Research

Modern networks increasingly span organizational, technological, and physical boundaries. Traffic may traverse multiple providers and submarine infrastructure before reaching its destination. Network functions that once ran entirely in software increasingly execute across programmable packet and optical systems, while satellite and quantum networks introduce new physical and operational constraints.

These systems are difficult to observe as a whole, and failures often cross the abstractions used to manage them. A physical hazard may remove apparently independent logical paths; an attack may create a bottleneck at another layer; a change inside one infrastructure may alter behavior observed somewhere else.

My work therefore asks three related questions: what parts of networked infrastructure remain hidden, how can we explain their behavior from incomplete evidence, and how should that understanding change the systems we build?

Reveal hidden infrastructure

Measure what the network does not expose.

Logical Internet measurements expose only part of the system. Important properties may live in physical infrastructure, topology, shared conduits, submarine cables, private backbones, or other hidden dependencies.

This work combines multiple forms of evidence to recover missing structure. The goal is not mapping for its own sake; it is exposing dependencies that matter for performance, security, and resilience.

Explain network behavior

Turn partial observations into explanations.

A network operator rarely has one authoritative source of truth. Traffic, BGP, DNS, telemetry, active measurements, logs, topology, and infrastructure metadata each expose different parts of the system.

The research question is how these observations can be connected well enough to determine what changed, why it changed, which evidence supports the explanation, which alternatives remain plausible, what additional measurement would reduce uncertainty, and what action should follow.

This direction grows naturally out of earlier work in measurement, telemetry, and network data analysis. AI appears here as a mechanism for reasoning over heterogeneous network evidence while preserving provenance, uncertainty, network semantics, and competing explanations.

Weak supervision and network data science

This line develops ways to learn from network data when high-quality labels are scarce, noisy, expensive, or distributed across organizations, extending from weak-supervision techniques to hybrid explainability for ML-powered networking systems.

Engineer resilient infrastructure

Design around the dependencies that measurement reveals.

Resilience often fails because different network layers hide dependencies from one another: logical paths may share physical infrastructure, DDoS defenses may sit downstream of the real bottleneck, and communication systems may depend on infrastructure exposed to the same hazards they are expected to survive.

The contribution is to identify a hidden dependency or constraint, expose it through measurement or modeling, and redesign the system around it.

Programmable security and packet-optical systems

This work studies defenses shaped by switch memory, link capacity, optical topology, and where attacks create bottlenecks.

Infrastructure under stress

This work examines what happens when the physical environment becomes part of the network failure model, from sea-level rise and climate exposure to Cascadia-scale earthquakes, wildfire monitoring, and multi-hazard satellite resilience.

Emerging infrastructure

The Argus project explores measurement and management techniques for multi-cloud networks, while satellite and quantum-classical work studies systems whose dependencies and control planes change over time.

Funded Projects

Securing campus CI and REN workflows

NSF CICI · 2026–2029

NSF award →

Measurement-informed multi-cloud management

NSF CAREER · 2022–2027

NSF award →

Cross-boundary monitoring for hazard infrastructure

NSF CICI · 2023–2026

NSF award →

Distributed data-plane runtime telemetry

NSF CNS · 2022–2026

NSF award →

Programmable defenses for terabit DDoS

NSF SaTC · 2022–2025

NSF award →

Democratizing Internet data science

NSF OAC · 2021–2025

NSF award →

Climate-change risk and Internet infrastructure resilience

Internet Society Foundation · 2021–2025

Project record →

Weak supervision for network telemetry

NSF CRII · 2019–2022

NSF award →

Future Direction

Networks have become remarkably programmable, but they remain surprisingly difficult to understand. I see an opportunity to bring together Internet measurement, network data science, programmable systems, resilience, and AI to build network infrastructure that can reason about its own state and dependencies.

This requires more than placing an AI interface in front of existing management tools. An intelligent network must be able to distinguish observations from inference, connect evidence across layers and datasets, represent uncertainty, explain why competing hypotheses differ, and determine what additional information is required before an action is safe.

The long-term objective is networked infrastructure that is not only programmable, but observable, explainable, adaptive, and resilient by construction.

Interested in working on these problems? See information for prospective students