REVIEW 2 major objections 6 minor 54 references
NetCloak: Dynamic Topology Expansion for Secure and Scalable Configuration Sharing
T0 review · 2 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read NetCloak claims to conceal a network's true size by embedding it in a larger synthetic topology while leaving every real forwarding path intact.
desk verdict k-DMA's threat model leaks the network scale the paper promises to hide, so the central privacy claim fails; the system engineering is real but needs a major rewrite. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing machinery is the graph-embedding expansion plus the $k$-degree mapping anonymity condition. Embedding is a maximum bipartite matching between original nodes and reference nodes of no smaller degree, followed by Havel-Hakimi-style residual degree completion and greedy edge rearrangement; it determines which nodes exist and how many links each one has. $k$-DMA is the privacy condition that makes those added nodes protective: because every original node has at least $k$ peers of equal or higher degree in the anonymized graph, degree information alone cannot identify the real devices. The functional carrier is the layered repair: inside an AS, SMT constraints encode the required shortest paths, with a correction distinguishing a unique primary path from ECMP alternatives, and between ASes, iterative comparison of border-router forwarding tables inserts filters until both views agree. Mimicry-based configuration generation supplies the realism carrier: each fake router inherits the command structure, stanza ordering, and naming conventions of its most similar real router.
What would settle it
Run a deanonymization game: give an adversary the anonymized configuration plus a candidate original network with fewer routers, and ask it to decide whether the original router count equals the small candidate or the expanded count. The scale-concealment claim fails if the adversary succeeds by counting host subnets, matching organizational records, or exploiting stylistic fingerprints, rather than by using the degree sequence that $k$-DMA is designed to protect.
Extended reading notes
Core claim
The central proposal is that obscuring a network's scale is compatible with preserving its function. NetCloak takes the original router-level graph and embeds it in a larger graph drawn from a real-world reference topology: each original node is matched to a reference node of at least equal degree, the original edges are kept, and the remaining degree budget is filled with Havel-Hakimi-style edge addition and greedy rewiring so that the anonymized degree sequence closely tracks the reference. A new privacy definition, $k$-degree mapping anonymity, then says that an attacker who knows only the original degree sequence, not the anonymized one, cannot single out any original node: under the strong form, the $i$-th highest-degree original node has at least $k+i-1$ nodes of at least its degree in the output. Configuration generation mimics real routers and applies the same routing-policy filters to fake hosts, and a layered repair step—SMT constraints for intra-AS paths, iterative forwarding-table filtering between ASes—restores the original end-to-end routes. The paper claims this combination conceals network size while satisfying strong functional equivalence, so control-plane and verification tools see a plausible larger network with intact real behavior.
Load-bearing premise
The whole privacy guarantee rests on the assumption that the adversary knows only the original network's degree sequence, and that no other observable signal—host counts, naming conventions, organizational data, traffic patterns, or configuration style—can separate the injected routers and hosts from real ones.
Editorial extensions
If this is right
- Organizations can publish anonymized configurations without revealing router count, so outsiders cannot infer organizational size or data-center capacity from topology degrees.
- Real configurations can be expanded into larger datasets, giving verification, synthesis, and repair research more realistic inputs than purely synthetic ones.
- Because strong functional equivalence is preserved, existing control-plane simulators and verifiers can be run on the anonymized files and will see the original forwarding behavior.
- The $k$-DMA notion requires far fewer added edges than classical $k$-degree anonymity, so anonymized networks stay structurally plausible instead of accumulating telltale fake links.
- The SMT-for-intra-AS, iterative-for-inter-AS split makes repair time stable under randomized link costs, where a purely iterative method can take many rounds.
Reading between the lines
- The scale-concealment guarantee is only as strong as the stated threat model: an adversary who exploits host subnets, VLANs, organizational charts, or traffic volumes is outside the model, and those signals would likely fingerprint real nodes; a natural extension is to anonymize those layers too.
- The rationality metric only measures the degree distribution, the 1K property of the dK-series, so the embedding could in principle be upgraded to preserve joint-degree (2K) and triangle (3K) correlations; the paper notes this direction but does not implement it.
- The choice of reference topology is a hidden parameter: when no reference is close to the target size, embedding overshoots the requested node count, so building synthetic reference topologies at arbitrary scales is a testable way to make the method fully flexible.
- A direct way to test the privacy claim without relying on graph properties alone would be an end-to-end deanonymization game: given the anonymized configs, can a classifier tell real devices from injected ones using style, naming, and policy patterns?
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents NetCloak, a configuration-anonymization framework that injects synthetic routers and hosts into a network topology to obscure network scale while preserving end-to-end forwarding behavior. The system selects a reference topology, embeds the original graph into it, applies a new k-degree mapping anonymity (k-DMA) scheme, generates fake configurations via template mimicry, and repairs routing using a combination of SMT-based intra-AS synthesis and iterative inter-AS filtering. Experiments on real and emulated campus/data-center topologies report a 73.5% improvement in topological rationality, a 29.0% increase in configuration similarity, and roughly 60% faster route repair relative to baselines. The paper is positioned as an extension of ConfMask that overcomes its inability to add router nodes.
Significance. If the central claim held, NetCloak would be a useful step toward privacy-preserving sharing of realistic network configurations, extending prior work beyond link/host manipulation to node-level scale obfuscation. The paper has clear strengths: it presents a complete implemented system built on ConfMask and NetComplete, evaluates on a diverse set of 12 networks, candidly discusses limitations in Section 8, and identifies a concrete gap in prior anonymization tools. The threat-model problem described below, however, means the headline privacy claim is not currently supported by the formal framework; the engineering and evaluation contributions are real but the core privacy assertion needs substantial revision.
major comments (2)
- [§2.3, §3.1, §4.2] The formal threat model is internally inconsistent with the paper's central claim of concealing network scale. Definition 3.2 and Section 4.2 state that k-degree mapping anonymity assumes the attacker knows only the original degree sequence. That sequence has exactly |V| entries, so an attacker granted this knowledge already knows the original router count with certainty. Consequently, injecting synthetic nodes cannot conceal scale from the stated adversary; the k-DMA guarantee only limits which anonymized nodes can be mapped to which original nodes, not the total number of real routers. The abstract and Section 2.3 promise that NetCloak 'obfuscates true scale,' but the formal model gives the scale to the attacker as background knowledge. The evaluation also never measures how well an adversary can estimate the original node count from the anonymized graph. This is a load-bearing mismatch: either the threat model should be revised to an adversary who does not know the original degree sequence (with an empirical scale-hiding evaluation), or the 'conceals network size' claim should be replaced by a narrower claim about hiding node identities and degree mappings.
- [Definition 3.3, §4.1, §6.3] Topological rationality is defined as the K-S distance between the degree sequence of the anonymized graph and that of the reference graph G_ref, and the embedding algorithm in Section 4.1 explicitly minimizes this exact distance during construction (node mapping, edge completion, and edge rearrangement all target degree-sequence closeness to G_ref). The reported 73.5% improvement in topological rationality over baselines is therefore partly by construction: the metric is the optimization objective of the proposed method but not of the compared baselines. To make the claim meaningful, the paper should report additional structural fidelity metrics that the algorithm does not directly optimize (e.g., clustering coefficient, diameter, joint degree distribution, or spectral properties), or explicitly frame the 73.5% as 'degree-sequence agreement with a chosen reference.'
minor comments (6)
- [§6.2] The configuration similarity metric computes, for each fake configuration, the maximum similarity to any real configuration and then averages these maxima. Since fake configurations are generated by selecting a real router as a template, this metric is favorable by construction; reporting the average similarity over real configurations (or a leave-one-out baseline) would give a less biased view of style fidelity.
- [Definition 3.3] The definition of 'K-S distance between degree sequences' should specify that it is the Kolmogorov–Smirnov statistic between the empirical cumulative distribution functions of the two degree sequences, and how ties or differing sequence lengths are handled.
- [Algorithm 1] Line 19 of Algorithm 1 contains a typo: 'create G_emb with all all edges of G' should read 'all edges of G.'
- [§8] The discussion of differential privacy refers to the 'post-processing immunity theorem'; the standard name is the post-processing property of differential privacy. The argument is correct in substance, but the terminology should be aligned with the literature.
- [References] Reference [23], the Netconan anonymizer, lists the URL as https://internet2.edu/; this appears to be an incorrect URL for the Netconan tool and should be corrected.
- [§6.1] The RMSE values for node-addition accuracy (4.31 for embedding, 7.20 for replica) are reported without describing how the target set was chosen or whether the differences are statistically significant; a brief clarification of the RMSE computation would improve reproducibility.
Circularity Check
Topology-rationality metric is the embedding objective, and the k-DMA threat model gives the attacker the very scale it claims to hide.
-
self definitional
[Definition 3.3; §4.1 'Our Approach: Embedding' MaxSMT soft constraint; §6.3 evaluation]
"The degree-sequence-based topology rationality is defined as the Kolmogorov–Smirnov (K-S) distance between the degree sequences of bG and Gref. ... To minimize the difference between the degree sequence of G_anonym and that of G_ref, we add the following soft constraints to the MaxSMT formulation: min Σ_r |degExpr(r) − eDeg(r)|."
The headline 73.5% topological-rationality improvement is measured with the K-S distance to G_ref, which is exactly the objective the embedding construction minimizes (via greedy edge rearrangement and MaxSMT soft constraints). Low K-S distance to the reference is therefore guaranteed by construction rather than being an independent test of realism. Some independent content remains because Sample-Connect and Replica do not optimize this objective, so the circularity is partial rather than total.
-
self definitional
[§3.1 Definitions 3.1–3.2; §2.3 and 'Idea 2' in §3]
"k-degree mapping anonymity assumes attackers know only the original degree sequence. ... Order the nodes in G in descending order as v1,v2,...,vn with deg(v1)≥deg(v2)≥···≥deg(vn)."
A degree sequence is a list of length n = |V|, so an attacker who 'knows only the original degree sequence' knows the original router count exactly. The central goal is to obfuscate true scale, yet the formal privacy definition supplies the true scale as adversary background knowledge. k-DMA only makes node degrees k-indistinguishable; it places no constraint on the number of real routers. Thus the claimed scale-concealment guarantee reduces to an assumption that the secret is already known, and the k-DMA experiments cannot support the abstract's scale-concealment claim.
full rationale
Two load-bearing definitional steps make parts of NetCloak's evaluation self-scoring. First, topology rationality (Definition 3.3) is defined as K-S distance to the reference graph, and the embedding algorithm explicitly minimizes that same distance; the 73.5% rationality improvement is therefore largely a check that the optimizer reached its objective, though the comparison with Sample-Connect keeps some independent content. Second, the stated adversary for k-DMA knows only the original degree sequence, but that sequence has |V| entries, so the adversary already knows the original router count; the central 'conceals network scale' claim is thus assumed rather than derived. The configuration-similarity and route-repair evaluations are not circular: mimicry genuinely copies real config styles and the SMT-vs-iterative comparison is empirical, and the self-citations to ConfMask are normal engineering reuse rather than load-bearing external authority. Overall, the paper contains real system contributions, but the headline privacy and rationality claims are partly fixed by definition, so score 6.
Assumptions & free parameters
free parameters (2)
- Anonymity levels k_R and k_H =
2 or 4 in experiments (user-specified)
- Configuration similarity weights w_stanza, w_cmd, w_order =
0.2, 0.5, 0.3
assumptions (6)
- domain assumption The selected reference topology is representative of realistic networks at the target scale.
- domain assumption Topological rationality is adequately captured by the K-S distance of degree sequences.
- domain assumption Attacker knowledge is limited to the original degree sequence.
- domain assumption Strong functional equivalence from ConfMask is a correct standard for anonymized configurations.
- domain assumption The SMT shortest-path encodings correctly model OSPF primary and ECMP routes.
- domain assumption Randomized OSPF costs in [1,20] are representative of real heterogeneous cost settings.
invented entities (1)
-
Synthetic routers and hosts injected by NetCloak
Cite this review
Pith. "Pith review of NetCloak: Dynamic Topology Expansion for Secure and Scalable Configuration Sharing." pith.science (2026). https://pith.science/paper/ODMLCARE
@misc{pith2026250414959,
author = {Pith},
title = {Pith review of: NetCloak: Dynamic Topology Expansion for Secure and Scalable Configuration Sharing},
year = {2026},
howpublished = {\url{https://pith.science/paper/ODMLCARE}},
note = {Machine review of arXiv:2504.14959}
}
read the original abstract
As modern networks continue to grow in both scale and complexity, sharing real-world device configurations poses significant privacy risks, especially when adversaries can infer organizational size or resource distribution from topology data. We present NetCloak, a configuration anonymization framework that adaptively injects synthetic routers and hosts into the network graph to obfuscate true scale, while preserving end-to-end forwarding behavior. NetCloak core techniques include: (1) a graph-embedding expansion algorithm that integrates the original topology into a larger reference graph, ensuring added nodes blend seamlessly with real ones; (2) a k-degree mapping anonymity scheme that selectively adds minimal links to guarantee each original node degree is indistinguishable among at least k peers; (3) a mimicry-driven configuration generator that derives command templates from existing devices, preserving command ordering, naming conventions, and routing policies; and (4) a layered repair process combining SMT-based intra-AS route synthesis with iterative inter-AS filter insertion to restore protocol-correct routing under OSPF and BGP. Extensive experiments on real and emulated campus and data-center topologies demonstrate that NetCloak effectively conceals network size, improving topological rationality by over 70% and configuration fidelity by nearly 30% compared to baseline methods, while reducing route-repair overhead by more than 50% under randomized link costs. NetCloak thus enables safe, privacy-preserving configuration sharing at scale.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[1]
[n. d.]. The Internet2 Project. ([n. d.]). https://internet2.edu/ https://internet2.edu/
-
[2]
Cisco BGP question about advertising routes
2011. Cisco BGP question about advertising routes. https://serverfault. com/questions/257000/cisco-bgp-question-about-advertising-routes
work page 2011
-
[3]
Anubhavnidhi Abhashkumar, Aaron Gember-Jacobson, and Aditya Akella. 2020. Tiramisu: Fast Multilayer Network Verification. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20) . USENIX Association, Santa Clara, CA, 201–219. https: //www.usenix.org/conference/nsdi20/presentation/abhashkumar
work page 2020
-
[4]
Ryan Beckett, Aarti Gupta, Ratul Mahajan, and David Walker. 2017. A General Approach to Network Configuration Verification. In Pro- ceedings of the Conference of the ACM Special Interest Group on Data Communication (Los Angeles, CA, USA) (SIGCOMM ’17) . Associa- tion for Computing Machinery, New York, NY, USA, 155–168. https: //doi.org/10.1145/3098822.3098834
arXiv 2017
-
[5]
Ryan Beckett, Ratul Mahajan, Todd Millstein, Jitendra Padhye, and David Walker. 2016. Don’t Mind the Gap: Bridging Network-wide Objectives and Device-level Configurations. In Proceedings of the 2016 ACM SIGCOMM Conference (Florianopolis, Brazil) (SIGCOMM ’16) . Association for Computing Machinery, New York, NY, USA, 328–341. https://doi.org/10.1145/293487...
arXiv 2016
-
[6]
Ryan Beckett, Ratul Mahajan, Todd Millstein, Jitendra Padhye, and David Walker. 2017. Network configuration synthesis with abstract topologies. In Proceedings of the 38th ACM SIGPLAN Conference on Programming Language Design and Implementation . ACM, Barcelona Spain, 437–451. https://doi.org/10.1145/3062341.3062367
arXiv 2017
-
[7]
Rudiger Birkner, Dana Drachsler-Cohen, Laurent Vanbever, and Mar- tin Vechev. 2020. Config2Spec: Mining Network Specifications from Network Configurations. In 17th USENIX Symposium on Networked Systems Design and Implementation (NSDI 20) . USENIX Association, Santa Clara, CA, 969–984. https://www.usenix.org/conference/nsdi20/ presentation/birkner
work page 2020
-
[8]
James Cheng, Ada Wai-chee Fu, and Jia Liu. 2010. K-isomorphism: privacy preserving network publication against structural attacks. In Proceedings of the 2010 ACM SIGMOD International Conference on Management of Data (Indianapolis, Indiana, USA) (SIGMOD ’10). As- sociation for Computing Machinery, New York, NY, USA, 459–470. https://doi.org/10.1145/1807167.1807218
arXiv 2010
Show all 54 references
-
[9]
Cisco Systems, Inc. 2023. Examine Border Gateway Protocol Case Stud- ies. https://www.cisco.com/c/en/us/support/docs/ip/border-gateway- protocol-bgp/26634-bgp-toc.html Accessed: 2025-01-29
2023
-
[10]
Wei-Yen Day, Ninghui Li, and Min Lyu. 2016. Publishing Graph De- gree Distribution with Node Differential Privacy. In Proceedings of the 2016 International Conference on Management of Data (San Francisco, California, USA) (SIGMOD ’16). Association for Computing Machinery, New ...
2016
-
[11]
Christian Doerr and Norbert Blenn. 2013. Metric convergence in so- cial network sampling. In Proceedings of the 5th ACM Workshop on HotPlanet (Hong Kong, China) (HotPlanet ’13). Association for Com- puting Machinery, New York, NY, USA, 45–50. https://doi.org/10. 1145/2491159.2491168
2013
-
[12]
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating Noise to Sensitivity in Private Data Analysis. In Theory of Cryptography , Shai Halevi and Tal Rabin (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 265–284
2006
-
[13]
Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, and Martin Vechev. 2017. Network-Wide Configuration Synthesis. In Proceedings of the 29th International Conference on Computer Aided Verification (CA V ’17). Springer
2017
-
[14]
Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, and Martin Vechev. 2018. NetComplete: Practical Network-Wide Configuration Synthesis with Autocompletion. In 15th USENIX Symposium on Net- worked Systems Design and Implementation (NSDI 18) . USENIX Asso- ciation, Renton, WA, ...
2018
-
[15]
Ari Fogel, Stanley Fung, Luis Pedrosa, Meg Walraed-Sullivan, Ramesh Govindan, Ratul Mahajan, and Todd Millstein. 2015. A General Ap- proach to Network Configuration Analysis. In 12th USENIX Sympo- sium on Networked Systems Design and Implementation (NSDI 15) . USENIX Associati...
2015
-
[16]
Damien Garros. 2020. The State of Network Operation Through Au- tomation / NetDevOps Survey 2019. https://blog.networktocode.com/ post/state-network-operations-netdevops-survey-2019/
2020
-
[17]
Aaron Gember-Jacobson, Aditya Akella, Ratul Mahajan, and Hongqiang Harry Liu. 2017. Automatically Repairing Network Control Planes Using an Abstract Representation. In Proceedings of the 26th Symposium on Operating Systems Principles . ACM, Shanghai China, 359–373. https://doi...
2017
-
[18]
Aaron Gember-Jacobson, Raajay Viswanathan, Aditya Akella, and Ratul Mahajan. 2016. Fast Control Plane Analysis Using an Abstract Representation. In Proceedings of the 2016 ACM SIGCOMM Conference (Florianopolis, Brazil) (SIGCOMM ’16) . Association for Computing Machinery, New Y...
2016
-
[19]
Minas Gjoka, Maciej Kurant, and Athina Markopoulou. 2013. 2.5K- graphs: From sampling to generation. In 2013 Proceedings IEEE INFO- COM. 1968–1976. https://doi.org/10.1109/INFCOM.2013.6566997
2013
-
[20]
Minas Gjoka, Bálint Tillman, and Athina Markopoulou. 2015. Construc- tion of simple graphs with a target joint degree matrix and beyond. In 2015 IEEE Conference on Computer Communications (INFOCOM) . 1553–1561. https://doi.org/10.1109/INFOCOM.2015.7218534
2015
-
[21]
Leo A. Goodman. 1961. Snowball Sampling. The Annals of Mathemati- cal Statistics 32, 1 (1961), 148–170. http://www.jstor.org/stable/2237615
1961
-
[22]
Gao Han, Hanyang Shao, Ruiqin Duan, Changqi Zhuang, and Qiao Xiang. 2024. ConfigHub: A Network Configuration Sharing Platform. In Proceedings of the 2024 SIGCOMM Workshop on Formal Methods Aided Network Operation (Sydney, NSW, Australia)(FMANO ’24). Association for Computing M...
2024
-
[23]
Intentionet. 2023. Netconan - A Network Configuration Anonymizer. (April 2023). v https://internet2.edu/
2023
-
[24]
Xun Jian, Yue Wang, and Lei Chen. 2023. Publishing Graphs Under Node Differential Privacy. IEEE Transactions on Knowledge and Data Engineering 35, 4 (2023), 4164–4177. https://doi.org/10.1109/TKDE. 2021.3128946 13
2023
-
[25]
Zach Jorgensen, Ting Yu, and Graham Cormode. 2016. Publish- ing Attributed Social Graphs with Formal Privacy Guarantees. In Proceedings of the 2016 International Conference on Management of Data (San Francisco, California, USA) (SIGMOD ’16) . Association for Computing Machiner...
2016
-
[26]
Brighten Godfrey
Ahmed Khurshid, Wenxuan Zhou, Matthew Caesar, and P. Brighten Godfrey. 2012. VeriFlow: Verifying Network-Wide Invariants in Real Time. In Proceedings of the First Workshop on Hot Topics in Software Defined Networks (HotSDN ’12) . ACM Press, Helsinki, Finland, 49. https://doi.o...
2012
-
[27]
Chul-Ho Lee, Xin Xu, and Do Young Eun. 2012. Beyond random walk and metropolis-hastings samplers: why you should not backtrack for unbiased graph sampling. In Proceedings of the 12th ACM SIGMET- RICS/PERFORMANCE Joint International Conference on Measurement and Modeling of Com...
2012
-
[28]
Jure Leskovec and Christos Faloutsos. 2006. Sampling from large graphs. In Proceedings of the 12th ACM SIGKDD International Confer- ence on Knowledge Discovery and Data Mining (Philadelphia, PA, USA) (KDD ’06). Association for Computing Machinery, New York, NY, USA, 631–636. h...
2006
-
[29]
Jure Leskovec, Jon Kleinberg, and Christos Faloutsos. 2005. Graphs over time: densification laws, shrinking diameters and possible ex- planations. In Proceedings of the Eleventh ACM SIGKDD International Conference on Knowledge Discovery in Data Mining (Chicago, Illinois, USA) ...
2005
-
[30]
Rong-Hua Li, Jeffrey Xu Yu, Lu Qin, Rui Mao, and Tan Jin. 2015. On random walk based graph sampling. In 2015 IEEE 31st International Conference on Data Engineering . 927–938. https://doi.org/10.1109/ ICDE.2015.7113345
2015
-
[31]
Kun Liu and Evimaria Terzi. 2008. Towards identity anonymization on graphs. In Proceedings of the 2008 ACM SIGMOD International Con- ference on Management of Data (Vancouver, Canada) (SIGMOD ’08). Association for Computing Machinery, New York, NY, USA, 93–106. https://doi.org/...
2008
-
[32]
Xu Liu, Peng Zhang, Anubhavnidhi Abhashkumar, Jiawei Chen, and Weirong Jiang. 2024. Automatic Configuration Repair. In Proceedings of the 23rd ACM Workshop on Hot Topics in Networks . ACM, Irvine CA USA, 213–220. https://doi.org/10.1145/3696348.3696895
2024
-
[33]
Xuesong Lu, Yi Song, and Stéphane Bressan. 2012. Fast Identity Ano- nymization on Graphs. In Database and Expert Systems Applications , Stephen W. Liddle, Klaus-Dieter Schewe, A. Min Tjoa, and Xiaofang Zhou (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 281–295
2012
-
[34]
Priya Mahadevan, Calvin Hubble, Dmitri Krioukov, Bradley Huf- faker, and Amin Vahdat. 2007. Orbis: rescaling degree correlations to generate annotated internet topologies. In Proceedings of the 2007 Conference on Applications, Technologies, Architectures, and Protocols for Com...
2007
-
[35]
Priya Mahadevan, Dmitri Krioukov, Kevin Fall, and Amin Vahdat. 2006. Systematic topology analysis and generation using degree correlations. In Proceedings of the 2006 Conference on Applications, Technologies, Architectures, and Protocols for Computer Communications (Pisa, Ital...
2006
-
[36]
Maltz, Jibin Zhan, Geoffrey Xie, Hui Zhang, Gísli Hjálmtýsson, Albert Greenberg, and Jennifer Rexford
David A. Maltz, Jibin Zhan, Geoffrey Xie, Hui Zhang, Gísli Hjálmtýsson, Albert Greenberg, and Jennifer Rexford. 2004. Structure preserving anonymization of router configuration data. In Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement (Taormina, Sicily, It...
2004
-
[37]
Rosenbluth, Marshall N
Nicholas Metropolis, Arianna W. Rosenbluth, Marshall N. Rosen- bluth, Augusta H. Teller, and Edward Teller. 1953. Equation of State Calculations by Fast Computing Machines. The Jour- nal of Chemical Physics 21, 6 (06 1953), 1087–1092. https:// doi.org/10.1063/1.1699114 arXiv:h...
1953 doi
-
[38]
Greg Minshall. 1997. TCPdpriv. (1997). https://ita.ee.lbl. gov/html/contrib/tcpdpriv.html https://ita.ee.lbl.gov/ html/con- trib/tcpdpriv.html
1997
-
[39]
Jason C. Neumann. 2015. The Book of GNS3: Build Virtual Network Labs using Cisco, Juniper, and More . No Starch Press
2015
-
[40]
Sivaramakrishnan Ramanathan, Zhaodong Wang, Sangki Yun, Ying Zhang, Mohab Gawish, Eric Lippert, Walid Taha, Jelena Mirkovic, Yogesh Mundada, and Minlan Yu. 2023. Practical Intent-driven Routing Configuration Synthesis
2023
-
[41]
Alessandra Sala, Xiaohan Zhao, Christo Wilson, Haitao Zheng, and Ben Y. Zhao. 2011. Sharing graphs using differentially private graph models. In Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference (Berlin, Germany) (IMC ’11) . As- sociation for Co...
2011
-
[42]
Joseph Severini, Radhika Niranjan Mysore, Vyas Sekar, Sujata Baner- jee, and Michael K. Reiter. 2021. The Netivus Manifesto: making collaborative network management easier for the rest of us. SIG- COMM Comput. Commun. Rev. 51, 2 (May 2021), 10–17. https: //doi.org/10.1145/3464...
2021
-
[43]
Adam Slagell, Jun Wang, and William Yurcik. 2004. Network Log Anonymization: Application of Crypto-Pan to Cisco Netflows. In Pro- ceedings of the Workshop on Secure Knowledge Management 2004
2004
-
[44]
Nazanin Takbiri, Xiaozhe Shao, Lixin Gao, and Hossein Pishro-Nik
-
[45]
Eli Upfal. 2005. Probability and computing: randomized algorithms and probabilistic analysis. Cambridge university press
2005
-
[46]
Yuejie Wang, Qiutong Men, Yao Xiao, Yongting Chen, and Guyue Liu. 2024. ConfMask: Enabling Privacy-Preserving Configuration Sharing via Anonymization. In Proceedings of the ACM SIGCOMM 2024 Conference (Sydney, NSW, Australia)(ACM SIGCOMM ’24). Association for Computing Machine...
2024
-
[47]
Ammar, and Sue B
Jun Xu, Jinliang Fan, Mostafa H. Ammar, and Sue B. Moon. 2002. Prefix-Preserving IP Address Anonymization: Measurement-Based Security Evaluation and a New Cryptography-Based Scheme. In 10th IEEE International Conference on Network Protocols, 2002. Proceedings. IEEE Comput. Soc...
2002 arXiv
-
[48]
Rulan Yang, Xing Fang, Lizhao You, Qiao Xiang, Hanyang Shao, Gao Han, Ziyi Wang, Zhihao Zhang, Jiwu Shu, and Linghe Kong. 2023. Diag- nosing Distributed Routing Configurations Using Sequential Program Analysis. In Proceedings of the 7th Asia-Pacific Workshop on Network- ing. A...
2023 doi
-
[49]
Fangdan Ye, Da Yu, Ennan Zhai, Hongqiang Harry Liu, Bingchuan Tian, Qiaobo Ye, Chunsheng Wang, Xin Wu, Tianchen Guo, Cheng Jin, Duncheng She, Qing Ma, Biao Cheng, Hui Xu, Ming Zhang, Zhiliang Wang, and Rodrigo Fonseca. 2020. Accuracy, Scalability, Coverage: A Practical Configu...
2020
-
[50]
Peng Zhang, Aaron Gember-Jacobson, Yueshang Zuo, Yuhao Huang, Xu Liu, and Hao Li. 2022. Differential Network Analysis. 601–
2022
-
[51]
Bin Zhou and Jian Pei. 2008. Preserving Privacy in Social Networks Against Neighborhood Attacks. In 2008 IEEE 24th International Confer- ence on Data Engineering . 506–515. https://doi.org/10.1109/ICDE.2008. 4497459
2008 doi
-
[52]
Tamer Özsu
Lei Zou, Lei Chen, and M. Tamer Özsu. 2009. k-automorphism: a general framework for privacy preserving network publication. Proc. VLDB Endow. 2, 1 (Aug. 2009), 946–957. https://doi.org/10.14778/ 1687627.1687734 15
2009
-
[615]
https://www.usenix.org/conference/nsdi22/presentation/zhang- peng
-
[2019]
In 2019 57th Annual Allerton Conference on Communication, Control, and Com- puting (Allerton)
Improving Privacy in Graphs Through Node Addition. In 2019 57th Annual Allerton Conference on Communication, Control, and Com- puting (Allerton). 487–494. https://doi.org/10.1109/ALLERTON.2019. 8919967
2019 doi
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.