Summary

  • Nick Feamster is a University of Chicago professor, measurement researcher, institution builder and NetMicroscope co-founder focused on making hidden Internet behaviour usable for accountable decisions.
  • His rcc work reported more than 1,000 previously undetected faults across 17 autonomous systems; the Routing Control Platform helped establish a network-wide control model later associated with SDN.
  • Projects on spam, broadband, censorship and smart homes also exposed measurement limits: reputation can misclassify, remote probes can create risk and encrypted metadata can reveal behaviour.
  • His current machine-learning work asks whether conclusions can be efficient, auditable and safe in production; his contribution is collaborative systems that preserve uncertainty rather than erase it.

Rcc: checking the combined configuration before deployment

The 2005 paper Detecting BGP Configuration Faults with Static Analysis, co-authored with Hari Balakrishnan, presented a router configuration checker known as rcc. It organised persistent faults into two broad classes. Route-validity faults occur when the control plane selects a route that does not correspond to a usable data-plane path. Path-visibility faults occur when a usable path exists but the routers that require it do not learn it. The categories tied configuration commands to consequences an operator could recognise.

rcc parsed configurations from multiple routers and checked network-wide constraints. The paper reported analysis of 17 autonomous systems, more than 1,000 previously undetected faults and more than 65 operator downloads. Those figures are historical and author-reported. They do not show that rcc became a universal industry product, and the supplied evidence does not establish how many networks continued to use it. They do establish that the project was built against real configurations and reached operators outside the authors’ laboratory.

The operational importance lies in the kind of evidence produced. A checker can point to a configuration relationship that violates an invariant before an outage. That is different from a dashboard reporting packet loss after a service has degraded. It gives an engineer a reasoned connection between a rule and a class of failure. The output can support review, testing and discussion among teams that otherwise hold only local views.

The limits are equally instructive. rcc could test only the properties encoded by its designers and supported by its parser. It could not know an undocumented business intention. It could not guarantee the absence of vendor defects or physical failure. It could not turn a clean configuration into proof that the network would never experience a transient problem. A network can pass every check that has been written and still violate a requirement nobody expressed.

That is why rcc belongs at the beginning of the larger profile. It established both the ambition and the restraint that recur later. The ambition was to make infrastructure behaviour computable before harm. The restraint was that correctness is always relative to observed inputs and stated properties. Modern AI systems for network operations face the same test, except that the boundary can be harder to see when a model produces fluent explanations rather than explicit invariants.

The Internet usually knows what it did, but cannot explain why

A packet reaches a destination or fails to do so. A video call stalls. A domain returns an unexpected address. A mail server rejects a connection. A smart speaker contacts a remote service at a revealing moment. Each event leaves traces, but the Internet has no central ledger that can give one authoritative explanation. Its behaviour emerges from independently operated networks, vendor-specific configurations, private interconnection agreements, home equipment, application design and changing user demand.

That structure is useful because it prevents one operator from controlling the whole system. It also makes diagnosis hard. A router can show its own routes without explaining every consequence of the combined routing policy. A speed test can measure one transfer without isolating Wi-Fi, access capacity, latency, interconnection and application effects. A censorship probe can observe a failed request without identifying the person or institution responsible. A traffic classifier can attach a label without proving that the label will remain accurate after the network changes.

Feamster’s research record can be read as a series of attempts to narrow those gaps. The technologies vary, but the operating method is recognisable. First, choose a hidden behaviour that matters. Second, find a vantage point from which the behaviour leaves a measurable signal. Third, build a representation that turns the signal into a question an operator, policymaker or user can ask. Fourth, test where the representation fails. The final step is essential because a system that produces a confident answer without exposing its limits can make infrastructure less accountable rather than more so.

This makes Feamster a digital-infrastructure subject even though he does not own fibre, run a public autonomous system or operate a hyperscale cloud. His work sits in the information layer around those assets. It influences how routes are checked, how abuse is identified, how broadband quality is described, how censorship is documented and how statistical models enter network operations. Routers and cables move the traffic; measurement and analysis determine whether anyone can explain what they are doing.

The strongest account of that career is therefore not a sequence of awards or a claim that one researcher invented several fields. It is the history of an observability programme that kept changing its object while preserving the same discipline: distinguish what was directly observed from what was inferred, and distinguish an experimental result from an operational guarantee.

One career, several institutional identities

At the research cutoff on 3 August 2026, the University of Chicago identified Feamster as Neubauer Professor of Computer Science and Faculty Director of Research at the Data Science Institute. His own current page also listed him as director of the Network Operations and Internet Security Lab, co-director of the Internet Innovation Initiative, co-lead of netml.io and co-director of the AI and Policy Pillar. A September 2024 Data Science Institute post used the title Director of Technology Policy. These descriptions can coexist because university roles overlap and evolve, but they should not be compressed into one permanent job title.

The institutional distinctions matter. As a professor, he researches and teaches. Through the NOISE Lab and netml.io, he works with students and collaborators on routing, measurement, privacy and machine learning. Through Internet Innovation and Internet Equity projects, he helps build evidence for public and infrastructure decisions. As a NetMicroscope co-founder and chief executive, he participates in a private company seeking to commercialise network-quality analysis. His biography also says he works as an expert witness in technology litigation. None of these roles automatically confers the authority of another.

A professor is not a regulator; a startup chief executive does not turn university research into a customer endorsement; an expert opinion is not a court finding.

That separation is consistent with the substance of the research. Feamster’s best work asks which system holds which piece of evidence and what conclusion that evidence can support. The same care is necessary when describing him. His current biography credits him with writing LookSmart’s first web crawler and helping design Damballa’s first botnet-detection algorithm. Those are useful, attributable facts about early industry work. They do not establish exact employment dates, sole authorship, ownership stakes or a complete product history.

The public record is much richer about professional work than personal life. It does not reliably establish his date or place of birth, citizenship, family background, compensation, NetMicroscope equity, personal investments or wealth. A profile grounded in the available evidence should not turn those absences into guesses. The career is sufficiently substantial without decorating it with a conventional celebrity biography the sources cannot support.

MIT, a web crawler and a thesis about failure before failure

Feamster remained at the Massachusetts Institute of Technology from undergraduate study through the doctorate. He completed an SB in electrical engineering and computer science in 2000, an MEng in the same field in 2001, and a PhD in computer science in 2005 under Hari Balakrishnan. The thesis title—Proactive Techniques for Correct and Predictable Internet Routing—states the early programme plainly. Instead of waiting for a routing fault to cause an outage and then reconstructing the cause, the network should expose enough structure to check important properties before deployment.

His early work at LookSmart offers a useful, limited prelude. A web crawler must discover a large graph that changes while it is being observed. It encounters broken links, duplicate pages, inconsistent responses and unreachable regions. The crawler did not directly become the later routing systems, and the sources do not support such a claim. The relevant continuity is methodological: a distributed system is not visible from one local view, so useful knowledge requires systematic collection and an explicit representation of what has been found.

The Damballa relationship added an adversarial version of the same problem. Botnets were designed to obscure their membership and control. Feamster’s official biography says he helped design the company’s first botnet-detection algorithm. The public evidence does not reconstruct the complete corporate team or show how later products used that work. It does show that his early career crossed between academic systems research and an operational security company that needed to infer malicious coordination from network traces.

The PhD research was formed in an environment where interdomain routing policies were distributed across devices and organisations. Operators configured routers with commands that expressed peering, customer relationships, export rules, backup paths and traffic-engineering preferences. Each configuration could look reasonable in isolation while the combined network hid a loop, a black hole or an unintended route. The problem was not simply a faulty protocol implementation. It was the difficulty of reasoning about a distributed program assembled from many local policies.

That framing became a durable signature. Feamster often treated the operational system around an algorithm as the real unit of research. The unit included configuration files, measurement vantage points, data pipelines, interfaces, operator incentives and institutional constraints. This broadened the work beyond a single theorem or classifier. It also created a larger responsibility: once a system touches real operators, households or people living under censorship, deployment and ethics become part of technical quality.

BGP configuration as a distributed program

The Border Gateway Protocol allows autonomous systems to exchange reachability while retaining control over business and routing policy. That autonomy is one reason the Internet can join networks with different owners and objectives. It also means that the global result is not designed by one engineer. Policies are composed indirectly through advertisements, preferences, filtering and the internal distribution of routes.

Inside an autonomous system, the problem can still be large. A network may have hundreds of routers and several ways to distribute external routes internally. A route learned at one edge must become visible where it is needed, but not necessarily everywhere. Export policy must prevent customer or peer routes from leaking to the wrong neighbour. Backup routes should appear when the primary path fails without creating loops or persistent oscillation. The operator knows the business intent, but the devices hold the executable fragments.

Feamster’s early routing work treated those fragments as a program that could be analysed. This was a practical change in perspective. A router configuration was no longer only text to be reviewed line by line. It became input to a network-wide computation. Correctness could be expressed as invariants: a chosen route should lead to a usable forwarding path; a usable path should be visible to the routers that need it; export policy should preserve the intended relationships; internal route distribution should not create a persistent inconsistency.

The analogy to software analysis was productive because it changed the time of intervention. Traditional troubleshooting begins after a symptom. Static analysis asks whether a known class of failure is already encoded in the configuration. It does not need to inject traffic or wait for a customer to report an outage. For networks that carry critical services, moving a defect from the incident queue into the review queue can be more valuable than shortening the post-failure diagnosis.

The analogy also has a boundary. Network state includes more than configuration. It includes live routes, topology, vendor behaviour, transient convergence, hardware tables, faulty links and business knowledge that may never have been written down. A static checker can be exactly correct about the model it has and still miss a failure outside that model. Feamster’s later research repeatedly returned to this distinction between a useful representation and the whole operational world.

The Routing Control Platform moved decisions out of individual routers

rcc asked whether distributed configuration satisfied known constraints. The Routing Control Platform asked a different question: why should every router independently reconstruct the information needed to select routes? Traditional internal BGP designs distributed external routes through a full mesh or through route reflectors. A full mesh became unwieldy as networks grew. Route reflection improved scale but could hide routes, create unexpected choices and make the result harder to reason about.

The RCP paper proposed a logically centralised service that collected external BGP routes and internal topology, selected routes for individual routers and communicated those choices through ordinary iBGP. The forwarding devices did not disappear. They still forwarded packets and spoke a familiar protocol at the interface. What changed was the location of route-selection logic and the view available to that logic.

“Logically centralised” did not mean one fragile physical box. The control service could be replicated and distributed while presenting one coherent decision function. This distinction is central to later software-defined networking as well. A controller can act from a network-wide view without requiring every control process to run on one machine. The engineering problem becomes one of state consistency, failure recovery and safe interfaces rather than a choice between complete centralisation and complete distribution.

RCP also respected installed infrastructure. It did not require a new forwarding plane or an immediate replacement of every router. That deployment choice matters in networks whose equipment, contracts and operational procedures cannot be changed at once. A research architecture gains practical value when it can enter a live environment through an interface operators already understand.

The evaluation used real backbone information, but the supplied record does not establish a broad production census. The defensible claim is that RCP demonstrated a workable architecture and became influential, not that it replaced internal BGP throughout the industry. Its 2015 NSDI Test of Time Award supports enduring intellectual importance. It does not prove market adoption or give one paper ownership of every later controller design.

A major contribution to SDN, not a sole-inventor story

Software-defined networking is often retold as a clean break: control moved into software, forwarding became programmable, and a new era began. The actual history is less tidy. Active networks, network virtualisation, the 4D architecture, Ethane, RCP, OpenFlow, NOX and other projects addressed different pieces of programmability, control separation and network-wide management. Feamster was a substantial contributor to that lineage, but no evidence supports describing him as the sole inventor of SDN.

RCP contributed a clear architectural idea: route decisions could be computed by a control service with a wider view and delivered to existing forwarding devices. rcc contributed another: network policy could be checked against invariants. Together they helped move the operating question away from “what command is on this router?” and towards “what behaviour does the complete control system implement?” That shift is one of the intellectual foundations of programmable networking.

Feamster later co-authored The Road to SDN, which presented the field as an accumulation of ideas rather than a single moment of invention. This historical position is useful because it resists the founder mythology that often grows around infrastructure technologies. A field becomes possible when multiple research groups, operators, vendors and standards communities solve adjacent problems and make them deployable.

The 2017 agenda paper Why (and How) Networks Should Run Themselves, co-authored with Jennifer Rexford, extended the argument from controller architecture into continuous operation. It described closed loops in which high-level intent guides decisions, telemetry reveals outcomes and the system adapts. The title was deliberately provocative. It should not be read as evidence that engineers are no longer needed. A self-adjusting network still requires accurate objectives, trustworthy telemetry, safe actuation, constrained permissions and a way to stop when evidence is ambiguous.

That agenda now looks less like a distant automation vision and more like a design problem for AI-assisted operations. Language models can suggest configuration, summarise incidents and select tools. They can also invent causes, misunderstand policy or act with excessive authority. The earlier routing work supplies a demanding standard for the new systems: learned recommendations should be surrounded by explicit checks and observable consequences, not accepted because the explanation sounds plausible.

Spam made the network around the message more important than the message

At Georgia Tech, the object of observation changed from configuration errors to adversaries. Spam campaigns and botnets were built to move. Compromised machines appeared and disappeared, addresses changed, domains were replaced and control infrastructure was distributed. Content signatures could catch a known message, but the delivery system itself often revealed the more durable pattern.

The 2006 SIGCOMM paper Understanding the Network-Level Behavior of Spammers analysed more than ten million unwanted messages according to the paper record. It examined where senders appeared, how long they remained active and how spam related to address space and routing behaviour. The paper’s importance was not one permanent percentage. It showed that abuse could be studied as infrastructure: the sender population, the routes, the timing and the concentration of sources could reveal coordination that message text alone did not.

This approach offered a practical advantage. Network-level features can be available early in a connection, before a full message is accepted or inspected. That can reduce processing and allow a defender to act at scale. It can also preserve some payload privacy by relying on metadata. Yet the same abstraction creates risk. A residential prefix can contain innocent users and compromised devices. A shared host can serve both legitimate and malicious domains. An address can change hands. Infrastructure reputation is useful only when uncertainty, decay and appeal are part of the system.

The DNSBL counter-intelligence work used an adversary’s own defensive behaviour as a signal. Botmasters checked DNS-based blocklists to see whether their machines had been identified. Characteristic lookup patterns could therefore reveal likely bot membership. The idea was elegant because the attacker’s reconnaissance became evidence. It remained a heuristic. A lookup could have a benign cause, and a likely-bot list still required corroboration before disruptive action.

SNARE used spatiotemporal and network-level features available during an SMTP exchange to score senders. Its evaluation reported accuracy around 93 per cent at a low false-positive rate. That number belongs to the dataset, threat environment and threshold of the study. It is not a property that survives unchanged for seventeen years. Adversaries adapt, mail infrastructure consolidates and feature distributions move. The result is best understood as proof that early network signals could support a useful classifier, not as a permanent benchmark.

The dynamic DNS reputation system expanded the same logic from senders to domains. Registration patterns, name servers, address changes and resolution behaviour can make malicious infrastructure look different from a stable legitimate service. A classifier can use those differences to assign risk before every payload is known. The method foreshadowed later network machine learning: construct a representation from metadata, train a decision rule, then confront the operational consequences when the representation is incomplete.

Reputation is an operational decision, not an objective label

Behavioural clustering of HTTP-based malware pushed the method further. Instead of requiring an exact signature for each binary, the system grouped malware samples by communication behaviour and generated network signatures. That can remain useful when code changes but a command protocol, destination pattern or timing behaviour persists. It can also group unrelated traffic when the representation is too coarse.

The distinction between signal and verdict determines how the system should be used. A model may report that an address, domain or flow resembles known abuse. An operator must decide what happens next. A low-confidence result might trigger observation. A stronger result might rate-limit a connection. Blocking an entire prefix or domain can impose costs on innocent users. The technical design therefore includes the threshold, the age of the evidence, the scope of action and the route for correction.

Feamster’s early Damballa work and a patent assigned to Georgia Tech Research Corporation show a commercial and intellectual-property context for this research. The patent lists Feamster with David Dagon, Wenke Lee and other inventors on a method for detecting and responding to attacking networks. A patent establishes a formal record of inventorship and assignment. It does not establish sole creation, production use, licensing revenue or the validity of every claim in every jurisdiction.

The larger contribution was to make reputation an infrastructure problem rather than an abstract accuracy score. A defender needs a classifier that runs soon enough, at the available line rate, with data that can be lawfully collected and with errors that can be managed. A paper can optimise one part of that chain. A production system has to carry the whole chain for years while the adversary changes.

This is the bridge from the security work to Feamster’s current machine-learning programme. The later projects devote more explicit attention to feature cost, drift, privacy and deployment. The underlying question remains the same: when a network signal is converted into a decision, what evidence makes the decision reliable enough to affect real traffic?

Measuring broadband from the gateway changed the vantage point

Broadband complaints are simple to state and hard to diagnose. “The Internet is slow” can describe a constrained access link, poor Wi-Fi, a busy household device, a congested interconnection, a distant server, application delay or a test that cannot generate traffic fast enough. Measurements from a laptop inherit the laptop’s software and local network. Measurements in the provider core miss what the household sees.

The gateway-based approach placed controlled measurement at the boundary between the home and the Internet service provider. The 2011 SIGCOMM study used longitudinal data from nearly 4,000 gateway devices across eight ISPs, within a larger deployment above 4,200 devices. It examined throughput, latency, access technologies and traffic-shaping behaviour. The value of the gateway was analytical: it could observe the access service while avoiding some of the uncontrolled variation of an ordinary end host.

That vantage point still did not make the answer automatic. The home gateway shares a local environment with devices and Wi-Fi. A measurement server has its own path and capacity. Tests can interfere with household traffic or run at unrepresentative times. The method improved attribution; it did not create a perfect view of user experience.

BISmark turned the gateway method into a reusable testbed. The 2014 USENIX ATC paper described custom routers and a backend capable of deploying measurements and applications. At the paper’s date, the platform operated in hundreds of homes across about 30 countries and had been used by researchers at nine institutions. Those figures are time-bound, but they show work that extended beyond one dataset.

Maintaining a home testbed is infrastructure work of its own. Hardware has to be shipped and supported. Users unplug devices. Firmware ages. Clocks drift. Consent must remain understandable. Data schemas and collection pipelines have to survive changes in networks and applications. The published system is therefore evidence of institution building as well as measurement design.

The broadband programme also demonstrates why method matters to policy. A result from a controlled gateway is not interchangeable with a browser test, an ISP counter or an advertised service tier. Each measures a different slice of the path. Public decisions become more defensible when the measurement position and its limits are visible rather than hidden behind one headline speed.

Once access links became faster, speed stopped explaining experience

Early broadband policy often centred on whether a provider delivered the advertised rate. That question remains important, especially where access capacity is scarce. It becomes less explanatory once a connection is fast enough that latency, Wi-Fi, content delivery and application design dominate the experience.

A study across more than 5,000 broadband networks examined web-performance bottlenecks and found that raw access throughput was often no longer the sole limiting factor above a study-specific range. A faster subscription could fail to make a page feel faster if round-trip delay, object dependencies or server behaviour controlled completion time. The exact threshold should not be treated as universal. The durable point is that quality becomes multi-dimensional as the access link improves.

Reliability adds another dimension. A service can have a strong median speed and still fail households through short outages. A video call, examination or remote medical session may be disrupted by a brief loss that disappears from a monthly average. Longitudinal measurement is needed because one test cannot describe the frequency, duration and timing of failures.

Encrypted DNS research exposed a similar trade-off. Resolver and protocol choices can affect latency, privacy and reachability. In the measured panel, no one configuration was best for every user and network. A security or privacy improvement can carry performance costs in one environment and not another. The result argues against turning one benchmark into a universal prescription.

COVID-era measurements showed how quickly the operating environment can change. Participating ISPs experienced abrupt shifts in traffic and interconnection demand, followed by capacity additions and altered patterns of use. The findings were limited to the measured networks, yet they demonstrated why planning based only on stable historical averages can fail during a societal shock.

This is the point at which broadband measurement becomes quality-of-experience engineering. Operators need to connect low-level signals—throughput, latency, loss, outages and interconnection—to application outcomes such as video stalls and conferencing quality. That connection later became part of NetMicroscope’s product thesis. Academic results do not prove every company claim, but the technical lineage is direct.

Interconnection measurement turned a commercial dispute into a shared data problem

The path between a household and an application can cross several business boundaries. An access provider may exchange traffic directly with a content network, through an internet exchange, or through a transit provider. Congestion can occur at one link, in one direction and during one period. Public arguments about “the interconnection” can therefore combine several technically different conditions.

The Interconnection Measurement Project asked participating ISPs to install a common measurement tool at interconnection links. The project reported roughly 2,900 links and about 31 per cent utilisation at peak periods in June 2021, together with evidence of capacity additions. Those aggregate results do not prove that every user path was uncongested. A link average can hide a short spike, an individual route or a local failure. The value of the project was the effort to give several parties a common method and vocabulary.

A common measurement system can reduce one kind of disagreement while creating another. Participants must agree which links are included, how utilisation is sampled, how private data are protected and which summaries can be published. Providers may have commercial reasons to limit disclosure. Researchers need enough detail to test claims without exposing customer relationships or security-sensitive topology.

Feamster’s role in this work is best described as building measurement capacity and institutional collaboration. He did not regulate interconnection contracts or compel participation. The project illustrates how his research moved from an instrument deployed at a home gateway to an evidence system shared with operators. The technical task was inseparable from governance: useful data required cooperation from the organisations that controlled the links.

Internet equity broadened performance into access, affordability and reliability

A broadband line can exist in a neighbourhood while remaining unaffordable. A household can subscribe and receive unreliable service. A provider can meet an advertised rate while Wi-Fi, building wiring or device quality prevents an application from working well. Treating the digital divide as a single coverage map hides these distinctions.

The University of Chicago’s Internet Equity Initiative combines dimensions including accessibility, infrastructure, affordability, adoption, performance and reliability. Its portals and projects bring network measurements together with demographic and policy data. Household devices in Chicago supplied direct evidence about service performance, while public datasets allowed comparisons across places and populations.

The method can reveal patterns without explaining every cause. A neighbourhood difference may be associated with income, building type, provider competition, subscription tier, equipment or historical investment. A demographic overlay supports investigation; it does not prove why the difference exists. Policy work needs the same distinction Feamster’s routing work required: representation makes a question testable, but it does not substitute for the missing variables.

UChicago reported in 2025 that Internet Innovation collaboration contributed measurement and analytical work to Illinois broadband planning associated with 175,000 underserved homes, businesses and community-anchor locations. That is a material institutional claim. It involved the Illinois Broadband Lab, state officials and other partners. It should not be rewritten as though one professor personally connected 175,000 locations or as evidence that every planned build was already complete.

The progression from gateway tests to Internet equity shows how the intended user of measurement changed. An operator might use a gateway result to diagnose a line. A city might use a neighbourhood pattern to target support. A state might use validated data in a funding challenge. The measurement becomes more consequential as it enters public decisions, which increases the need for transparent definitions, versioned data and a clear account of what remains uncertain.

Censorship research made observability a question of human safety

Censorship is difficult to measure for the same structural reason routing is difficult to explain: the observer sees an outcome produced by several systems. A failed domain lookup may reflect state filtering, a local firewall, an ordinary DNS error, a server outage or routing instability. A reset connection may be injected, generated by an endpoint or caused by a middlebox unrelated to political control. The signal is rarely a signed statement of responsibility.

The stakes are different because a measurement can expose a person. Researchers seek vantage points inside censored networks, yet volunteers may face retaliation. Remote techniques can reduce the need to recruit local participants, but they may involve users, websites or systems that never agreed to be part of an experiment. In this field, the safety model is part of the measurement architecture.

Feamster’s work began with Infranet in 2002. The system approached censorship as circumvention. Cooperating web servers encoded covert upstream requests in ordinary-looking HTTP activity and hid downstream information in images. Its web assumptions belong to an earlier technical environment, but the project established a long-running idea: censorship is partly a contest over which traffic patterns can be distinguished from normal communication.

Later work moved from helping users cross a block to measuring the block itself. That shift created a public-interest opportunity. Large, repeatable measurements could document filtering that governments or network operators did not disclose. It also created a harder ethical boundary. A measurement system can generate evidence for the public while imposing risk on the individual machine that produces the signal.

This tension is not secondary to the career. It is the clearest case in which making the Internet explain itself can harm people who never asked the question. The ethical quality of a censorship measurement therefore depends on target selection, consent, rate limits, data retention, disclosure and the plausibility of retaliation, rather than statistical accuracy alone.

Encore showed how scale can outrun consent

Encore used cross-origin browser requests to test whether selected web resources were reachable from different networks. A participating website could cause a visitor’s browser to make a request, allowing researchers to infer whether the resource was blocked. The design promised scale without installing special software in every country.

The same mechanism created a serious ethics dispute. A person visiting an unrelated page could become a measurement vantage point without understanding the experiment. A request to a sensitive domain could be visible to a censor. A third-party website might appear to be probing material it had not chosen. The person bearing the risk and the researcher receiving the data were not necessarily the same person.

The independent paper No Encore for Encore? argued that the design raised concerns about informed consent, transparency, user safety and harm to third-party sites. It also documented communication with Feamster and changes to the system. The critique should neither be inflated into a finding of research misconduct nor reduced to a footnote that later work erased. It identified a genuine design risk in a system built for a legitimate public purpose.

Feamster and Ben Jones subsequently published Can Censorship Measurements Be Safe(r)? The title correctly treats safety as a continuum rather than a binary certification. Coverage, repeatability and accuracy compete with exposure of volunteers, targets and bystanders. A measurement that reaches many networks can be less acceptable if it cannot bound the risk imposed on each participant.

The episode changed the intellectual content of the research. Ethics was no longer an external review appended to a technical method. Threat models had to include the people who generated the traffic, the organisations that hosted the tests and the authorities that might observe them. That is a lasting lesson for all infrastructure measurement, especially as browsers, home devices and AI agents are used as distributed sensors.

Augur, Iris and later systems tried to increase reach without hiding the risk

Augur attempted to infer connectivity between remote locations through TCP/IP side channels without controlling a traditional measurement point at either end. The paper reported validation across nearly 180 countries during a 17-day period and included design choices intended to avoid implicating individual users. The approach expanded geographic reach, but the inference depended on operating-system behaviour, address selection, filtering asymmetry and statistical assumptions.

Iris focused on DNS manipulation. Repeated queries to resolvers could be compared across locations to identify anomalous answers. DNS provides structured evidence, but legitimate systems also cache, redirect, localise and filter. A difference in response is a starting point for attribution, not proof that a particular government agency issued the rule.

Test-list construction became another source of bias. A measurement programme that probes only globally prominent political sites can miss local languages and culturally specific topics. A 2018 project used natural-language processing and search to identify 1,125 sites absent from the then-largest China blocklist. The expanded list improved coverage for that study; it remained a time-bound artefact as domains, content and policy changed.

GFWeb, published at USENIX Security in 2024, examined HTTP and HTTPS filtering by China’s Great Firewall over 20 months. The paper reported testing 1.02 billion domains and identifying hundreds of thousands of pay-level domains affected by different filtering mechanisms. Those are measurement counts, not a census of affected people. Their value lies in showing that protocol-specific tests reveal different parts of a filtering system and that one technique can undercount.

Research on Turkmenistan reported testing 15.5 million domains, identifying 122,000 censored domains and inferring broader overblocking rules affecting millions more. The work also explored evasion. Publishing an evasion technique can help users and simultaneously teach the censor what to block next. Disclosure timing and local knowledge are therefore engineering decisions with human consequences.

Feamster’s record in this field is substantial and collaborative. He co-authored systems, helped build research communities and continues to teach Internet Censorship and Online Speech. He should not be described as the sole founder of every related observatory or assigned credit for Geneva merely because collaborators and topics overlap. Mapping papers and roles is more accurate than applying an umbrella inventor label.

Measurement ethics became part of technical correctness

The censorship work makes a broader point about observability. A system can be statistically powerful and still be technically unsuccessful if it cannot be operated responsibly. Consent mechanisms, target choice, query frequency, data minimisation and publication strategy determine whether the method can be repeated without unacceptable harm.

This is not a demand that researchers eliminate every risk. Complete safety may be impossible in a field where the subject is an adversarial state or network operator. It is a demand that risk be explicit, allocated and compared with the expected public benefit. The people most exposed should not disappear behind a global domain count.

The same principle applies outside censorship. A broadband probe can reveal household activity patterns. An IoT tool can collect device metadata. A security reputation score can deny service. A synthetic dataset can memorise traces it was supposed to protect. In each case, the measurement system creates a new infrastructure with its own users, privileges and failure modes.

Feamster’s career is valuable precisely because it includes a documented dispute rather than a seamless sequence of successes. The Encore controversy shows how a method can be criticised, modified and followed by more explicit safety work. It also shows why later safeguards should not be used to rewrite the original risk. A serious profile can credit learning while preserving the disagreement that made the learning necessary.

Smart homes showed what encryption does not hide

Encryption protects payload content, but a network still needs timing, packet sizes, directions and destinations to deliver traffic. A smart plug, camera, television or voice assistant can contact predictable services with a recognisable pattern. An observer who cannot read the message may still infer that a device turned on, streamed video or reported an event.

A Smart Home Is No Castle demonstrated this side channel, and Spying on the Smart Home extended the analysis while evaluating traffic-shaping defences. The latter paper reported that a constant-rate defence could protect activity at an overhead of roughly 40 kilobytes per second in its tested setting. That figure is not a universal privacy price. The device mix, threat model, link capacity and required level of concealment change the trade-off.

The work corrected a common simplification in consumer privacy. “Encrypted in transit” can be true while behaviour remains exposed through metadata. A privacy policy that discusses only content can therefore omit a meaningful risk. Defences such as shaping and padding consume bandwidth, energy or latency, and their cost may fall on the household rather than the manufacturer.

The practical question is not whether traffic analysis is possible in a laboratory. It is who can observe the home, what inference is reliable enough to matter and which party can change the design. An ISP, local adversary, device vendor and cloud provider have different views. Measurement identifies the leakage; consumer protection requires a decision about defaults, disclosure, remediation and responsibility.

IoT Inspector became a consumer tool and a research infrastructure

IoT Inspector moved the smart-home work from a controlled study into an open-source tool that users could run on their own networks. It allowed a participant to select devices, observe contacted destinations and, with consent, contribute labelled metadata to research. The 2020 paper documented thousands of users and tens of thousands of devices across many vendors and categories.

Later reports used different totals—44,956, 54,094, more than 55,000 or about 63,000 devices—because collection windows and reporting conventions differed. Choosing the largest number without a date would turn a changing dataset into false precision. The important evidence is that the project operated at a scale where user support, label quality, privacy and software maintenance became first-order research problems.

A user-facing inspection tool also exposes ambiguity. A domain may be shared by several cloud customers. A device label can be wrong. A connection to a tracker does not by itself explain what data moved or what harm followed. Showing a destination can improve visibility without giving the user a practical remedy.

The project team’s retrospective discussed incentives, consent, data minimisation and operational maintenance. That record matters because an open research platform can create obligations similar to a service provider’s. It stores sensitive evidence, relies on participant understanding and must continue to communicate what its findings can and cannot establish.

Related studies of sampled medical IoT devices, connected toys and user perceptions extended the work into consumer protection. Results should remain tied to the tested product, version and date. Firmware changes, vendor remediation and different deployments can alter the outcome.

Network machine learning is a pipeline, not a classifier in isolation

Machine learning entered Feamster’s work through spam and reputation long before the current generative-AI cycle. The later netml.io programme made the surrounding pipeline more explicit. A network classifier depends on how packets are represented, how labels are obtained, where features are extracted, how quickly the model runs, how drift is detected and what action follows.

nPrint represented packets at bit level in a standard form, while nPrintML paired representation with automated modelling. The objective was not to prove that one representation is best for every task. It was to make comparisons more reproducible by reducing hidden changes in feature engineering.

Traffic Refinery addressed the cost of producing features at high rates. An accurate model is operationally poor if feature extraction drops packets, exhausts CPU or returns a result after the decision window has passed. LEAF examined concept drift, the change in statistical relationships as applications, devices and networks evolve. A production model needs criteria for retraining, rollback and per-environment error monitoring.

CATO combined predictive and systems objectives. Its NSDI 2025 evaluation reported up to 3,600 times lower inference latency and 3.7 times higher zero-loss throughput under specific experimental conditions. Those numbers are not general production guarantees. Their conceptual importance is that statistical accuracy and packet-processing cost must be optimised together.

Current work extends that logic into low-cost classification, queueing, probe selection, L4S field measurement and language-model analysis of misconfiguration. The 2005 thesis relied on explicit invariants; a 2026 language model may infer a likely problem from examples and text. The newer method can cover cases that are difficult to formalise. It also risks replacing proof with plausibility unless the recommendation is checked against observable network state.

Synthetic traffic tries to share useful data without exposing the real network

Real traffic traces are difficult to share. They can reveal communications, users, devices, organisational structure and proprietary applications. Labels are expensive, and a trace can become stale quickly. Synthetic data promises an alternative: generate packets and flows that preserve useful properties without publishing the original records.

NetDiffusion used diffusion models with protocol constraints to generate packet-level traffic. NetSSM added state and multi-flow awareness. GATEAU, led by Feamster and Francesco Bronzino, frames the broader problem around privacy, collection cost and scarce labelled data. These projects seek a middle ground between random packets that are technically valid but unrealistic and real traces that cannot be safely distributed.

A generated trace can still fail in several ways. It may preserve marginal statistics while losing the correlations needed for a downstream task. It may memorise sensitive examples. It may satisfy protocol syntax without reproducing congestion, session state or user behaviour. A classifier trained on it may appear successful and fail on production traffic.

The 2026 work on privacy and quality trade-offs treats those risks as measurable rather than assuming that “synthetic” means anonymous. That is the right standard. Privacy must be tested against plausible attacks, while utility must be tested on the task for which the data will be used. Synthetic traffic is a research instrument, not a certificate that the original network has disappeared.

NetMicroscope tests whether the measurement programme can become a business

NetMicroscope is the clearest commercial translation of Feamster’s broadband and machine-learning research. The company identifies Feamster as chief executive and co-founder and Francesco Bronzino as chief technology officer and co-founder. University commercialisation material says they founded it in 2021, with a remote team centred in Chicago and Lyon.

The product thesis is that throughput, latency, loss, device state and application signals become more useful when combined into an estimate of user-facing quality. An operator may know that a line is active without knowing why a video session degraded. NetMicroscope says it uses machine learning to infer application experience and identify problems before a complaint.

The verified financial evidence is limited. In January 2024, the George Shultz Innovation Fund awarded the company $200,000 for product, market, team and intellectual-property development. The company also participated in I-Corps and the Compass accelerator. These are meaningful early commercial signals. They are not evidence of valuation, total financing, revenue, customer count, retention, market share or profitability.

The academic-company boundary deserves ordinary scrutiny rather than insinuation. Papers related to traffic classification may overlap with a commercial product. Readers need disclosure of affiliations, funding, data access, licences and intellectual-property ownership. The supplied record does not show that all BISmark, nPrint or university code was transferred exclusively to the company.

NetMicroscope therefore supports a modest conclusion: it tests whether years of measurement research can become an operational service customers will pay for. The public evidence verifies the founders, product direction and a university award. It does not yet support a claim of commercial dominance.

Teaching turned the research arc into an infrastructure curriculum

Feamster’s teaching record follows the same progression as the research. Courses at Georgia Tech covered Internet architecture, security and next-generation networking. Later offerings included software-defined networking. At Princeton, the subjects joined networking with information security and technology policy. Current UChicago courses include Machine Learning for Computer Systems, Internet Censorship and Online Speech, and Security, Privacy, and Consumer Protection.

He co-authored the sixth edition of Andrew Tanenbaum’s Computer Networks in 2020. His teaching page also credits him with creating and serving as founding instructor for the computer-networking course in Georgia Tech’s Online Master of Science in Computer Science programme. That online course extended networking instruction far beyond one campus cohort, although the founding claim should remain attached to his documented teaching record unless a programme archive is cited separately.

The 2026 Quantrell Award provides independent institutional evidence that teaching is central to his work. UChicago’s announcement highlighted open-ended problems, collaborative reasoning and exercises designed around real work. The student comments are qualitative, but the award demonstrates that the career cannot be reduced to papers and startups.

Institution building widened the audience further. Feamster directed Princeton’s Center for Information Technology Policy and later helped lead UChicago programmes connecting network measurement, public policy and data science. Workshops around free and open communications helped establish a community in which ethics and measurement design could be debated together.

A fair account must keep collaborators visible. Many systems were implemented or led by students and junior researchers. IoT Inspector, censorship projects, broadband testbeds and ML systems have substantial multi-author teams. A professor can set direction and build institutions without becoming the sole author of every result.

Policy work supplies evidence but does not exercise regulatory authority

Feamster’s public-policy role is rooted in measurement. UChicago says he has worked with organisations including the Federal Communications Commission and the City of Chicago. Internet Equity and broadband projects can provide evidence about accessibility, affordability, reliability and performance. They do not decide subsidy eligibility, regulate prices or order a provider to change its network.

That boundary matters because technical evidence gains authority when it enters government. A speed test can inform a challenge process, but the legal criteria are set elsewhere. An interconnection graph can clarify utilisation, but contracts and routing decisions remain outside the graph. A censorship dataset can document interference without completing the legal or political analysis.

The current AI privacy work extends the same problem into a new ecosystem. A Google Privacy Faculty Award supports research on third-party integrations in language-model systems. A user may see one interface while prompts, context and inferred attributes move among plugins, APIs and remote services. The structure resembles a smart home: one visible product coordinates several hidden data relationships.

The 2026 publication list includes work on implicit LLM inference, where a model derives sensitive attributes even when a user has not supplied a conventional identifier. That makes data minimisation harder. Removing names or account numbers does not prevent a model from inferring health, political or demographic information from ordinary interaction.

The policy value of this work lies in making evidence boundaries visible. A model, dataset or professor can inform a decision without owning it. Good institutional use requires transparent methods, error estimates, versioned data and an explicit separation between what the measurement shows and what an authorised body chooses to do.

What the career has made visible—and what remains hidden

Across routing, spam, broadband, censorship, smart homes and machine learning, Feamster’s projects repeatedly converted a diffuse operational problem into an evidence system. rcc mapped configurations to invariants. RCP gave route selection a wider view. Reputation systems inferred coordination from metadata. Gateways isolated parts of broadband performance. Censorship systems compared remote signals. IoT Inspector connected device traffic to user labels. NetML projects joined representation to deployment cost and drift.

The systems did not make the Internet fully knowable. A clean configuration check does not eliminate physical failure. A reputation score does not establish guilt. A speed measurement does not explain affordability. A DNS anomaly does not identify a government agency. Encrypted metadata does not reveal every device action. A synthetic trace does not guarantee privacy. A language model does not become correct because it produces a coherent diagnosis.

Those limitations are not reasons to dismiss measurement. They are reasons to design the operating system around it carefully. Useful evidence should show its source, age, scope and uncertainty. High-impact actions should have review, appeal or recovery. Researchers should state when a result is paper-reported, institution-reported or independently reproduced. Commercial claims should not inherit the authority of academic publication without separate evidence.

Feamster’s enduring contribution is the repeated construction of that middle layer between opaque infrastructure and consequential decisions. His work has helped operators, researchers, users and public institutions ask better questions of systems that were not built to explain themselves. The result is not certainty. It is a more disciplined account of what can be observed, what can be inferred and what still requires judgement.