- Nick Feamster is a professor at the University of Chicago, a measurement researcher, institution-builder and co-founder of NetMicroscope; he seeks to make the hidden behaviours of the Internet usable in responsible decisions.
- His rcc work flagged over 1,000 previously undetected faults across 17 autonomous systems; the Routing Control Platform helped establish a network-wide control model that later became associated with SDN.
- His projects on spam, broadband, censorship and connected devices also revealed the limits of measurement: erroneous reputation, risks of remote probes and exposure through encrypted metadata.
- His current work in machine learning asks whether conclusions can be effective, auditable and safe in production; his contribution lies in collaborative systems that preserve uncertainty.
Rcc: checking the combined configuration before deployment
The 2005 paperDetecting BGP Configuration Faults with Static Analysis, co-authored with Hari Balakrishnan, presented a router configuration checker called rcc. It organised persistent faults into two broad categories. Route validity faults occur when the control plane selects a route that does not correspond to a usable path in the data plane. Visibility faults occur when a usable path exists but the routers that need it do not learn it. These categories linked configuration commands to operator-recognisable consequences.
rcc analysed the configurations of multiple routers and checked network-wide constraints. The paper reported 17 autonomous systems analysed, over 1,000 previously undetected faults, and more than 65 operator downloads. Those figures are historical and declared by the authors. They do not prove that rcc became a universal industry product, and the record does not show how many networks used it sustainably. They do show, however, that the project worked with real configurations and reached operators outside the lab.
The operational significance lies in the type of evidence produced. A checker can flag, before a failure, a configuration relationship that violates an invariant. That differs from a dashboard that registers packet loss after service degradation. The engineer receives a reasoned link between a rule and a class of failure. That result can inform review, testing and discussion among teams that otherwise have only local views.
The limits are equally instructive. rcc could only test the properties encoded by its designers and supported by its analyser. It could not know an undocumented commercial intent, guarantee the absence of a vendor defect, or eliminate a physical failure. A configuration declared sound did not prove the network would never experience a transient problem. A network can pass every written check and still violate a requirement nobody formulated.
That is why rcc sits at the beginning of the profile. The project established the ambition and the restraint that follow. The ambition was to make infrastructure behaviour computable before damage. The restraint was to recall that correctness is always relative to observed inputs and stated properties. Today’s AI systems for network operations face the same test, with an added difficulty: the boundary can become less visible when the model produces a fluent explanation rather than an explicit invariant.
The Internet generally knows what it has done, but cannot explain why
A packet reaches its destination, or it does not. A video call freezes. A domain name returns an unexpected address. A mail server refuses a connection. A connected speaker contacts a remote service at a telling moment. Each of these events leaves traces, but the Internet has no central registry capable of providing a single authoritative explanation. Its behaviour results from separately operated networks, vendor-specific configurations, private peering arrangements, home equipment, application choices and evolving demand.
This arrangement is useful because it prevents a single operator from controlling the whole system. It also makes diagnosis hard. A router can display its own routes without explaining all the consequences of the combined routing policy. A speed test can measure a transfer without isolating the effects of Wi‑Fi, access capacity, latency, interconnection and the application. A censorship probe can record a failed request without identifying the responsible person or institution. A traffic classifier can assign a label without proving it will remain correct once the network has changed.
Feamster’s scientific path reads as a series of attempts to narrow these gaps. The technologies change, but the method remains recognisable. First, choose a hidden behaviour that matters. Then find an observation point where that behaviour produces a measurable signal. Next, build a representation that transforms that signal into a question usable by an operator, a public decision-maker or a user. Finally, test the places where the representation fails. That last step is indispensable: a system that produces a confident answer without showing its limits can make infrastructure less accountable, not more explainable.
Feamster is therefore a subject of digital infrastructure even though he owns no fibre, operates no public autonomous system and directs no hyperscale cloud. His work occupies the information layer around those assets. It influences how routes are verified, abuse identified, broadband quality described, censorship documented and statistical models introduced into network operations. Routers and cables carry the traffic; measurement and analysis determine whether anyone is able to explain what they do.
The strongest narrative is therefore neither a list of awards nor an assertion that a single researcher invented several fields. It is the story of an observability programme that changed entity while keeping the same discipline: distinguishing what was directly observed from what was inferred, and then distinguishing an experimental result from an operational guarantee.
A career, several institutional identities
As of the research cut‑off date, 3 August 2026, the University of Chicago listed Feamster as Neubauer Professor of Computer Science and Faculty Director of Research of the Data Science Institute. His personal page also described him as director of the Network Operations and Internet Security Lab, co‑director of the Internet Innovation Initiative, co‑lead of netml.io and co‑director of the AI and Policy Pillar. A Data Science Institute post published in September 2024 used the title Director of Technology Policy.
These descriptions can coexist because academic responsibilities overlap and evolve; they should not be merged into a permanent label.
These institutional distinctions matter. As a professor, Feamster teaches and conducts research. Through the NOISE Lab and netml.io he works with students and collaborators on routing, measurement, privacy and machine learning. Through the Internet Innovation and Internet Equity projects he helps produce evidence for public and infrastructure decisions. As co‑founder and CEO of NetMicroscope he participates in a private company that seeks to commercialise network quality analytics. His biography also states that he serves as an expert witness in technology litigation.
None of these roles automatically transfers the authority of another: a professor is not a regulator, a startup executive does not turn an academic publication into a client recommendation, and an expert opinion does not constitute a court ruling.
This separation mirrors the substance of his research. Feamster’s best work asks which system holds which evidence and what conclusion that evidence supports. The same caution is warranted in describing him. His current biography credits him with LookSmart’s first crawler and a contribution to the design of Damballa’s first botnet detection algorithm. Those are useful, attributable items of early industry experience. They establish neither precise employment dates, nor sole inventorship, nor financial interests, nor the full product history.
The public record is far richer on professional work than on personal life. It does not allow reliable establishment of his date or place of birth, citizenship, family background, compensation, stake in NetMicroscope, personal investments or wealth. An evidence‑based profile must not turn these absences into assumptions. The career provides enough material without adding the attributes of a celebrity biography that sources do not document.
MIT, a crawler and a thesis on failure before failure
Feamster completed all his higher education at the Massachusetts Institute of Technology, from undergraduate to doctorate. He earned an SB in electrical engineering and computer science in 2000, an MEng in the same field in 2001, and a PhD in computer science in 2005 under Hari Balakrishnan. The thesis title,Proactive Techniques for Correct and Predictable Internet Routing, states the first research programme clearly. Instead of waiting for a routing fault to cause a failure before reconstructing its cause, the network should expose enough structure that important properties can be checked before deployment.
His initial work at LookSmart is a useful prelude, provided it is not exaggerated. A crawler must discover a large graph that changes while it observes it. It encounters broken links, duplicate pages, inconsistent responses and unreachable areas. The crawler did not directly become the later routing systems, and sources do not support that genealogy. The relevant continuity is methodological: a distributed system is not visible from a single local view; it requires systematic collection and an explicit representation of what was found.
The relationship with Damballa added an adversarial version of the same problem. Botnets are designed to hide their members and control. Feamster’s official biography says he helped design the company’s first botnet detection algorithm. The public record does not allow reconstruction of the full team or how later products drew on that work. It shows, however, that early in his career Feamster moved between academic systems research and an operational security company that had to infer malicious coordination from network traces.
The doctoral research was formed in an environment where interdomain routing policies were distributed across equipment and organisations. Operators programmed routers with commands expressing peering and customer relationships, export rules, backup paths and traffic‑engineering preferences. Each configuration could look reasonable in isolation while the combination hid a loop, a black hole or an unwanted route. The problem was not merely a flawed protocol implementation. It was the difficulty of reasoning about a distributed programme assembled from many local policies.
That way of framing the problem became a lasting signature. Feamster often treated the operational system surrounding an algorithm as the real unit of research: configuration files, observation points, data pipelines, interfaces, operator incentives and institutional constraints. The work thus went beyond a theorem or an isolated classifier. It also took on a broader responsibility: as soon as a system touches real operators, households or people living under censorship, deployment and ethics become dimensions of technical quality.
BGP configuration as a distributed programme
The Border Gateway Protocol allows autonomous systems to exchange reachability information while keeping control of their commercial and routing policies. That autonomy partly explains how the Internet can connect networks with different owners and objectives. It also means that the global outcome is designed by no single engineer. Policies compose indirectly through announcements, preferences, filtering and internal route distribution.
Inside an autonomous system the problem remains large. A network can contain hundreds of routers and several mechanisms for distributing external routes internally. A route learned at a border must become visible where it is needed, without necessarily being visible everywhere. The export policy must prevent a customer or peer route from being announced to the wrong neighbour. Backup routes must appear when the primary path fails without creating a loop or persistent oscillation. The operator knows the commercial intent, but the equipment holds the executable fragments.
Feamster’s early work treated those fragments as an analysable programme. The change of perspective was concrete. A router configuration was no longer merely text to be reviewed line by line; it became the input to a network‑wide computation. Correctness could be expressed through invariants: a selected route must lead to a usable forwarding path; a usable path must be visible to the routers that need it; the export policy must preserve the intended relationships; internal distribution must not create persistent inconsistency.
The analogy with software analysis was productive because it shifted the moment of intervention. Classic troubleshooting starts after a symptom appears. Static analysis asks whether a known class of failure is already encoded in the configuration. It does not need to inject traffic or wait for a customer complaint. For a network that carries critical services, moving a fault from the incident queue to the review queue can be more valuable than reducing the post‑failure diagnosis time.
That analogy also has a boundary. A network’s state is not reducible to its configuration: it includes active routes, topology, provider behaviour, transient convergence phases, hardware tables, faulty links and commercial knowledge that may never be formalised. A static checker can be exactly correct about its model while missing a failure outside it. Feamster’s later work returned repeatedly to this difference between a useful representation and the whole operational world.
The Routing Control Platform moved decisions out of individual routers
rcc asked whether a distributed configuration satisfied known constraints. The Routing Control Platform asked a different question: why should every router independently reconstruct the information needed for route selection? Traditional iBGP architectures distributed external routes through a full mesh or route reflectors. The mesh became hard to manage at scale. Reflection reduced that cost but could hide routes, produce unexpected choices and make the result less intelligible.
The RCP paper proposed a logically centralised service that collected external BGP routes and internal topology, chose the routes for each router and communicated those choices through ordinary iBGP. The forwarding devices did not disappear: they continued to forward packets and used a familiar protocol at the interface. What changed was the location of the selection logic and the breadth of the view it had.
“Logically centralised” did not mean a single, fragile physical box. The control service could be replicated and distributed while presenting a consistent decision function. That distinction is also central to the software‑defined networks that followed. A controller can act from a global view without requiring all control processes to run on one machine. The engineering problem becomes one of state consistency, failure recovery and safe interfaces, rather than a binary choice between full centralisation and full distribution.
RCP also respected the installed base. It required neither a new forwarding plane nor the immediate replacement of every router. That deployment choice matters in networks whose equipment, contracts and procedures cannot be changed all at once. A research architecture acquires practical value when it can enter a production environment through an interface operators already know.
The evaluation used real backbone information, but sources do not provide an extensive deployment census. The defensible claim is that RCP demonstrated a workable and influential architecture, not that it replaced internal iBGP across the industry. The NSDI Test of Time Award received in 2015 confirms lasting intellectual significance. It does not prove market adoption and does not give a single paper ownership of all later controllers.
A major contribution to SDN, not the story of a single inventor
Software‑defined networking is often told as a clean break: control moved into software, forwarding became programmable, and a new era began. The actual history is less tidy. Active networks, virtualisation, the 4D architecture, Ethane, RCP, OpenFlow, NOX and other projects addressed different parts of programmability, control separation and global management. Feamster made a substantial contribution to this lineage, but nothing justifies presenting him as the sole inventor of SDN.
RCP contributed one clear architectural idea: routing decisions could be computed by a control service with a broader view and delivered to existing devices. rcc contributed another: a network policy could be checked against invariants. Together these projects helped shift the operational question from “what command is on this router?” to “what behaviour does the complete control system implement?”. That shift is one of the intellectual foundations of programmable networking.
Feamster later co‑authoredThe Road to SDN, which presented the field as an accumulation of ideas rather than a single invention. That historical stance is useful because it resists the founder mythology that often forms around infrastructure technologies. A field becomes possible when multiple research groups, operators, vendors and standards communities solve neighbouring problems and make their solutions deployable.
The 2017 programme paperWhy (and How) Networks Should Run Themselves, co‑authored with Jennifer Rexford, extended the argument from controller architecture to continuous operation. It described closed loops in which high‑level intent guides decisions, telemetry shows effects, and the system adapts. Its title was deliberately provocative. It does not demonstrate that engineers became unnecessary. A self‑tuning network still requires correct objectives, trustworthy telemetry, safe actions, bounded authority and a stop mechanism when evidence is ambiguous.
That agenda today looks less like a distant vision and more like a design problem for AI‑assisted operation. Language models can propose a configuration, summarise an incident and select a tool. They can also invent a cause, misunderstand a policy or act with too much authority. The early routing work supplies a demanding standard: learned recommendations must be surrounded by explicit checks and observable consequences, not accepted because their explanation sounds plausible.
Spam made the network around the message more important than the message
At Georgia Tech the observation target shifted from configuration errors to adversaries. Spam campaigns and botnets were designed to move: compromised machines appeared and disappeared, addresses changed, domains were swapped out and control was distributed. A content signature could recognise a known message, but the delivery system often revealed a more durable pattern.
The 2006 SIGCOMM paperUnderstanding the Network‑Level Behavior of Spammersanalysed, by its own account, over ten million spam messages. It examined the apparent origin of senders, their active duration and the relationship between spam, address space and routing. Its significance does not lie in an eternal percentage. It showed that abuse could be studied as infrastructure: sender population, routes, temporality and source concentration could reveal coordination invisible in the text of messages.
This method offered a practical advantage. Network‑level features are available early in a connection, before a full message is accepted or inspected. They can reduce processing cost and enable action at scale. They can also preserve some content privacy. But the same abstraction creates a risk: a residential prefix can contain both innocent users and compromised machines; shared hosting can serve both legitimate and malicious domains; an address can change owner. Infrastructure reputation is useful only if uncertainty, time‑decay and the possibility of recourse are part of the system.
DNSBL‑based counter‑intelligence work turned the adversary’s defensive behaviour into a signal. Botnet operators queried DNS blocklists to learn whether their machines had been detected. Characteristic query patterns could therefore flag likely botnet members. The idea was elegant because the attacker’s reconnaissance became evidence. It remained heuristic: a query could have a benign cause, and a list of likely bots still needed corroboration before any disruptive action.
SNARE turned several spatial and temporal features available at the start of an SMTP session into a reputation score. Its evaluation reported around 93 % accuracy with a low false‑positive rate. That number describes a particular dataset and threshold, not a permanent property of the system. Spam infrastructure, email providers and adversarial tactics evolve. Operational value therefore requires fast update, calibrated thresholds and the ability to measure errors after deployment.
DNS reputation widened the target from senders to domains. Malicious domains sometimes show different patterns in registration, name servers, addresses and resolution. A model can assign risk before every payload is examined. That logic foreshadows modern machine learning applied to networks: the system infers a category from structured metadata, and its usefulness depends on evasion resistance, calibrated uncertainty and data drift.
Behavioural malware clustering added another layer. Instead of requiring an exact signature for every binary, it grouped samples by communication habits and produced network signatures. The method is useful when the code changes but the infrastructure or protocol stays stable. It can also wrongly cluster unrelated flows if the representation is too coarse. The common thread is therefore not the certainty of a label, but the possibility of converting network behaviour into an operational hypothesis to be checked.
Reputation is an operational decision, not an objective label
Reputation systems bridge measurement and action. They do not merely describe an address or a domain: they influence whether an email is accepted, a connection blocked or an investigation prioritised. Their quality therefore does not depend only on statistical accuracy. It also depends on who receives the score, the cost of a false positive, the correction delay and the ability of the affected entity to understand or challenge the decision.
A compromised residential address illustrates that problem. Blocking the address may reduce a spam campaign but also cut off a user who neither chose the infection nor has the means to diagnose it. A reputation attached for too long can punish the next subscriber. One that is too short lets the attacker start again. The score’s half‑life is therefore an infrastructure and governance decision, not a mere model parameter.
This tension connects the security work to later projects on the connected home and machine learning. In each case metadata is used to infer a hidden state. The closer the inference gets to automatic action, the more its provenance, freshness, threshold and errors must be known. A readable explanation can help, but it does not replace measurement of consequences.
The patent record offers formal, limited evidence. Feamster is listed among several inventors of an attacking‑network detection and response system, assigned to the Georgia Tech Research Corporation. The patent does not prove solo invention, deployment in a product, licensing revenue or the validity of every claim after challenge. It shows that this line of research was also viewed as commercially translatable.
The editorial challenge is not to confuse detection with guilt. Reputation is a constrained estimate. It can be extremely useful if the organisation treats error as a normal state to manage, rather than as an impossible exception. That lesson reappears in censorship measurement, IoT device classification and the AI models of the current phase.
Measuring broadband from the gateway changed the vantage point
Broadband complaints are simple to make and hard to diagnose. “The Internet is slow” can mean a constrained access link, poor Wi‑Fi, a very active home device, congested interconnection, a distant server, application delay or a test unable to generate enough traffic. Measurements from a laptop inherit its software and the local network. Measurements inside the provider’s core do not see what the household experiences.
The gateway approach placed a controlled measurement at the boundary between the home and the access provider. The 2011 SIGCOMM study used longitudinal data from nearly 4 000 gateways across eight ISPs, within a larger deployment of over 4 200 devices. It examined throughput, latency, access technologies and traffic‑shaping mechanisms. The gateway’s value was analytical: it observed the access service while avoiding some of the uncontrolled variation of an ordinary endpoint.
That observation point did not make the answer automatic. The gateway still shares the local environment with devices and Wi‑Fi. The measurement server has its own path and capacity. Tests may interfere with home traffic or run at unrepresentative times. The method improved attribution; it did not create a perfect view of user experience.
BISmark turned this method into a reusable testbed. The 2014 USENIX ATC paper described customised routers and a central system able to deploy measurements and applications. At the time of the paper the platform operated in hundreds of homes across roughly 30 countries and had served researchers from nine institutions. Those numbers are tied to a specific period, but they show infrastructure that went beyond a single dataset.
Maintaining a home testbed is infrastructure work in itself. Hardware must be shipped and supported. Users unplug devices. Firmware ages and clocks drift. Consent must stay understandable. Collection schemas and pipelines must survive changes in networks and applications. The published system thus provides evidence of institution‑building as much as of metrological design.
The broadband programme also shows why method matters for public policy. A result produced by a controlled gateway is not interchangeable with a browser test, an ISP meter or an advertised commercial speed. Each measures a different part of the path. A public decision is more defensible when the measurement position and its limits are visible rather than hidden behind a single speed number.
When access got faster, throughput was no longer enough to explain experience
Early broadband policies often focused on whether the provider delivered the advertised speed. That question remains important, especially when access capacity is scarce. It becomes less explanatory once the connection is fast enough that latency, Wi‑Fi, content distribution and application design dominate the experience.
A study covering more than 5 000 broadband connections examined web bottlenecks and found that, above a study‑specific range, raw access throughput was often no longer the sole limiting factor. A faster subscription might not speed up a page if round‑trip time, entity dependencies or server behaviour determined the load finish. The exact threshold is not universal. The lasting result is that quality becomes multidimensional as access improves.
Reliability adds another dimension. A service can show good median speed yet fail for households because of brief disconnections. A video call, an exam or a remote medical consultation can be interrupted by a short loss that disappears in a monthly average. Longitudinal measurement is necessary because a single test describes neither the frequency, duration nor timing of failures.
Encrypted DNS research revealed a comparable trade‑off. The choice of resolver and protocol can influence latency, privacy and reachability. In the measured panel no single configuration was best for every user and every network. A security or privacy improvement can have a performance cost in one environment but not in another. The result argues against turning a single benchmark into a universal prescription.
Measurements taken during the COVID‑19 pandemic showed how quickly the operating environment can change. Participating ISPs experienced sharp shifts in traffic and interconnection demand, followed by capacity additions and new usage patterns. The findings remained limited to the measured networks but demonstrated why a plan based solely on stable historical averages can fail during a societal shock.
It is here that broadband measurement becomes quality‑of‑experience engineering. Operators must link low‑level signals — throughput, latency, loss, disconnections and interconnection — to application outcomes such as video freezing and conference quality. That linkage later became part of the NetMicroscope product thesis. Academic results do not validate every company claim, but the technical lineage is direct.
Interconnection measurement turned a commercial dispute into a shared‑data problem
The path between a home and an application can cross multiple commercial boundaries. An access provider may exchange traffic directly with a content network, through an Internet exchange point or via a transit provider. Congestion can occur on a single link, in one direction and during a particular period. Public debates about “interconnection” therefore sometimes lump together technically different situations.
The Interconnection Measurement Project asked participating ISPs to install a common tool on their interconnection links. The project reported roughly 2 900 links and utilisation near 31 % at peak times in June 2021, along with capacity increases. Those aggregate results do not prove that every user path was congestion‑free. A link average can mask a short spike, an individual route or a local failure. The project’s value lay in the attempt to give multiple parties a shared method and vocabulary.
A shared measurement system can reduce one kind of disagreement while creating another. Entities must agree on the links included, sampling frequency, protection of private data and publishable summaries. Providers sometimes have commercial reasons to limit disclosure. Researchers need enough detail to scrutinise claims without revealing customer relationships or security‑sensitive topology.
Feamster’s role here is that of a builder of measurement capacity and institutional collaboration. He neither regulated interconnection contracts nor compelled providers to participate. The project illustrates the move from an instrument installed in a home gateway to a shared evidence system with operators. The technical task was inseparable from governance: useful data required the cooperation of the organisations that controlled the links.
Digital equity broadened performance to access, price and reliability
A broadband line can exist in a neighbourhood yet remain unaffordable. A household can subscribe and receive unstable service. A provider can meet the advertised speed while Wi‑Fi, building wiring or device quality prevents the application from working well. Reducing the digital divide to a single coverage map hides these differences.
The University of Chicago’s Internet Equity Initiative combines dimensions such as availability, infrastructure, price, adoption, performance and reliability. Its portals and projects bring network measurements together with demographic data and public policy. Devices placed in Chicago homes provided direct measurements, while public datasets enabled comparisons across geographies and populations.
The method can highlight patterns without explaining every cause. A difference between neighbourhoods may be associated with income, building type, provider competition, subscription tier, hardware or investment history. A demographic overlay supports inquiry; it does not prove the origin of the difference. Public‑facing work must respect the distinction already present in the routing research: a representation makes a question testable, but it does not replace missing variables.
In 2025 the University of Chicago stated that the Internet Innovation collaboration had supplied measurements and analysis to an Illinois broadband plan associated with 175 000 underserved homes, businesses and community anchor sites. That is a significant institutional claim. The work involved the Illinois Broadband Lab, state officials and other partners. It should not be rewritten as if one professor personally connected 175 000 sites, nor as if all planned work was already complete.
The shift from gateway tests to digital equity shows that the measurement audience has changed. An operator can use a gateway result to diagnose a line. A city can use a neighbourhood pattern to target support. A state can integrate validated data into a funding challenge. The more measurement enters a public decision, the more it demands transparent definitions, versioned data and a clear statement of what remains uncertain.
Censorship research made observability a question of human safety
Censorship is hard to measure for the same structural reason routing is hard to explain: the observer sees a result without necessarily seeing the mechanism. A request can fail because of state filtering, a local firewall, DNS malfunction, an offline server, routing instability or measurement error. The environments where measurement is most needed are sometimes those where recruiting a volunteer is most dangerous.
Infranet, published in 2002, first approached censorship as a circumvention problem. Cooperating web servers hid upstream requests inside ordinary HTTP activity and downstream information inside images. Its assumptions belong to an earlier web, but the project established a lasting idea: censorship is also a competition over which traffic patterns can be distinguished from normal communication.
Later work shifted attention from bypassing a block to measuring the block itself. This created a public‑interest possibility: wide, repeatable measurements could document filtering that governments or operators did not disclose. It also created a stiffer ethical boundary. A measurement system can produce publicly useful evidence while imposing risk on the machine or the person generating the signal.
This tension is not secondary in Feamster’s career. It is the clearest case where making the Internet explain itself can harm people who never asked the question. The ethical quality of a censorship measurement therefore depends on target selection, consent, frequency caps, data retention, publication and the plausibility of retaliation, rather than on statistical precision alone.
Encore showed how scale can outrun consent
Encore used cross‑origin requests launched by browsers to test whether certain web resources were reachable from different networks. A participating site could trigger a request in a visitor’s browser, allowing researchers to infer whether the resource was blocked. The design promised large scale without installing specialised software in each country.
The same mechanism produced a serious ethical conflict. Someone visiting a page unrelated to the research could become a measurement point without understanding the experiment. A request to a sensitive domain could be visible to a censor. A third‑party site could appear to probe content it had not chosen. The person bearing the risk was not necessarily the one receiving the data.
The independent paperNo Encore for Encore?argued that the design posed problems of informed consent, transparency, user safety and possible harm to third‑party sites. It also documented exchanges with Feamster and system modifications. That critique should neither be inflated into a finding of scientific misconduct nor reduced to a footnote erased by subsequent work. It identified a real risk in a system designed for a legitimate public goal.
Feamster and Ben Jones later publishedCan Censorship Measurements Be Safe(r)?. The title correctly treats safety as a continuum, not a binary certification. Coverage, repeatability and precision are in tension with the exposure of volunteers, targets and bystanders. A measurement that reaches more networks can become less acceptable if it cannot bound the risk imposed on each entity.
That episode changed the intellectual content of the research. Ethics was no longer an external review added to a technical method. Threat models had to include the people generating the traffic, the organisations hosting the tests and the authorities that might observe them. The lesson applies to any distributed infrastructure measurement, especially when browsers, home devices and AI agents are used as sensors.
Augur, Iris and later systems sought greater reach without hiding the risk
Augur attempted to infer connectivity between distant locations using TCP/IP side channels, without controlling a conventional measurement point at either end. The paper reported validation in nearly 180 countries over 17 days and design choices meant to avoid involving individual users. The method widened geographic coverage, but inference depended on operating‑system behaviour, address selection, filtering asymmetry and statistical assumptions.
Iris focused on DNS manipulation. Repeated queries sent to resolvers could be compared across locations to identify anomalous responses. DNS provides structured evidence, but legitimate systems also cache, redirect, localise and filter. A response difference opens an attribution enquiry; it does not prove that a specific public agency imposed the rule.
Building test lists became another source of bias. A programme that probes only globally‑known political sites can miss local languages and culturally specific topics. In 2018 a project used natural‑language processing and search to find 1 125 sites missing from the largest Chinese blocklist then available. That extension improved study coverage but remained a dated artefact: domains, content and policies change.
GFWeb, published at USENIX Security 2024, studied HTTP and HTTPS filtering by China’s Great Firewall over 20 months. The paper reported 1.02 billion domain tests and hundreds of thousands of registrable domains affected by different mechanisms. Those are measurement volumes, not a census of affected persons. Their value lies in showing that protocol‑specific tests reveal different parts of the system and that a single technique can undercount.
Turkmenistan research reported 15.5 million domains tested, 122 000 censored domains identified and broader overblocking rules potentially affecting millions more domains. The work also explored evasion. Publishing a circumvention technique can help users and teach the censor what to block next. The disclosure timeline and local knowledge are therefore engineering decisions with human consequences.
Feamster’s role in this area is substantial and collective. He has co‑authored systems, contributed to research communities and continues to teach Internet Censorship and Online Speech. He should not be presented as the sole founder of every related observatory, nor should he receive credit for Geneva simply because collaborators and topics overlap. Accurate mapping of papers and roles is better than a blanket inventor label.
Measurement ethics became a component of technical correctness
The censorship work shows a wider principle. A system can be statistically powerful and yet fail technically if it cannot be operated responsibly. Consent, target selection, query frequency, data minimisation and publication strategy determine whether the method can be repeated without unacceptable harm.
This is not about requiring research to eliminate all risk. Complete safety may be impossible when the subject is a hostile state or operator. It is about requiring that risk be explicit, assigned and weighed against the expected public benefit. The most exposed people must not disappear behind a worldwide domain count.
The same principle applies elsewhere. A broadband probe can reveal household habits. An IoT tool can collect device metadata. A reputation score can deny service. A synthetic dataset can memorise the traces it was meant to protect. In each case the measurement system creates new infrastructure, with its own users, privileges and failure modes.
Feamster’s career is all the more instructive because it contains a documented disagreement rather than a smooth run of successes. The Encore controversy shows how a method can be criticised, modified and followed by more explicit safety work. It also shows why later safeguards should not be used to rewrite the original risk. A serious profile can acknowledge the learning while preserving the conflict that made it necessary.
The connected home showed what encryption does not hide
Encryption protects payload content, but the network still needs the timing, size, direction and destination of packets to carry traffic. A plug, a camera, a television or a voice assistant can contact predictable services in a recognisable pattern. An observer unable to read the message can still infer that a device turned on, streamed video or reported an event.
A Smart Home Is No Castledemonstrated this side channel, andSpying on the Smart Homeextended the analysis by evaluating traffic‑shaping defences. The latter paper reported an overhead of roughly 40 kilobytes per second for a constant‑rate defence in the tested scenario. That number is not a universal price of privacy. The device mix, threat model, link capacity and desired concealment level change the trade‑off.
The work corrected a common consumer‑protection simplification. “Encrypted in transit” can be true while behaviour remains visible through metadata. A privacy policy that addresses only content can therefore miss an important risk. Padding and shaping defences consume bandwidth, energy or latency, and their cost may be borne by the household rather than the manufacturer.
The practical question is not whether traffic analysis is possible in the lab. It is who can observe the home, which inference is reliable enough to count and which party can change the design. An ISP, a local adversary, a manufacturer and a cloud provider have different views. The measurement identifies the leak; consumer protection requires a decision about defaults, transparency, redress and accountability.
IoT Inspector became both a consumer tool and a research infrastructure
IoT Inspector moved the connected‑home work from a controlled study to an open‑source tool that users could run on their own network. A entity could select devices, observe contacted destinations and, with consent, contribute labelled metadata for research. The 2020 paper documented thousands of users and tens of thousands of devices from many categories and vendors.
Later reports used different totals — 44 956, 54 094, over 55 000 or about 63 000 devices — because collection windows and counting conventions varied. Picking the highest number without a date would turn an evolving dataset into false precision. The important point is that the project had reached a scale where user support, label quality, privacy and software maintenance became first‑order research problems.
A user‑facing inspection tool also exposes ambiguity. A domain can be shared by multiple cloud customers. A device label can be wrong. A connection to a tracker does not by itself explain what data flowed or what harm resulted. Showing a destination improves visibility without necessarily giving the user a means of action.
The team’s retrospective addressed incentives, consent, data minimisation and operational upkeep. That reflection matters because an open research platform can assume obligations comparable to those of a service provider. It holds sensitive evidence, depends on entity understanding and must keep explaining what its findings do and do not establish.
Related studies on sampled medical IoT devices, connected toys and user perceptions extended the work toward consumer protection. Every result must stay tied to the product, version and date tested. A firmware update, a vendor fix or a different deployment can change the result.
Network machine learning is a pipeline, not an isolated classifier
Machine learning entered Feamster’s work through spam and reputation, well before the current generative AI cycle. The netml.io programme then made explicit the full chain surrounding a model. A network classifier depends on packet representation, label acquisition, where features are extracted, computation time, drift detection and the action triggered.
nPrint represented packets at the bit level in a standardised format, while nPrintML paired that representation with automated modelling. The goal was not to prove that one representation fitted all tasks. It was to make comparisons more reproducible by reducing hidden changes in feature engineering.
Traffic Refinery addressed the cost of producing those features at high throughput. A precise model remains bad in operation if the extraction drops packets, exhausts the CPU or returns its answer after the decision window. LEAF studied concept drift — the change in statistical relationships as applications, devices and networks evolve. A model in production needs retraining criteria, rollback and per‑environment error tracking.
CATO combined predictive and system goals. Its NSDI 2025 evaluation reported, under precise experimental conditions, up to 3 600 × lower inference latency and up to 3.7 × higher loss‑free throughput. Those numbers are not general production guarantees. Their conceptual interest is to show that statistical accuracy and packet‑processing cost must be optimised together.
Current work extends that logic to low‑cost classification, queueing, probe selection, field measurement of L4S and configuration‑error analysis via language models. The 2005 thesis relied on explicit invariants; a 2026 language model can infer a likely problem from examples and text. The new method can cover cases that are hard to formalise. It also risks replacing proof with plausibility if the recommendation is not checked against an observable network state.
Synthetic traffic seeks to share useful data without exposing the real network
Real traffic traces are hard to share. They can reveal communications, users, equipment, organisational structure and proprietary applications. Labels are expensive and a trace ages quickly. Synthetic data promises an alternative: generate packets and flows that preserve useful properties without publishing the original records.
NetDiffusion used diffusion models with protocol constraints to generate packet‑level traffic. NetSSM added state and multi‑flow awareness. GATEAU, led by Feamster and Francesco Bronzino, frames the problem more broadly around privacy, collection cost and label sparsity. These projects seek a middle ground between technically valid but unrealistic random packets and real traces that cannot be safely shared.
A generated trace can still fail in several ways. It can preserve marginal statistics while losing the correlations needed for a downstream task. It can memorise sensitive examples. It can respect protocol syntax without reproducing congestion, session state or human behaviour. A classifier trained on it can look good and fail on production traffic.
The 2026 work on privacy‑quality trade‑offs treats these risks as measurable entities instead of assuming “synthetic” means anonymous. That is the right level of rigour. Privacy must be tested against plausible attacks, and utility on the task for which the data will be used. Synthetic traffic is a research instrument, not a certificate that the original network has disappeared.
NetMicroscope tests whether the measurement programme can become a business
NetMicroscope is the clearest commercial translation of Feamster’s broadband and machine‑learning research. The company lists Feamster as CEO and co‑founder, and Francesco Bronzino as CTO and co‑founder. University commercialisation records indicate they founded it in 2021 with a distributed team centred on Chicago and Lyon.
The product thesis is that throughput, latency, loss, device state and application signals become more useful when combined into a quality‑of‑experience estimate. An operator can know a line is up without understanding why a video session degraded. NetMicroscope claims to use machine learning to infer application experience and identify a problem before the complaint.
Verified financial evidence remains limited. In January 2024 the George Shultz Innovation Fund granted the company $200 000 for product, market, team and IP development. It also participated in I‑Corps and the Compass accelerator. Those are early, meaningful commercial signals. They do not constitute proof of valuation, total funding, revenue, customer count, retention, market share or profitability.
The university‑company boundary deserves ordinary scrutiny, without insinuation. Papers on traffic classification can overlap with a commercial product. Readers need to know affiliations, funding, data access, licences and IP. The record does not show that the full BISmark, nPrint or university codebase was transferred exclusively to the company.
The conclusion must therefore remain modest: NetMicroscope tests whether years of metrology research can become an operational service for which customers will pay. The public evidence establishes the founders, the product direction and university support. It does not yet permit talk of commercial dominance.
Teaching turned the research arc into an infrastructure curriculum
Feamster’s teaching followed the same progression as his research. At Georgia Tech his courses covered Internet architecture, security and next‑generation networks, then software‑defined networking. At Princeton the subjects combined networks, information security and technology policy. His current Chicago courses include Machine Learning for Computer Systems, Internet Censorship and Online Speech, and Security, Privacy, and Consumer Protection.
In 2020 he co‑authored the sixth edition of Andrew Tanenbaum’sComputer Networks. His teaching page also credits him with creating and being the first instructor of the Georgia Tech Online Master of Science in Computer Science networking course. That online course extended training far beyond a campus cohort, but the founding claim must remain tied to his teaching file until a programme archive is cited separately.
The 2026 Quantrell Award provides independent institutional evidence of the central role of teaching. The University of Chicago announcement highlighted open problems, collaborative reasoning and exercises inspired by real work. Student comments are qualitative, but the award shows that the career is not reducible to papers and a startup.
Institution‑building widened the audience further. Feamster directed Princeton’s Center for Information Technology Policy, then contributed to Chicago programmes that link network measurement, public policy and data science. Workshops around free and open communications helped create a community where ethics and measurement design could be debated together.
A fair presentation must keep collaborators visible. Many systems were implemented or led by students and junior researchers. IoT Inspector, the censorship projects, the broadband testbeds and the machine‑learning systems have large, multi‑author teams. A professor can set direction and build institutions without becoming the sole author of every result.
Public‑policy work supplies evidence without exercising regulatory authority
Feamster’s public role is rooted in measurement. The University of Chicago says he has worked with organisations including the Federal Communications Commission and the city of Chicago. The Internet Equity and broadband projects can produce evidence on availability, price, reliability and performance. They do not decide grant eligibility, set rates or order a provider to change its network.
That limit matters because technical evidence acquires particular authority when it enters administration. A speed test can inform a challenge proceeding, but the legal criteria are set elsewhere. An interconnection map can clarify utilisation, but contracts and routing decisions remain outside the map. A censorship dataset can document disruption without completing the legal or policy analysis.
Current AI privacy research extends the same problem into a new ecosystem. A Google Privacy Faculty Award supports work on third‑party integrations of language model systems. The user can see a single interface while their queries, context and inferred attributes flow between extensions, APIs and remote services. The structure recalls the connected home: a visible product coordinates multiple hidden data relationships.
The 2026 publication list includes work on implicit inference by LLMs, where a model deduces sensitive attributes even without a conventional user‑supplied identifier. Data minimisation becomes harder. Removing names or account numbers does not stop a model from inferring medical, political or demographic information from an ordinary interaction.
The policy value of this work lies in the visibility of evidence boundaries. A model, a dataset or a professor can inform a decision without owning it. Good institutional use demands transparent methods, error estimates, versioned data and an explicit separation between what the measurement shows and what an authorised body decides to do with it.
What the career made visible — and what remains hidden
From routing to spam, from broadband to censorship, from the connected home to machine learning, Feamster’s projects turned diffuse operational problems into evidence systems. rcc linked configurations to invariants. RCP gave a broader view to route selection. Reputation systems inferred coordination from metadata. Gateways isolated components of broadband performance. Censorship systems compared remote signals. IoT Inspector linked device traffic to user labels. NetML projects combined representation, deployment cost and drift.
These systems did not make the Internet fully knowable. A passed configuration check does not eliminate physical failure. A reputation score does not establish guilt. A speed measurement does not explain price. A DNS anomaly does not identify a public agency. Encrypted metadata does not reveal every device action. A synthetic trace does not guarantee privacy. A language model does not become correct because it produces a coherent diagnosis.
Those limits do not justify discarding measurement. They require carefully designing the operational system around it. Useful evidence should expose its source, age, scope and uncertainty. High‑impact actions should allow review, recourse or rollback. Researchers should state whether a result is reported by a paper, by an institution or independently reproduced. A commercial claim must not inherit the authority of an academic publication without distinct evidence.
Feamster’s lasting contribution is having built, repeatedly, that intermediate layer between opaque infrastructure and consequential decisions. His work helped operators, researchers, users and public institutions ask better questions of systems that were not designed to explain themselves. The result is not certainty. It is a more disciplined account of what can be observed, what can be inferred and what still requires judgement.

