Publications

41 publications.

2026

Achieving QUIC's Full Potential: How a DNS Deployment Gap Is Limiting HTTP/3 Performance
L. Csikor , D. M. Divakaran
NANOG 96, General Session (2026)
Abstract

The growing complexity of web browsing, driven by the widespread adoption of HTTPS and privacy-enhancing protocols like DNS-over-HTTPS (DoH), introduces significant network overhead. This is caused by a cascade of sequential handshakes and information retrievals—including DNS resolution, TLS setup, and protocol negotiation—that can cause substantial latency before a single byte of content is delivered. As a result, users often experience sub-optimal performance even on high-speed connections. In this presentation, we demonstrate how leveraging newly standardized DNS HTTPS records (RFC 9460) can significantly reduce this overhead. We will show how a missing link between browser capabilities and web server configurations prevents the full benefits of protocols like QUIC/HTTP/3 from being realized. Through our open-source WebTrafficSphere tool and the apexDNS proof-of-concept, we show how to transparently deliver the necessary endpoint information to the browser, bypassing unnecessary negotiation and reducing packet exchanges by up to 50%.

Drishti: AI-Led Human-Directed Vulnerability Auditing for 5G Cores
S. Ramachandran , L. Csikor , D. M. Divakaran
arXiv (2026)
Abstract

Candidate generation for open-source vulnerabilities is no longer scarce. AI-assisted code review now produces defect candidates cheaply, and industry programs pair them with expert human triage. The remaining scarcity is validation and impact assessment, and the gap is largest in critical-infrastructure software like 5G cores. Here, validation costs split along four axes: verification that a candidate is a real defect, reachability under a realistic attacker model, impact on a deployed stack, and fix-completeness against the vulnerability class rather than the reported instance. We present Drishti, an AI-led human-directed vulnerability audit framework built from four scaffolds, one per cost: (i) an anti-pattern catalog of recurring defect-producing code patterns in cellular-core codebases; (ii) a 3GPP-procedure-driven triage that prioritizes attacker-reachable procedures; (iii) concentric validation across four stages, each more expensive than the last; and (iv) a separable patch-defect axis that re-reads shipped CVE fixes from the original attacker's position. Across audits of Open5GS and free5GC, Drishti produced three findings: 1) a pre-authentication NULL-dereference in Open5GS's NRF multipart parser, fixed upstream and submitted to MITRE for a CVE; 2) an ASN.1-PER memory amplification in free5GC's NGAP decoder, where a 2-byte pre-authentication input from a rogue gNodeB OOM-kills the AMF in 6.2 seconds; and 3) a defective patch on CVE-2025-69248 whose intended defense-in-depth check is dead code on the pre-authentication path.

RECTor: Robust and Efficient Correlation Attack on Tor
B. Wu , D. M. Divakaran , L. Csikor , M. Gurusamy
IEEE Communications Magazine (2026)
Abstract

Tor is a widely used anonymity network that conceals user identities by routing traffic through encrypted relays, yet it remains vulnerable to traffic correlation attacks that deanonymize users by matching patterns in ingress and egress traffic. However, existing correlation methods suffer from two major limitations: limited robustness to noise and partial observations, and poor scalability due to computationally expensive pairwise matching. To address these challenges, we propose RECTor, a machine learning-based framework for traffic correlation under realistic conditions. RECTor employs attention-based Multiple Instance Learning (MIL) and GRU-based temporal encoding to extract robust flow representations, even when traffic data is incomplete or obfuscated. These embeddings are mapped into a shared space via a Siamese network, and efficiently matched using approximate nearest neighbor (aNN) search. Empirical evaluations show that RECTor outperforms state-of-the-art baselines such as DeepCorr, DeepCOFFEA, and FlowTracker - achieving up to 60% higher true positive rates under high-noise conditions, and reducing training and inference time by over 50%. Moreover, RECTor demonstrates strong scalability: inference cost grows near-linearly as the number of flows increases. These findings reveal critical vulnerabilities in Tor's anonymity model and highlight the need for advanced model-aware defenses.

2025

DNS-over-QUIC and HTTP/3 in the Era of Transformers: The New Internet Privacy Battle
L. Csikor , Z. Lian , H. Zhang , N. Lakshmanan , D. M. Divakaran
IEEE Communications Magazine (2025)
Abstract

Moving away from plain-text DNS communications, users now can switch to encrypted DNS protocols for name resolutions. DNS-over-QUIC (DoQ) employs QUIC—the latest transport protocol—for encrypted communications between users and their recursive DNS servers. QUIC is also poised to become the foundation of our daily web browsing by becoming the transport for HTTP/3, the latest version of the HTTP protocol. Traditional TCP-based web browsing is vulnerable to website fingerprinting (WFP) attacks that can identify the websites a user visits. The emergence of QUIC-based DNS and HTTP protocols raises an important question: are regular users better protected from WFP attacks when using these new protocols? To investigate this, we first collect and publicly release the first benchmark dataset of network traffic corresponding to real visits to QUIC-enabled websites while using DoQ for domain resolution. This dataset will help advance the research on WFP attacks and defenses. Second, we implement and evaluate the first WFP attack targeting the combined use of DoQ and HTTP/3 protocols by users by developing two transformer models tailored for WFP attacks. Finally, we conduct comprehensive experiments, which reveal that these models are effective in identifying user-visited websites, emphasizing the need for defensive measures.

2024

JUNCTION: A Scalable Multi-Access Solution Using Programmable Switches
X. Z. Khooi , C. H. Song , S. K. Permal , N. Budhdev , L. Csikor , R. Joshi , M. C. Chan
2024 21st Annual IEEE International Conference on Sensing, Communication, and Networking (SECON) (2024)
Abstract

Multi-access networks are increasingly important for reliable end-to-end connectivity and enhanced throughput performance. A scalable multi-access solution is required to roll out multi-access networks at scale. However, existing CPU-based solutions can no longer scale sustainably, as network traffic has outgrown the CPU performance growth. Consequently, hardware accelerators offer a compelling alternative. This paper introduces JUNCTION, a scalable multi-access solution designed using programmable switches. JUNCTION features a multipath protocol tailored to the hardware constraints and optimized for efficient memory utilization, enabling it to handle a large number of multipath sessions. We validate JUNCTION on a 5G-WiFi multi-access testbed. Our analysis demonstrates that it can scale an order of magnitude better than existing solutions.

RollBack: A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
L. Csikor , H. W. Lim , J. W. Wong , S. Ramesh , R. P. Parameswarath , M. C. Chan
ACM Transactions on Cyber-Physical Systems (2024)
Abstract

Automotive Keyless Entry (RKE) systems provide car owners with a degree of convenience, allowing them to lock and unlock their car without using a mechanical key. Today’s RKE systems implement disposable rolling codes, making every key fob button press unique, effectively preventing simple replay attacks. However, a prior attack called RollJam was proven to break all rolling code–based systems in general. By a careful sequence of signal jamming, capturing, and replaying, an attacker can become aware of the subsequent valid unlock signal that has not been used yet. RollJam, however, requires continuous deployment indefinitely until it is exploited. Otherwise, the captured signals become invalid if the key fob is used again without RollJam in place.We introduce RollBack, a new replay-and-resynchronize attack against most of today’s RKE systems. In particular, we show that even though the one-time code becomes invalid in rolling code systems, replaying a few previously captured signals consecutively can trigger a rollback-like mechanism in the RKE system. Put differently, the rolling codes become resynchronized back to a previous code used in the past from where all subsequent yet already used signals work again. Moreover, the victim can still use the key fob without noticing any difference before and after the attack.Unlike RollJam, RollBack does not necessitate jamming at all. In fact, it requires signal capturing only once and can be exploited at any time in the future as many times as desired. This time-agnostic property is particularly attractive to attackers, especially in car-sharing/renting scenarios in which accessing the key fob is straightforward. However, while RollJam defeats virtually any rolling code–based system, vehicles might have additional anti-theft measures against malfunctioning key fobs, hence against RollBack. Our ongoing analysis (with crowd-sourced data) against different vehicle makes and models has revealed that ∼ 50% of the examined vehicles in the Asian region are vulnerable to RollBack, whereas the impact tends to be smaller in other regions, such as Europe and North America.

2023

The Evolution of DNS Security and Privacy
L. Csikor , D. M. Divakaran
arXiv (2023)
Abstract

DNS, one of the fundamental protocols of the TCP/IP stack, has evolved over the years to protect against threats and attacks. This study examines the risks associated with DNS and explores recent advancements that contribute towards making the DNS ecosystem resilient against various attacks while safeguarding user privacy.

2022

ZeroDNS: Towards Better Zero Trust Security Using DNS
L. Csikor , S. Ramachandran , A. Lakshminarayanan
Proc. Annual Computer Security Applications Conference (ACSAC) (2022)
Abstract

Due to the increasing adoption of public cloud services, virtualization, IoT, and emerging 5G technologies, enterprise network services and users, e.g., remote workforce, can be at any physical location. This results in that network perimeter cannot be defined precisely anymore, making adequate access control with traditional perimeter-based network security models (e.g., firewall, DMZ) challenging. The Zero Trust (ZT) network access framework breaks with this traditional approach by removing the implicit trust in the network. ZT demands strong authentication, authorization, and encryption techniques irrespective of the physical location of the devices. While several prominent companies have embraced ZT (e.g., Google, Microsoft, Cloudflare), its adoption has several obstacles. In this paper, we focus on three problems with practical deployment of ZT. First, the DNS infrastructure, a critical entity in every network, does not adhere to ZT principles, i.e., anyone can access the DNS and resolve a domain name or leverage it with malicious intent. Second, ZT's authorization procedures require new entities in the network to authorize and verify access requests, which can result in changes in preferred network routes (hence requiring additional traffic engineering), as well as introduce potential bottlenecks. Thirdly, ZT adds additional time cost, increasing the time-to-first-byte (TTFB). We propose ZeroDNS, wherein the control plane of Zero Trust is implemented using the DNS infrastructure, obviating the need for a separate entity to issue authorization tokens. Since the control plane is implemented using DNS, it reduces the number of round-trips authorized clients require before accessing an enterprise resource (e.g., web service). Furthermore, we apply ZT principles to DNS, meaning access to DNS requires authentication, authorization, and encrypted communication. ZeroDNS uses mutual TLS for DNS communication for authentication, and only permitted clients with valid certificates can query domain names. We implement ZeroDNS on top of NGINX, a reverse proxy typically used as a load-balancer in enterprise settings. We show that the additional packet processing time in ZeroDNS has a negligible impact on the overall name resolution latency, yet it decreases TTFB.

RollBack - A New Time-Agnostic Replay Attack Against the Automotive Remote Keyless Entry Systems
L. Csikor , H. W.Lim , S. Ramesh , J. W. Wong , R. P. Parameswarath , C. M. Choon
BlackHat USA Briefings (2022)
Abstract

Automotive Remote Keyless Entry (RKE) systems implement disposable rolling codes, making every key fob button press unique, effectively preventing simple replay attacks. However, RollJam was proven to break all rolling code-based systems in general. By a careful sequence of signal jamming, capturing, and replaying, an attacker can become aware of the subsequent valid unlock signal1 that has not been used yet. RollJam, however, requires continuous deployment indefinitely until it is exploited. Otherwise, the captured signals become invalid if the key fob is used again without RollJam in place. We introduce RollBack, a new replay-and-resynchronize attack against most of today's RKE systems. In particular, we show that even though the one-time code becomes invalid in rolling code systems, replaying a few previously captured signals consecutively can trigger a rollback-like mechanism in the RKE system. Put differently, the rolling codes become resynchronized back to a previous code used in the past from where all subsequent yet already used signals work again. Moreover, the victim can still use the key fob without noticing any difference before and after the attack. Unlike RollJam, RollBack does not necessitate jamming at all. Furthermore, it requires signal cap- turing only once and can be exploited any time in the future as many times as desired. This time-agnostic property is particularly attractive to attackers, especially in car-sharing/renting scenarios where accessing the key fob is straightforward. However, while RollJam defeats virtually any rolling code-based system, vehicles might have additional anti-theft measures against malfunctioning key fobs, hence against Roll- Back. Our ongoing analysis (covering Asian vehicle manufacturers for the time being) against different vehicle makes and models using RKE implementations from NXP revealed that more than 80% of them are vulnerable to RollBack.

2021

Privacy of DNS-over-HTTPS: Requiem for a Dream?
L. Csikor , H. Singh , M. S. Kang , D. M. Divakaran
IEEE European Symposium on Security and Privacy (2021)
Abstract

The recently proposed DNS-over-HTTPS (DoH) protocol is becoming increasingly popular in addressing the privacy concerns of exchanging plain-text DNS messages over potentially malicious transit networks (e.g., mass surveillance at ISPs). By employing HTTPS to encrypt DNS communications, DoH traffic inherently becomes indistinguishable from regular encrypted Web traffic, rendering active disruption (e.g., downgrading to the plain-text DNS) by transit networks extremely hard. In this work, we investigate whether DoH traffic is indeed indistinguishable from encrypted Web traffic. To this end, we collect several DoH traffic traces corresponding to 25 resolvers (including major ones, e.g., Google and Cloudflare) by visiting thousands of domains in Alexa's list of top-ranked websites at different geographical locations and environments. Based on the collected traffic, we train a machine learning model to classify HTTPS traffic as either Web or DoH. With our DoH identification model in place, we show that an authoritarian ISP can identify ~97.4% (~90%) of the DoH packets correctly in a closed-world (open-world) setting while only misclassifying 1 in 10, 000 Web packets. To counter this DoH identification model, we propose an effective mitigation technique, making the identification model impractical for ISPs to filter and consequently downgrade DoH to plain-text DNS communications.

2020

Transition to SDN is HARMLESS: Hybrid Architecture for Migrating Legacy Ethernet Switches to SDN
L. Csikor , M. Szalay , G. Rétvári , G. Pongrácz , D. P. Pezaros , L. Toka
IEEE/ACM Trans. Netw. (2020)
On the Feasibility and Enhancement of the Tuple Space Explosion Attack against Open vSwitch
L. Csikor , V. Ujawane , D. M. Divakaran
CoRR (2020)
DIDA: Distributed In-Network Defense Architecture Against Amplified Reflection DDoS Attacks
X. Z. Khooi , L. Csikor , D. M. Divakaran , M. S. Kang
2020 6th IEEE Conference on Network Softwarization (NetSoft) (2020)
Towards Low Latency Industrial Robot Control in Programmable Data Planes
F. E. R. Cesen , L. Csikor , C. Recalde , C. E. Rothenberg , G. Pongrácz
2020 6th IEEE Conference on Network Softwarization (NetSoft) (2020)
Towards In-Network Time-Decaying Aggregates for Heavy-Hitter Detection
X. Z. Khooi , L. Csikor , M. S. Kang , D. M. Divakaran
Proceedings of the ACM SIGCOMM 2020 Conference on Posters and Demos (2020)
In-Network Defense Against AR-DDoS Attacks
X.Z. Khooi , L. Csikor , M. S. Kang , D. M. Divakaran
Proceedings of the ACM SIGCOMM 2020 Conference on Posters and Demos (2020)

2019

The Discrepancy of the Megaflow Cache in OVS, Part II
L. Csikor , M. S. Kang , D. M. Divakaran
OVS+OVN Conference (2019)
Tuple Space Explosion: A Denial-of-Service Attack against a Software Packet Classifier
L. Csikor , D. M. Divakaran , M. S. Kang , A. Kőrösi , B. Sonkoly , D. Haja , D. P. Pezaros , S. Schmid , G. Rétvári
Proc. International Conference on Emerging Networking Experiments And Technologies (2019)

2018

BB-Gen: A Packet Crafter for P4 Target Evaluation
F. C. E. Rodriguez , G. Patra , L. Csikor , C. E. Rothenberg , S. Laki , P. Vörös , G. Pongrácz
Proceedings of the ACM SIGCOMM 2018 Conference on Posters and Demos (2018)
Policy Injection: A Cloud Dataplane DoS Attack
L. Csikor , C. E. Rothenberg , D. P. Pezaros , S. Schmid , L. Toka , G. Rétvári
Proceedings of the ACM SIGCOMM 2018 Conference on Posters and Demos (2018)
Towards a Sweet Spot of Dataplane Programmability, Portability and Performance: On the Scalability of Multi-Architecture P4 Pipelines
G. Patra , F. C. E. Rodriguez , J. S. Mejia , D. Feferman , L. Csikor , C. E. Rothenberg , G. Pongrácz
IEEE Journal on Selected Areas in Communications, Scalability Issues and Solutions for Software Defined Networks (2018)
HARMLESS: Cost-Effective Transitioning to SDN for Small Enterprises
L. Csikor , L. Toka , M. Szalay , G. Pongrácz , D. P. Pezaros , G. Rétvári
Proceedings of IFIP Netwoking (2018)
The Discrepancy of the Megaflow Cache in OVS
L. Csikor , G. Rétvári
Open vSwitch Fall Conference (2018)

2017

End-host Driven Troubleshooting Architecture for Software-Defined Networking
L. Csikor , D. P. Pezaros
IEEE Globecom 2017 (2017)
HARMLESS: Cost-Effective Transitioning to SDN
M. Szalay , L. Toka , G. Rétvári , G. Pongrácz , L. Csikor , D. P. Pezaros
Proceedings of the SIGCOMM Posters and Demos (2017)

2016

Dataplane Specialization for High-performance OpenFlow Software Switching
L. Molnár , G. Pongrácz , G. Enyedi , Z. Kis , L. Csikor , F. Juhász , A. Kőrösi , G. Rétvári
ACM SIGCOMM (2016)

2015

On Providing Fast Protection with Remote Loop-Free Alternates
L. Csikor , G. Rétvári
Telecommunication Systems Journal (2015)
Customizable real-time service graph mapping algorithm in carrier grade networks
B. Németh , J. Czentye , G. Vaszkun , L. Csikor , B. Sonkoly
IEEE Conference on Network Function Virtualization and Software Defined Networks Demo Track (NFV-SDN) (2015)
NFPA: Network Function Performance Analyzer
L. Csikor , M. Szalay , B. Sonkoly , L. Toka
IEEE Conference on Network Function Virtualization and Software Defined Networks Demo Track (NFV-SDN) (2015)

2014

Multi-layered Service Orchestration in a Multi-Domain Network Environment
A. Csoma , B. Sonkoly , L. Csikor , F. Németh , A. Gulyás , D. Jocha , J. Elek , W. Tavernier , S. Sahhaf
EWSDN (DEMO) (2014)
SDN based testbeds for evaluating and promoting multipath TCP
B. Sonkoly , F. Németh , L. Csikor , A. L. Gulyás , A. Gulyás
Proc. IEEE International Conference on Communications (ICC) (2014)
ESCAPE: Extensible Service Chain Prototyping Environment Using Mininet, Click, NETCONF and POX
A. Csoma , B. Sonkoly , L. Csikor , F. Németh , A. Gulyás , W. Tavernier , S. Sahhaf
ACM SIGCOMM (DEMO) (2014)

2013

A Large-Scale Multipath Playground for Experimenters and Early Adopters
F. Németh , B. Sonkoly , L. Csikor , A. Gulyás
ACM SIGCOMM (DEMO) (2013)
Improving resiliency and throughput of transport networks with OpenFlow and Multipath TCP: Demonstration of results over the Géant OpenFlow testbed (Demonstration of results over the Géant OpenFlow testbed)
F. Németh , B. Sonkoly , L. Csikor , A. Gulyás
Open Networking Summit (DEMO) (2013)
High Availability in the Future Internet
L. Csikor , G. Rétvári , J. Tapolcai
The Future Internet (2013)
Optimizing IGP Link Costs for Improving IP-level Resilience with Loop-Free Alternates
L. Csikor , G. Rétvári , J. Tapolcai
Computer Communications Journal (2013)

2012

IP Fast Reroute with Remote Loop-Free Alternates: the Unit Link Cost Case
L. Csikor , G. Rétvári
Proc. RNDM (2012)

2011

Information Spreading in Self Organizing Mobile Network
L. Csikor , Z. Fehér
MACRo (2011)
Optimizing IGP Link Costs for Improving IP-level Resilience
G. Rétvári , L. Csikor , J. Tapolcai , G. Enyedi , A. Császár
Proc. International Workshop on Design Of Reliable Communication Networks (DRCN) (2011)
Network Optimization Techniques for Improving Fast IP-level Resilience with Loop-Free Alternates
L. Csikor , M. Nagy , G. Rétvári
Infocommunications Journal (2011)

2010

Exploring Hidden Relations in Moving Human Groups
L. Csikor , Z. Fehér
POSTER (2010)