activity
20182025
most citedQUICsand: Quantifying QUIC Reconnaissance Scans and DoS Flooding Events

22 citations · 58 across the 9 of their papers we have counts for

collaborators
Showing cs.CRShow all

6 papers · 1 filter

cs.CR2024

A Call to Reconsider Certification Authority Authorization (CAA)

Pouyan Fotouhi Tehrani, Raphael Hiesgen, Thomas C. Schmidt +1

Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine it…

cs.CR202419 cited

The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments

Raphael Hiesgen, Marcin Nawrocki, Marinho Barcellos +14

Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best…

cs.CR20242 cited

Do CAA, CT, and DANE Interlink in Certificate Deployments? A Web PKI Measurement Study

Pouyan Fotouhi Tehrani, Raphael Hiesgen, Teresa Lübeck +2

Integrity and trust on the web build on X.509 certificates. Misuse or misissuance of these certificates threaten the Web PKI security model, which led to the development of several…

cs.CR20235 cited

Pool Inference Attacks on Local Differential Privacy: Quantifying the Privacy Guarantees of Apple's Count Mean Sketch in Practice

Andrea Gadotti, Florimond Houssiau, Meenatchi Sundaram Muthu Selva Annamalai +1

Behavioral data generated by users' devices, ranging from emoji use to pages visited, are collected at scale to improve apps and services. These data, however, contain fine-grained…

cs.CR2023

SoK: A Data-driven View on Methods to Detect Reflective Amplification DDoS Attacks Using Honeypots

Marcin Nawrocki, John Kristoff, Raphael Hiesgen +3

In this paper, we revisit the use of honeypots for detecting reflective amplification attacks. These measurement tools require careful design of both data collection and data analy…

cs.CR20213 cited

Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope

Raphael Hiesgen, Marcin Nawrocki, Alistair King +3

Large-scale Internet scans are a common method to identify victims of a specific attack. Stateless scanning like in ZMap has been established as an efficient approach to probing at…