IRTF MAPRG, IETF-126 (Vienna)

Note-takers: Mirja,

IRTF maprg agenda for IETF-126 (Vienna)

Date: Thursday, 23 July 2026, Session IV 16:30-18:30

Full client with Video:
https://meetecho.ietf.org/conference/?group=maprg&short=maprg&item=1

Room: Grand Klimt Hall 2

IRTF Note Well: https://irtf.org/policies/irtf-note-well-2019-11.pdf

Agenda

Dave: How do you identify the bots -> AS number
Dave: Do they try to hide actively? -> mostly saw traffic from specific
IPs
Tim Chown: how to make your page still searchable?
Raghav: did you try different top level domains? -> not yet

Firefox has many e2e metrics publicly available

Mirja: Is ECN total? -> yes, about 20% or ECN traffic sees CE

Robert Kisteleki: Is IPv6 number of connection or valume? -> number of
connection but we can look at volume as well; also per country might be
interesting

Lars Eggert: are these just bit flips? -> we also saw this outside of
trace route and multiplease bits would need to be flipped at once

Robert: we have data until 2010 -> online data is not complete? -> we
will check and yes network is growing

Ben Schwartz: Are there loop? Is looking at TTLs still valuable? ->
Don't think it's loop but TTL is still value; might only be a bug

Lorenzo: Did you also measure IPv6? -> we didn't; wouldn't assume a bit
difference and traceroute wouldn't work anymore this way -> okay you
could measure but you didn't

Ben: Is the DNS resolver co-located to the first ground hop? -> no
public information where resolvers are located; probably are co-located;
mostly used public resolvers? -> Ben: are public resolvers co-located
with peering points? Would be interested to learn more about space-x DNS
topology and behvaior

Lorenzo: we see anycast resolvers here

Lars: Nice methodology but you might a find a lot of small servers that
are rarly used; that's created a bias and that's why it doesn't match up
with our data; we can work on this and the Morzilla data

Lorenzo: I second that. might not be comparable to actually expierence.
Focus on servers that are intented for use. These DoQ servers might be
something different. E.g. we didn't implement DoH2. Look at high
performance resolvers and compare there.

Erik Nygen: Do you confirm these are first resolvers? because primary
use case for DoQ is authoritative servers.

Thom Vauhgan quickly presented and Dave asked some questions