressed hosts.
Evidence: Crossfire paper | CoDef | SPIFFY | Operational carpet-bombing analysis
Impact: Established a long-running research area in routing-aware DDoS attacks and defenses
Broader relevance: Anticipated distributed, low-rate attacks that evade endpoint-oriented defenses
We evaluate impact using verifiable evidence: source-code changes, release notes, security advisories, vulnerability identifiers, standards records, coordinated-disclosure acknowledgments, and direct adoption by later research.
Not every important result immediately produces a patch. Some findings reveal architectural limitations that require long-term protocol or standards work; others provide the concepts and methods on which later attacks and defenses are built. We report these forms of impact separately so that each claim can be traced to its supporting evidence.