Summary

  • Nick Feamster is a University of Chicago professor, measurement researcher, institution builder, and co-founder of NetMicroscope, focused on making hidden internet behaviour actionable for accountable decisions.
  • His work on rcc reported over 1,000 previously undiscovered faults across 17 autonomous systems; the Routing Control Platform helped establish a network-wide control model later associated with SDN.
  • His spam, broadband, censorship and smart-home projects also revealed measurement limits: reputation can mis-classify, remote probes can create risk, and encrypted metadata can expose behaviour.
  • His current machine-learning research asks whether results are effective, auditable and safe in production; his most notable contribution is collaborative systems that preserve uncertainty.

Rcc: inspecting collective configuration before deployment

A 2005 paper,Detecting BGP Configuration Faults with Static Analysis, which Feamster co-authored with Hari Balakrishnan, introduced a router configuration checker called rcc. It categorised persistent faults into two broad classes. Route validity faults occur when the control plane selects a path for which no usable data-plane route exists. Route visibility faults occur when a usable route exists but the routers that need it do not learn it. The two classes linked configuration commands to outcomes an operator could recognise.

rcc analysed configurations from multiple routers and checked network-wide constraints. The paper reported analysing 17 autonomous systems, finding over 1,000 previously undetected faults, and more than 65 operator downloads. These are historical figures the authors reported. They do not prove that rcc turned into a general industry product, nor does the evidence show how many networks carried on using it. But they demonstrate that it was built on real configurations and reached operators beyond the authors’ lab.

The operational significance lies in the kind of evidence. The checker can point to a configuration relationship that violates a constant before an outage. That is different from a dashboard showing packet loss after service degradation. It ties a rule to a reasoning failure class and supports review, testing and discussion among teams that ordinarily have only local vantage points.

The limitations are equally instructive. rcc could check only properties its designers wrote and its analyser supported. It did not know the intent of undocumented practices, could not guarantee the absence of vendor defects or physical failures, and did not turn a clean configuration into proof that the network would not encounter a transient problem. A network could pass every written check and still violate a condition no one had expressed.

This is why rcc sits at the start of the wider narrative. It established the ambition and the caveat that recur later. The ambition is to make infrastructure behaviour computable before damage. The caveat is that correctness is always relative to observed inputs and declared properties. Modern AI-for-operations systems face the same test, but the boundary can be harder to see when the model generates fluent explanations rather than explicit constants.

The internet usually knows what it did, but it cannot explain why

A packet reaches its destination, or it does not. A video call stalls. A domain returns an unexpected address. A mail server refuses a connection. A smart speaker contacts a remote service at a moment that reveals something about activity. Every event leaves a trace, but the internet keeps no central log that delivers a single authoritative explanation. Its behaviour emerges from independently operated networks, vendor-specific configurations, private interconnection agreements, home equipment, application design and shifting user demand.

That architecture is valuable because it prevents any single operator from controlling the whole system, but it makes diagnosis hard. A router can display its paths, but it does not explain every combined outcome of the routing policies. A speed test can measure one hop, but it does not isolate the effect of Wi‑Fi, access capacity, latency, interconnection and application. A censorship probe can detect a failed request, but it cannot identify the person or entity responsible. And a traffic classifier can assign a label, but it does not prove that the label will remain correct after the network changes.

Feamster’s research record can be read as a series of attempts to narrow these gaps. The techniques differ, but the method is clear. First, pick a hidden behaviour that matters. Second, find an observation point where that behaviour leaves a measurable signal. Third, build a representation that turns the signal into a question an operator, a policymaker or a user can ask. Fourth, test where the representation fails. That last step is essential, because a system that gives a confident answer without showing its limits can make infrastructure less accountable, not more.

That is why Feamster is a subject of digital infrastructure even though he owns no fibre, operates no public autonomous system and manages no hyperscale cloud. His work sits in the information layer surrounding those assets. He influences how paths are audited, how abuse is identified, how broadband quality is characterised, how censorship is documented, and how statistical models enter network operations. Routers and cables move traffic; measurement and analysis determine whether anyone can explain what they are doing.

So the most powerful account of this career is not a prize list nor a claim that a single researcher invented several fields. It is the history of an observation programme that continually changed its subject while keeping the same discipline: separate what was directly observed from what was inferred, and separate an experimental result from an operational guarantee.

One career, multiple institutional identities

As of the research cut‑off, 3 August 2026, the University of Chicago described Feamster as the Neubauer Professor of Computer Science and Faculty Director of Research at the Data Science Institute. His current page also lists him as director of the Network Operations and Internet Security Lab, co‑director of the Internet Innovation Initiative, co‑lead of netml.io, and co‑director of the AI and Policy Pillar. A September 2024 Data Science Institute post used the title Director of Technology Policy. These descriptions can coexist because university roles overlap and evolve, but they should not be merged into a single permanent job title.

The institutional distinctions have practical weight. As a professor he conducts research and teaches. Through the NOISE Lab and netml.io he works with students and collaborators on routing, measurement, privacy and machine learning. Through the Internet Innovation and Internet Equity projects he helps build evidence for public and infrastructure decisions. As co‑founder and CEO of NetMicroscope he participates in a private company that seeks to turn network‑quality analysis into a commercial product. His biography also notes that he serves as an expert witness in technology cases.

No role automatically imparts the authority of the other: the professor is not a regulator, the start‑up CEO does not turn university research into a client recommendation, and the expert opinion is not a judicial ruling.

This separation is consistent with the core of the research. Feamster’s best work asks which system holds which piece of evidence and what inference that evidence can support. The same caution is needed when describing the person. His current biography attributes writing the first web crawler for LookSmart and helping design the first botnet‑detection algorithm at Damballa. These are useful, attributable facts about early industry work, but they do not prove precise employment dates, sole authorship, ownership stakes, or a full product history.

The public record is far richer on professional work than on personal life. It does not reliably establish date or place of birth, nationality, family background, compensation, NetMicroscope stake, personal investments or wealth. An evidence‑based profile should not turn that absence into speculation. The career is rich enough without adorning it with celebrity biography the sources do not support.

MIT, a web crawler and a thesis about detecting failure before it happens

Feamster stayed at the Massachusetts Institute of Technology from undergraduate to doctorate. He earned an SB in electrical engineering and computer science in 2000, an MEng in the same field in 2001, and a PhD in computer science in 2005 under Hari Balakrishnan. The thesis title,Proactive Techniques for Correct and Predictable Internet Routing, plainly states the early programme: instead of waiting for a routing error to cause an outage and then reconstructing the cause, the network should expose enough structure to check important properties before deployment.

The early LookSmart work provides a useful but limited prelude. A web crawler must discover a large graph that changes while it is being watched, and handle broken links, duplicate pages, inconsistent responses and unreachable regions. The crawler did not directly turn into the later routing systems, and sources do not support that claim. The methodological continuity matters more: a distributed system does not appear from a single local perspective, so useful knowledge requires structured collection and an explicit representation of what has been discovered.

The Damballa connection added an adversarial version of the same problem. Botnets are designed to hide their members and their control. The official biography says Feamster helped design the company’s first botnet‑detection algorithm. The public evidence does not reconstruct the full team or show how later products used that work. But it does show that his early career crossed between academic systems research and an operational security company that needed to infer malicious coordination from network traces.

The doctoral research took shape in an environment where inter‑domain routing policies were distributed across devices and organisations. Operators expressed, through router commands, peers, customers, export rules, backup paths and traffic‑engineering preferences. Every configuration could look reasonable alone while the combined network hid a loop, a black hole or an unintended path. The problem was not just a faulty protocol implementation; it was the difficulty of reasoning about a distributed programme assembled from many local policies.

That framing became a lasting feature. Feamster often treated the operational system around the algorithm as the real unit of research: the configuration files, measurement points, data pipelines, interfaces, operator incentives and institutional constraints. It expanded the work beyond a single theorem or classifier, but it also expanded the responsibility. When a system touches real operators, homes or people living under censorship, deployment and ethics become part of technical quality.

BGP configuration as a distributed programme

The Border Gateway Protocol lets autonomous systems exchange reachability information while retaining control over business and routing policy. That autonomy is one reason the internet can connect networks with different owners and different goals. But it also means that the global outcome is not designed by a single engineer. Policies are composed indirectly from announcements, preferences, filtering and the internal distribution of routes.

The problem can be large even inside a single autonomous system. A network may contain hundreds of routers and several ways of distributing external routes. A route learned at one edge must appear where it is needed, not necessarily everywhere. Export policy should prevent leaking customer or peer routes to the wrong neighbour. Backup paths should appear when the primary fails without creating loops or permanent oscillation. The operator knows the business intent; the devices carry the executable pieces.

The early routing research treated these pieces as analysable programmes. A router’s configuration was no longer just text to be reviewed line‑by‑line; it became an input to a network‑wide calculation. Correctness could be expressed as constants: the chosen path should lead to a usable forwarding path; the usable path should appear to the routers that need it; export policy should preserve intended relationships; and internal route distribution should not create lasting inconsistency.

The software‑analysis analogy was useful because it changed the timing of intervention. Traditional troubleshooting starts after a symptom appears; static analysis asks whether a known class of failure is already encoded in the configuration. It needs no traffic injection and no wait for a customer report. In networks that carry critical services, moving the defect from the incident queue to the review queue can matter more than shortening post‑failure diagnosis.

But the analogy has limits. Network state includes more than configuration: live routes, topology, vendor behaviour, transitional convergence, hardware tables, failed links and unwritten commercial knowledge. A static checker can be perfectly accurate inside its model and miss a failure outside it. Feamster’s later research returned repeatedly to the gap between a useful representation and the whole operational world.

The Routing Control Platform moved decisions out of individual routers

rcc asked whether the distributed configuration satisfied known constraints. The Routing Control Platform asked a different question: why should every router independently reconstruct the information needed to choose paths? Traditional iBGP designs distributed external routes via a full mesh or route reflectors. A full mesh becomes unwieldy as the network grows. Reflectors improve scalability but can hide routes, produce unexpected choices and make the outcome harder to analyse.

The RCP paper proposed a logically centralised service that collects external BGP routes and the internal topology, chooses paths for each router, and delivers the choices over ordinary iBGP. The forwarding devices did not go away; they still moved packets and spoke a familiar protocol at the interface. What changed was where the path‑selection logic lived and how much visibility it had.

‘Logically centralised’ did not mean a single fragile physical box. The control service could be replicated and distributed while still offering a consistent decision function. That distinction is fundamental in later SDN as well. A controller can operate with network‑wide visibility without running every control operation on one device. The problem becomes one of state consistency, fault recovery and safe interfaces, not a binary choice between total centralisation and total distribution.

RCP respected the installed base. It did not demand a new forwarding layer or an immediate replacement of every router. That choice has value in networks where hardware, contracts and procedures cannot be changed all at once. A research architecture gains operational value when it enters a live environment through an interface operators already understand.

The evaluation used real data from backbone networks, but the supplied record does not prove wide production deployment. The defensible claim is that RCP demonstrated a workable architecture and became influential, not that it replaced internal iBGP across the entire industry. Its 2015 NSDI Test of Time Award supports lasting intellectual importance, but it does not prove market adoption and does not give a single paper ownership of every subsequent controller design.

A major SDN contribution, not a lone‑inventor story

SDN is often recounted as a clean break: control moved to software, forwarding became programmable, and a new era began. But the history is less tidy. Active Networks, virtualisation, the 4D architecture, Ethane, RCP, OpenFlow, NOX and other projects addressed different pieces of programmability, control separation and network‑wide management. Feamster was an important contributor to that thread, but no evidence justifies describing him as the sole inventor of SDN.

RCP offered a clear architectural idea: a control service with wider visibility can calculate path decisions and push them to existing forwarding devices. rcc offered another: network policy can be audited against constants. Together they helped shift the operational question from ‘what is on this router?’ to ‘what behaviour does the whole control system implement?’ That shift is one intellectual foundation of programmable networking.

Feamster later co‑authoredThe Road to SDN, which presented the field as an accumulation of ideas, not a single moment of invention. That historical stance is useful for resisting the founder‑myth that grows around infrastructure technologies. A field becomes possible when research groups, operators, vendors and standards bodies solve neighbouring problems and make solutions deployable.

A 2017 paper,Why (and How) Networks Should Run Themselves, with Jennifer Rexford, extended the argument from controller architecture to continuous operation. It described closed loops where high‑level intent drives decisions, measurements detect outcomes, and the system adapts. The title was deliberately provocative and does not mean that engineers are no longer needed. A self‑adjusting network needs correct objectives, trustworthy measurements, safe execution, bounded authority and a mechanism to stop when the evidence is ambiguous.

That programme today looks more like a design problem for AI‑augmented operations than a distant vision. Language models can suggest configurations, summarise incidents and select tools, but they can hallucinate causes, misunderstand policy and act with excessive authority. The early routing research imposes a hard standard: learned recommendations should be surrounded by explicit checks and observable outcomes, not accepted because their explanation sounds plausible.

Spam research made the network around the message more important than the message itself

At Georgia Tech the observation subject moved from configuration errors to adversaries who deliberately change. Spam campaigns and botnets were designed to move. Compromised machines appeared and disappeared, addresses shifted, domains were replaced, and control infrastructure was distributed. A content fingerprint could catch a known message, but the delivery system itself often revealed the more persistent pattern.

The 2006 SIGCOMM paper,Understanding the Network‑Level Behavior of Spammers, analysed more than ten million spam messages according to the paper’s record. It studied where senders appeared, how long they stayed, and how spam related to address space and routing behaviour. The significance was not a single fixed rate, but in showing that abuse could be studied as infrastructure: the set of senders, paths, timing and source concentration could reveal coordination that the message text alone would not.

The method offered a practical advantage. Network‑level properties can be available early in the connection, before the full message is accepted or inspected. This reduces processing, lets defence work at scale, and can preserve some content privacy by relying on metadata. But the abstraction itself creates risk. A residential prefix can contain innocent users and compromised machines. A shared server can host benign and malicious domains. The owner of an address can change. An infrastructure reputation is useful only if it incorporates uncertainty, staleness and a challenge path.

The DNSBL counter‑intelligence work used the adversary’s need for self‑defence as a signal. Botnet operators queried DNS‑based blocklists to see whether their machines had been detected. Distinctive query patterns could suggest likely botnet membership. The idea was clever because the attacker’s reconnaissance became evidence, but it remained probabilistic inference. A query can have a legitimate reason, and the list of candidate machines still needs confirmation before a disruptive action.

SNARE used spatial, temporal and network features available during an SMTP session to assess senders. The evaluation reported roughly 93 % accuracy with a low false‑positive rate. That result belongs to the study’s data, threat environment and threshold; it is not a fixed property seventeen years later. Adversaries adapt, mail infrastructure consolidates, and feature distributions change. The result therefore shows that early network signals can support a useful classifier, not that they are a permanent benchmark.

The dynamic DNS reputation system extended the same reasoning from senders to domains. Registration patterns, name servers, address churn and resolution behaviour can make malicious infrastructure look different from a stable, legitimate service. A classifier can use those differences to assign a risk before it knows every payload. The method foreshadowed later network‑based machine learning: build a representation from metadata, train a decision rule, and then face the operational consequences when the representation is incomplete.

Reputation is an operational decision, not an objective label

Behavioural clustering of HTTP‑based malware pushed the method further. Instead of requiring a matching signature for every binary, samples were grouped by communication behaviour and then network fingerprints were created. That can remain useful when code changes but control‑protocol habits, destinations or timing persist, though it can lump unrelated traffic together if the representation is coarse.

The gap between signal and judgement governs how a system is used. A model can say that an address, a domain or a flow resembles known abuse. An operator must decide what happens next. A low‑confidence result may trigger extra monitoring; a stronger one may lead to rate‑limiting. Blocking an entire range or an entire prefix can impose a cost on innocent users. Technical design therefore includes the threshold, the shelf‑life of the evidence, the scope of the action and the correction path.

The early Damballa work and a patent assigned to Georgia Tech Research Corporation show a commercial and legal context for this research. The patent lists Feamster together with David Dagon, Wenke Lee and other inventors for a method of detecting and responding to attack networks. The patent provides a formal record of inventors and assignment, but it does not prove sole invention, production use, licensing income or that every claim is valid in every jurisdiction.

The wider contribution was turning reputation into an infrastructure problem rather than an abstract accuracy score. A defender needs a classifier that runs in time, at line rate, on data that can be lawfully collected, with errors that can be managed. A paper can improve one piece of the chain; a production system has to carry the whole chain for years while the adversary changes.

This is the link between the security work and the current machine‑learning programme. Later projects give clearer attention to feature cost, drift, privacy and deployment. The foundational question remains the same: when a network signal becomes a decision, what evidence makes that decision reliable enough to affect real traffic?

Home‑gateway measurement changed the observation point for broadband

It is easy to say ‘the internet is slow’ but hard to diagnose what is meant. The problem could sit in the access‑link capacity, Wi‑Fi, a resource‑hungry home device, a congested interconnection, a distant server, application delay, or a test that cannot generate traffic fast enough. A measurement from a laptop inherits the state of its software and its local network, while a measurement from deep inside the provider’s network misses what the home actually sees.

The gateway approach placed controlled measurement at the boundary between the home and the ISP. A 2011 SIGCOMM study used longitudinal data from about 4,000 gateway devices across eight providers, within a broader deployment that exceeded 4,200 devices. It studied throughput, latency, access technologies and traffic‑shaping behaviour. The gateway’s value was analytical: it watched the access service while avoiding some of the uncontrolled variance in an ordinary endpoint.

That observation point did not make the answer automatic. A home gateway shares the local environment with devices and Wi‑Fi. The measurement server has its own path and capacity. The test can interfere with home traffic or run at unrepresentative times. The method improved attribution, but it did not create a complete view of user experience.

BISmark turned the gateway method into a reusable testbed. A 2014 USENIX ATC paper described dedicated routers and a back‑end that could deploy measurements and applications. At the paper’s date the system was running in hundreds of homes across about 30 countries and was used by researchers at nine institutions. Those numbers are time‑bound, but they indicate work that went beyond a single dataset.

Maintaining a home platform is infrastructure work in itself. Hardware must be shipped and supported, users unplug devices, firmware ages, clocks drift, and consent must stay meaningful. Data schemas and collection pipelines have to survive changing networks and applications. The deployed system was therefore as much a demonstration of building a research institution as it was a measurement design.

The broadband programme also illustrates why methodology matters for policy. A controlled gateway result cannot be substituted by a browser test, an ISP‑provided meter or an advertised package speed; each measures a different piece of the path. Public decisions become more defensible when measurement location and its limits are visible rather than hidden behind a single speed number.

When access links got faster, speed alone stopped explaining the experience

Early broadband policy focused heavily on whether the provider delivered the advertised rate. The question remains important where access capacity is scarce, but it loses some explanatory power once the link is fast enough that latency, Wi‑Fi, content distribution and application design dominate the experience.

A study covering more than 5,000 broadband networks examined web‑performance bottlenecks and found that, above a study‑specific speed range, the raw access rate was often not the sole factor. A faster package may not make a page feel faster if round‑trip time, page‑element dependencies or server behaviour determine completion time. The precise threshold should not be turned into a universal rule. The longer‑lasting finding is that quality becomes multi‑dimensional as the access link improves.

Reliability adds another dimension. A service can achieve a good median speed and still fail a home with short outages. A call, an exam or a telehealth session can break because of a brief loss that vanishes in a monthly average. Longitudinal measurement is needed to characterise failure frequency, duration and timing; a single test cannot do that.

Encrypted DNS research revealed a similar trade‑off. Resolver and protocol choices affect latency, privacy and reachability. In the measured sample no single setting was best for every user and network. A security or privacy improvement can carry a performance cost in one environment but not in another. That cautions against turning one standard into a blanket prescription.

COVID‑era measurements showed how quickly the operating environment can change. The participating providers faced a sudden shift in traffic and interconnection demand, followed by capacity additions and altered usage patterns. The results are bounded to the measured networks, but they showed why planning built solely on stable historical averages can fail under a societal shock.

At this point broadband measurement becomes user‑experience engineering. An operator needs to connect low‑level signals—throughput, latency, loss, outages, interconnection—to outcomes such as video stalls and meeting quality. That linkage became part of the NetMicroscope product hypothesis. The academic results do not prove every company claim, but the technical lineage is direct.

Interconnection measurement turned a commercial dispute into a shared data problem

A path between a home and an application can cross several commercial boundaries. An access provider may exchange traffic directly with a content network, through an internet exchange point, or through a transit provider. Congestion can sit on a single link, in one direction, during one interval. Public discussions about ‘interconnection’ can therefore lump together different technical situations.

The Interconnection Measurement Project asked participating providers to install a common measurement tool at interconnection points. The project reported about 2,900 links and peak‑period utilisation of roughly 31 % in June 2021, together with evidence of capacity additions. These aggregate results do not prove that every user path was free of congestion; an average can hide a short spike, a single path or a local failure. The project’s value was in giving several parties a shared method and vocabulary.

A shared measurement regime can reduce one kind of disagreement and create another. Entities must agree on which links are measured, how usage is sampled, how private data are protected, and which summaries can be published. Providers can have commercial reasons to limit disclosure. Researchers need enough detail to test claims without revealing customer relationships or security‑sensitive topology.

Feamster’s role here is more precisely described as building measurement capability and institutional cooperation. He did not regulate interconnection contracts, nor did he hold compulsory authority to make parties participate. The project shows the research moving from a tool on a home gateway to a shared evidence regime with operators. The technical task was not separate from governance: useful data required cooperation from the organisations that control the links.

Internet equity expands performance to include access, cost and reliability

A broadband line can exist in a neighbourhood but remain unaffordable. A household can subscribe but receive an unreliable connection. A provider can deliver the advertised rate while Wi‑Fi, building wiring or device quality prevent an application from working well. Reducing the digital divide to a single coverage map hides these differences.

The Internet Equity Initiative at the University of Chicago gathers dimensions including availability, infrastructure, affordability, adoption, performance and reliability. Its gateways and projects link network measurements to demographic data and public policy. Devices in Chicago homes provided direct evidence of service performance, while open data enabled comparisons across places and groups.

The method can show a pattern without explaining every cause. A difference between neighbourhoods can correlate with income, building type, provider competition, subscription tier, equipment or historic investment. The demographic overlay supports investigation, but it does not prove why a gap exists. Policy needs the same distinction that routing research required: a representation makes the question testable, but it does not compensate for missing variables.

UChicago reported in 2025 that the Internet Innovation collaboration contributed measurement and analysis to broadband planning in Illinois covering 175,000 unserved homes, businesses and institutional locations. That is an important institutional claim, but it involved the Illinois Broadband Lab, state officials and other partners. It should not be turned into a statement that a single professor personally reached 175,000 locations or that every planned build is already complete.

The move from gateway tests to internet equity reveals a change in the intended user of measurement. An operator can use a gateway result to diagnose a line, a city can use a neighbourhood pattern to target a subsidy, and a state can use verified data in a funding process. The more measurement enters high‑stakes public decisions, the more it needs transparent definitions, versioned data and a clear account of what remains uncertain.

Censorship research made observability a question of human safety

Internet censorship is hard to measure for the same structural reason that makes routing hard to explain: the observer sees an outcome produced by multiple systems. A DNS failure could result from government filtering, a local firewall, an ordinary DNS error, a server outage or routing instability. A connection reset could be injected, generated by the endpoint, or caused by a middlebox unrelated to political control. The signal rarely arrives signed with the responsible party’s name.

The risks are different because measurement can expose a person. Researchers seek observation points inside censored networks, but volunteers can face retaliation. Remote techniques can reduce the need to recruit local entities, but they can involve users, sites or systems that have not consented to the experiment. In this domain the safety model is part of the measurement architecture.

Feamster’s work in this line began with Infranet in 2002. The system treated censorship as a circumvention problem. Cooperating web servers encoded covert upstream requests inside ordinary‑looking HTTP and hid the downstream data in images. Its web assumptions belong to an older environment, but it established a long‑lived idea: censorship, too, is a struggle over which traffic patterns can be distinguished from normal communication.

Later work moved from helping a user bypass a block to measuring the block itself. That created a public‑interest opportunity; wide, repeatable measurements can document filtering that a government or operator does not announce. But it also created a harder ethical boundary. A measurement system can produce evidence for the public while placing risk on the individual device that emits the signal.

This trade‑off is not marginal in the career. It is the clearest case where making the internet explain itself can harm people who never asked the question. The ethical quality of a censorship measurement therefore depends on target selection, consent, rate limits, data retention, disclosure and the prospect of retaliation—not on statistical accuracy alone.

Encore showed how scale can outrun consent

Encore used cross‑origin browser requests to test whether chosen web resources were reachable from different networks. A participating site could cause a visitor’s browser to issue a request, and researchers would infer whether the resource was blocked. The design promised scale without installing special software in every country.

The mechanism itself created a serious ethical dispute. A person visiting an unrelated page could become a measurement point without understanding the experiment. A censor could see a request for a sensitive domain. A third‑party site could appear to test material it had not chosen. The person bearing the risk was not necessarily the researcher receiving the data.

The independent paperNo Encore for Encore?argued that the design raised issues of informed consent, transparency, user safety and potential harm to third‑party sites. It also documented communication with Feamster and changes to the system. The criticism should not be inflated into a verdict of research misconduct, nor should it be reduced to a footnote erased by later work. It identified a genuine design risk in a system with a legitimate public purpose.

Feamster and Ben Jones later publishedCan Censorship Measurements Be Safe(r)?. The title correctly treats safety as a continuum, not a binary certificate. Coverage, reproducibility and accuracy compete with the exposure of volunteers, targets and bystanders. A measurement that reaches many networks may be less acceptable if it cannot bound the risk it imposes on every entity.

The episode changed the intellectual content of the research. Ethics was no longer an external review added after the technical method. The threat model had to include the people who generate traffic, the organisations that host the test, and the authorities that may be watching. That remains a lesson for all infrastructure measurement, especially as browsers, home devices and AI agents become distributed sensors.

Augur, Iris, and later systems tried to widen coverage without hiding risk

Augur tried to infer reachability between remote sites through TCP/IP side channels without controlling a traditional measurement point at either end. The paper reported validation across about 180 countries over 17 days and included design choices meant to avoid implicating specific users. The method widened geographic coverage, but the inference depended on operating‑system behaviour, address selection, filtering asymmetry and statistical assumptions.

Iris focused on DNS manipulation. Repeated queries to resolvers across locations could be compared to detect anomalous answers. DNS provides structured evidence, but legitimate systems also cache, redirect, localise and filter. An answer difference is a starting point for attribution, not proof that a particular government body issued the rule.

Test‑list construction became another source of bias. A programme that tests globally known political sites can miss local languages and culturally specific topics. A 2018 project used natural‑language processing and search to identify 1,125 sites not in the largest Chinese blocklist at the time. The list improved coverage in that study, but it remained a time‑bound artefact as domains, content and policy changed.

GFWeb, published at USENIX Security in 2024, examined HTTP and HTTPS filtering by the Great Firewall of China over 20 months. The paper reported testing 1.02 billion domains and identifying hundreds of thousands of affected pay‑level domains through different mechanisms. Those are measurement counts, not a head‑count of affected people. Their value is in showing that different protocol tests reveal different pieces of the filtering system and that a single technique can under‑count.

Research on Turkmenistan reported testing 15.5 million domains, identifying 122,000 censored domains, and inferring broader overblocking rules that affect millions more. It also examined circumvention tools. Publishing a circumvention method can help a user and, at the same time, teach a censor what to block next. Disclosure timing and local knowledge are therefore engineering decisions with human consequences.

Feamster’s record in the area is large and collaborative. He co‑authored systems, helped build a research community, and still teachesInternet Censorship and Online Speech. He should not be described as the sole founder of every relevant observatory, nor should Geneva be attributed to him simply because collaborators and topics overlap. Mapping papers and roles is more accurate than attaching an all‑encompassing inventor label.

Measurement ethics became part of technical soundness

Censorship research offers a wider point about observability. A system can be statistically powerful and still be technically failed if it cannot be run responsibly. Consent mechanisms, target selection, query frequency, data minimisation, and disclosure strategy determine whether a method can be repeated without unacceptable harm.

That does not demand that researchers eliminate every risk. Complete safety may be impossible in a domain whose subject is a hostile state or network operator. What is required is that risk be explicit, distributed, and weighed against the expected public benefit. The people at greatest exposure should not be made to vanish behind a global domain count.

The same principle applies beyond censorship. A broadband probe can reveal a pattern of home activity. An IoT tool can collect device metadata. A security reputation score can deny service. A synthetic dataset can retain traces it was supposed to protect. In each case the measurement system creates new infrastructure, with its own users, authorities and failure modes.

Part of the value of Feamster’s career is that it contains a documented dispute rather than an unbroken string of successes. The Encore episode shows how a method is criticised, adjusted, and followed by more explicit safety work. It also shows why later safeguards should not be used to rewrite the original risk. A serious profile can appreciate the learning while preserving the disagreement that made it necessary.

Smart homes showed what encryption does not hide

Encryption protects payload content, but the network still needs timing, packet sizes, directions and destinations to deliver traffic. A smart plug, camera, television or voice assistant may contact predictable services in a distinguishable pattern. An observer who cannot read the message can still infer that a device turned on, streamed video or reported an event.

A Smart Home Is No Castledemonstrated this side channel, andSpying on the Smart Homeextended the analysis with an evaluation of traffic‑shaping defences. The latter paper reported that a constant‑rate defence could protect activity at an overhead of about 40 kbit/s in the tested environment. That figure is not a universal price of privacy. The device mix, threat model, link capacity and required level of concealment all change the trade‑off.

The work corrected a common consumer‑privacy simplification. ‘Encrypted in transit’ can be true while behaviour remains exposed through metadata. A privacy policy that discusses only content can therefore miss a material risk. Defences such as shaping and padding consume bandwidth, energy or time, and the cost can fall on the home, not the manufacturer.

The practical question is not whether traffic can be analysed in the lab, but who can observe a home, which inference is reliable enough to matter, and which actor can change the design. An ISP, a local attacker, a device vendor and a cloud provider have different vantage points. Measurement identifies the leakage; consumer protection needs a decision about defaults, disclosure, remedy and liability.

IoT Inspector became a consumer tool and research infrastructure

IoT Inspector moved smart‑home work from a controlled study to an open‑source tool a user can run on their own network. It let a entity select devices, see the destinations they contact, and, with consent, contribute labelled metadata to research. A 2020 paper documented thousands of users and tens of thousands of devices across many vendors and categories.

Later reports used different numbers—44,956, 54,094, more than 55,000 or around 63,000 devices—because collection windows and reporting conventions differed. Picking the largest figure without a date turns a moving set into false precision. The more important evidence is that the project operated at a scale where user support, labelling quality, privacy and software maintenance became first‑order research issues.

The user‑facing inspection tool also reveals ambiguity. Several cloud customers can share a single domain. Device labelling can be wrong. A connection to a tracker alone does not explain what data moved or what harm occurred. Showing the destination increases visibility without necessarily giving the user an actionable remedy.

The project team’s review discussed incentives, consent, data minimisation and operational maintenance. That matters because an open research platform can create obligations akin to those of a service provider: it holds sensitive evidence, depends on entity understanding, and must keep explaining what its results do and do not prove.

Related studies of selected medical IoT devices, networked games and user perceptions extended the work toward consumer protection. Findings should be tied to the product, version and date tested. Firmware updates, vendor fixes and the deployment environment can change the result.

Machine learning for networks is a full production pipeline, not a standalone classifier

Machine learning entered Feamster’s work through spam and reputation long before the current generative‑AI cycle. The later netml.io programme made the surrounding pipeline more explicit. A network classifier depends on how packets are represented, how labels are obtained, where features are extracted, how fast the model runs, how drift is detected, and what action follows the result.

nPrint represented packets in a standardised bit‑level format, and nPrintML linked the representation to automated modelling. The aim was not to prove that one representation is best for every task, but to make comparisons more reproducible by reducing hidden variation in feature engineering.

Traffic Refinery tackled the cost of producing features at high data rates. An accurate model is operationally weak if feature extraction drops packets, drains the CPU, or returns a result after the decision window has closed. LEAF studied concept drift—the way statistical relationships change as applications, devices and networks evolve. A production model needs criteria for retraining, fallback and per‑environment error monitoring.

CATO combined prediction and system objectives. The NSDI 2025 evaluation reported reducing inference latency by up to 3,600 times and improving loss‑free throughput by up to 3.7 times under specified experimental conditions. These figures are not general production guarantees. Their conceptual importance is that statistical accuracy and packet‑processing cost must be optimised together.

Current work extends this reasoning to low‑cost classification, scheduling, probe selection, field measurement of L4S, and configuration‑error analysis with language models. The 2005 thesis relied on explicit constants; a language model in 2026 might infer a potential problem from examples and text. The newer method can cover cases that are hard to cast as formal rules, but it can substitute plausibility for proof if the recommendation is not checked against observable network state.

Synthetic traffic tries to share useful data without exposing the real network

Real traffic traces are hard to share. They can expose communications, users, devices, institutional structure and proprietary applications. Labelling is expensive, and a trace can go stale quickly. Synthetic data promises an alternative: generate packets and flows that retain useful properties without releasing the original logs.

NetDiffusion used diffusion models with protocol constraints to generate packet‑level traffic. NetSSM added state awareness and multi‑flow modelling. GATEAU, led by Feamster and Francesco Bronzino, frames the wider problem around privacy, collection cost and the scarcity of labelled data. These projects search for a middle ground between random packets that are technically valid but unrealistic, and real traces that cannot be safely distributed.

A generated trace can fail in several ways. It can preserve marginal statistics while losing correlations that a downstream task needs. It can memorise sensitive examples. It can satisfy protocol syntax without reproducing congestion, session state or user behaviour. A classifier trained on it can succeed in testing and fail on production traffic.

2026 work on the privacy–quality trade‑off treats these risks as measurable quantities rather than assuming that ‘synthetic’ means anonymous. Privacy must be tested against plausible attacks, and utility must be tested on the task that will use the data. Synthetic traffic is a research tool, not a certificate that the original network has vanished.

NetMicroscope tests whether a measurement programme can become a business

NetMicroscope is the clearest commercial translation of Feamster’s broadband and machine‑learning research. The company describes him as CEO and co‑founder, with Francesco Bronzino as CTO and co‑founder. University marketing materials say they founded the company in 2021 with a remote team based largely in Chicago and Lyon.

The product hypothesis is that throughput, latency, loss, device state and application signals become more useful when they are combined into an estimate of the quality a user perceives. An operator can know a line is up without knowing why a video session degrades. NetMicroscope says it uses machine learning to infer application experience and identify problems before a complaint.

Verified financial evidence is limited. In January 2024 the George Shultz Innovation Fund awarded the company $200,000 for product, market, team and intellectual‑property development. The company also participated in I‑Corps and the Compass accelerator. These are important early commercial signals, but they are not proof of valuation, total funding, revenue, customer count, retention, market share or profitability.

The university–company boundary deserves ordinary scrutiny, not innuendo. Papers on traffic classification can overlap with a commercial product. Readers need disclosure of affiliations, funding, data access, licences and IP ownership. The supplied record does not show that every BISmark, nPrint or university‑owned code was exclusively transferred to the company.

NetMicroscope therefore supports a modest conclusion: it tests whether years of measurement research can become an operational service customers pay for. The public evidence establishes the founders, product direction and a university grant, but it does not yet support a claim of commercial dominance.

Teaching turned the research thread into an infrastructure curriculum

Feamster’s teaching record follows the same arc as his research. His Georgia Tech courses covered internet architecture, security and next‑generation networks, later adding software‑defined networking. At Princeton, networking met information security and technology policy. His current UChicago courses includeMachine Learning for Computer Systems,Internet Censorship and Online Speech, andSecurity, Privacy, and Consumer Protection.

He co‑authored the sixth edition of Andrew Tanenbaum’sComputer Networksin 2020. His teaching page also credits him with creating the computer networking course for the Georgia Tech Online Master of Science in Computer Science and serving as its founding instructor. The online course extended networking education to an audience beyond a single university cohort, but the founding claim should be kept as his published record states unless a separate programme archive is cited.

The 2026 Quantrell Award provides independent institutional evidence that teaching is central to his work. UChicago’s announcement highlighted open problems, collaborative reasoning and exercises built around real‑world work. Student comments are qualitative, but the award shows the career cannot be reduced to papers and start‑ups.

Institution building widened the audience further. Feamster directed the Center for Information Technology Policy at Princeton, then co‑led UChicago programmes that link network measurement to public policy and data science. Workshops on free and open communications helped build a community where ethics and measurement design could be discussed together.

A fair account should keep collaborators visible. Many systems were implemented or led by students and early‑career researchers. IoT Inspector, the censorship projects, the broadband platforms and the machine‑learning systems involve large, multi‑author teams. A professor can set direction and build institutions without becoming the sole author of every result.

Policy work provides evidence but does not exercise regulatory authority

Feamster’s public‑policy role rests on measurement. UChicago says he has worked with bodies including the Federal Communications Commission and the City of Chicago. The internet equity and broadband projects can supply evidence about access, cost, reliability and performance, but they do not determine subsidy eligibility, regulate prices, or order a provider to change its network.

That boundary matters because technical evidence gains authority when it enters government. A speed test can feed a challenge process, but legal standards are defined elsewhere. An interconnection graph can show utilisation, while contracts and routing decisions remain outside the graph. A censorship dataset can document interference without completing the legal or political analysis.

The AI privacy work extends the same problem into a new ecosystem. A Google Privacy Faculty Award supports research into the risks of third‑party integrations in LLM systems. A user sees a single interface while prompts, context and inferred attributes move across plugins, APIs and remote services. The architecture resembles the smart home: one visible product orchestrates multiple hidden data relationships.

The 2026 publication list includes work on implicit LLM inference, where a model infers sensitive attributes even when the user provides no traditional identifier. That makes data minimisation harder; removing a name or account number does not stop the model from inferring health, political or demographic information from an ordinary interaction.

The policy value lies in showing the limits of the evidence. A model, a dataset or a professor can inform a decision without owning it. Good institutional use requires transparent methods, error estimates, versioned data, and an explicit separation between what a measurement shows and what an authorised body chooses to do.

What this career made visible and what remained hidden

Across routing, spam, broadband, censorship, smart homes and machine learning, Feamster’s projects repeatedly turned a scattered operational problem into an evidence system. rcc tied configurations to constants. RCP gave path selection wider visibility. Reputation systems inferred coordination from metadata. Gateways isolated pieces of broadband performance. Censorship systems compared remote signals. IoT Inspector linked device traffic to user labels. NetML projects tied representation to deployment cost and drift.

The systems did not make the internet fully knowable. A clean configuration check does not remove a physical failure. A reputation score does not prove guilt. A speed measurement does not explain affordability. A DNS anomaly does not identify a government body. Encrypted metadata does not reveal every device action. A synthetic trace does not guarantee privacy. A language model does not become correct because it formulates a coherent diagnosis.

These limits are not a reason to reject measurement; they are a reason to design the surrounding operational system carefully. Useful evidence should show its source, age, scope and uncertainty. High‑impact actions should have a review, a challenge or a rollback. Researchers should show whether a result was reported by paper authors, by an institution, or independently reproduced. A commercial claim should not inherit the authority of an academic publication without separate evidence.

Feamster’s lasting contribution is the repeated construction of that middle layer between opaque infrastructure and consequential decisions. His work helped operators, researchers, users and public institutions ask better questions of systems that were not built to explain themselves. The result is not certainty, but a more disciplined account of what can be observed, what can be inferred, and what still requires judgement.