REVIEW 3 major objections 4 minor 54 references
At least 21% of reflection DDoS attacks come from more than one spoofing source, and TTL clustering at anycast honeypots can prove it.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-02 00:54 UTC pith:7GHUJN2A
load-bearing objection The 21% 'lower bound' is not actually a lower bound as stated—the frequency-weighted estimator can overestimate—but the measurement apparatus is real and worth engaging. the 3 major comments →
Spoofer or Spoofers? Estimating a Lower Bound on the Number of DRDoS Sources Using Anycast Honeypots
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The central claim is that the number of networks actively sending spoofed traffic in a DRDoS attack can be lower-bounded without any router cooperation, using only which anycast honeypots see the traffic and how the TTL values cluster at each site. To separate real source differences from normal path fluctuation, the paper derives a per-honeypot threshold j_h from the measured spread of TTL values observed by geographically diverse probes: half the 95th percentile of per-probe TTL ranges, rounded up. On top of this, it defines two estimators—a minimum interval cover, which places the fewest possible source intervals over the observed TTLs, and a frequency-weighted interval cover, which cente
What carries the argument
The machinery is an anycast honeypot network: 32 sites spread over six continents announcing one shared anycast address, so spoofed amplifier requests are drawn to the site closest to their true origin. The IP TTL field supplies the measurement signal, giving a quantized hop-count estimate for each packet. The algorithmic core is the interval cover: given a set of TTL values seen at a honeypot and the calibrated tolerance j_h, the minimum interval cover greedily places the smallest set of intervals of radius j_h that covers every value, while the frequency-weighted variant starts each interval at the most frequent uncovered TTL. The number of intervals across all honeypots is the lower-bound
Load-bearing premise
The method assumes a single spoofing source's TTL values will fluctuate no more than the per-honeypot threshold calibrated from ordinary Internet probes; if attacker-controlled paths vary more—due to congestion-driven load balancing, routing changes, or deliberate TTL tweaks within the allowed ranges—the count can be inflated and the 'lower bound' property breaks.
What would settle it
A controlled experiment with known ground truth: have one source send spoofed traffic through deliberately unstable or load-balanced paths, with per-request TTL randomization inside the allowed 30-hop window, and check whether either estimator reports more than one source. If it systematically over-reports in this setting, the claim that the estimators give lower bounds under realistic attack conditions is refuted.
If this is right
- At least 21.0% of observed DRDoS attacks involve multiple spoofing sources, making single-source attribution models unsafe as a default.
- The frequency-weighted estimator gives tighter bounds (closer to true counts in simulation) at a tiny overestimation risk, so it is the better choice when defense planning wants a realistic picture rather than a strict floor.
- Attack scale does not predict source count: packet count shows no meaningful correlation and duration only a weak one, so multi-source attacks occur at both small and large volumes.
- The method runs in real time as soon as an attack is observed, with no protocol changes, router support, or long BGP manipulation campaigns, unlike previous traceback proposals.
- Defenders should expect that knocking out one presumed source is often not enough; coordinated, distributed mitigation is needed.
Where Pith is reading between the lines
- Inference: Because 21.0% is a lower bound and the method deliberately undercounts when sources share path lengths or use TTL values within one threshold, the true share of multi-source attacks is likely higher; defense investments in distributed mitigation are therefore more justified than the headline number alone suggests.
- Inference: The same TTL-clustering logic could be combined with other passive fingerprints—packet sizes, protocol mix, scanning behavior—to move from a lower bound toward a point estimate, since the paper's raw material is already per-packet metadata.
- Inference: The observed blind spot of attackers randomizing TTL values within the allowed 30-hop window suggests an arms race: if the method is used operationally, attackers may adapt by varying TTLs more subtly, and detectors would need to look at joint distributions across honeypots rather than single TTL values.
- Inference: The stability of the calibrated thresholds across a 99-day gap implies the estimator could be run continuously as an early-warning index; a sudden jump in inferred source count across many honeypots could flag a new spoofing service or botnet before attribution tools catch up.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a methodology to estimate a lower bound on the number of spoofing sources involved in DRDoS attacks. The authors deploy a 32-node anycast honeypot testbed that emulates amplifiers, collect attack traffic over 287 days (843K + 2.93M attacks), and propose two interval-cover estimators based on TTL values: a minimum interval cover and a frequency-weighted interval cover. Per-honeypot TTL stability thresholds are calibrated from RIPE Atlas probing (12,502 probes). The main empirical claim is that 'at least 21.0%' of attacks originate from more than one spoofing source, based on the frequency-weighted estimator. A simulation study with 469 Atlas probes from non-filtering networks is used to evaluate estimator accuracy, with the minimum cover never overestimating and the frequency-weighted estimator overestimating in 6 of 82,312 simulations.
Significance. If the lower-bound property holds, the 21.0% multi-source estimate is a valuable empirical finding that challenges the common single-spoofer assumption and has implications for DDoS attribution and defense. The study's strengths include the large, real-world dataset; a public measurement infrastructure; machine-checkable algorithms; a repeated calibration experiment demonstrating threshold stability; and a conservative minimum-cover estimator that is never observed to overestimate. The paper is clearly written and the methodology is explained in detail. The potential significance is high for the DDoS measurement community, provided the headline claim is properly supported.
major comments (3)
- [Abstract, §5.3, Table 1] The headline 'at least 21.0%' is computed with the frequency-weighted interval cover (Algorithm 2), which the paper's own Table 1 shows can overestimate: in 6 of 82,312 simulations (0.007%), including 3 of 441 single-source simulations (~0.7%). With ~3.77M attacks in the combined dataset, even a 0.7% false-positive rate among single-source attacks would misclassify tens of thousands of attacks as multi-source. The strict lower bound is provided only by the minimum interval cover (Algorithm 1), which never overestimates in the simulations. The paper does not report the minimum-cover multi-source percentage, so 'at least 21.0%' is not demonstrated. Please report the minimum-cover percentage and rephrase the central claim as a point estimate with a small upward bias.
- [§4.2 and §5.5] The thresholds j_h are calibrated from RIPE Atlas probes under normal traffic, and the simulation in §5.5 deliberately does not trigger congestion-driven load balancing. If real attacker traffic experiences stronger path variability (e.g., high-rate ECMP, route flaps, or TTL manipulation within the 30-hop ranges), j_h is too tight and both estimators can overcount sources, breaking the lower-bound property. The paper acknowledges this but provides no sensitivity analysis (e.g., varying j_h across the observed distribution) to quantify how the 21.0% figure depends on this assumption. This is load-bearing for the central claim.
- [§4.3] The estimator sums per-honeypot lower bounds, so a single spoofing source whose traffic is anycast-routed to multiple honeypots (4.4% of /24 prefixes per [21]) is counted multiple times. The manuscript notes this but does not correct or bound its effect on the final estimate. For a claim of a lower bound, this overcounting should be addressed, e.g., by a conservative correction or an explicit statement of which estimator is robust to it.
minor comments (4)
- [§5.2, Figures 2–3] The shaded 'allowed TTL ranges' are not defined in the captions; please state explicitly that they correspond to 34–64, 98–128, and 225–255.
- [§4.2] The sentence 'By favoring underestimation, our estimator remains conservative' is not true for the frequency-weighted estimator; please qualify this claim to refer specifically to the minimum interval cover.
- [Figure 4] Add numeric percentages for the minimum cover estimator to allow direct comparison with the 21.0% figure and to support the major comment about the strict lower bound.
- [Abstract and §5.3] The abstract uses 'at least 21.0%' while §5.3 says 'identified that 21.0%... originated'; align the wording with the actual statistical guarantee of each estimator.
Circularity Check
No significant circularity: the estimation pipeline is empirical and self-contained; the 'at least 21.0%' wording is a statistical-support issue, not a circular derivation.
full rationale
The derivation chain is not circular. The per-honeypot TTL stability threshold j_h = ceil(P95({delta_{h,a}})/2) is fitted to RIPE Atlas calibration measurements (§4.2), but the 21.0% result is not that fitted threshold renamed; it is produced by applying two generic interval-cover algorithms (Algorithms 1 and 2, §4.3) to observed attack TTL values. The minimum cover's lower-bound property follows from the stated assumption that a source's TTL values vary by at most j_h, and the paper explicitly acknowledges that the frequency-weighted algorithm "may yield overlapping intervals" and is not minimal (§4.3.2), so its higher count is a point estimate rather than a guaranteed lower bound. That is a correctness/interpretation concern about the headline 'at least 21.0%', not a circularity: the number is not forced by construction. The RIPE Atlas-based validation in §5.5 does reuse the same measurement platform used for calibration, and the paper itself notes it does not trigger congestion-driven load balancing; this limits how strongly the simulation can validate the lower-bound assumption, but it does not make the attack-data estimate equal to the calibration input. The self-citations ([11], [20], [21]) are empirical, parameter-free measurements of anycast convergence and catchment stability used as supporting evidence, not uniqueness theorems or fitted ansatze imported to force the conclusion; they are load-bearing only in the weak sense of bounding multi-site routing effects. Overall, no step reduces to its own input by construction.
Axiom & Free-Parameter Ledger
free parameters (4)
- Per-honeypot TTL stability threshold j_h =
1 for 26/32 honeypots, 0 for 3, 2 for 3
- 95th percentile choice =
95
- Division by two and rounding up =
ceil(P95/2)
- 30-hop allowed TTL range =
34-64, 98-128, 225-255
axioms (5)
- domain assumption A single spoofing source produces TTL values at a honeypot that vary by at most j_h.
- domain assumption TTL variability observed from RIPE Atlas probes is representative of TTL variability from actual spoofing sources.
- domain assumption Path instability caused by congestion-driven load balancing is not significant for attack traffic.
- domain assumption Attackers generally do not randomize TTL values inside the allowed 30-hop ranges.
- domain assumption Each source /24 prefix has affinity to a single anycast site, with only 4.4% observed multi-homing.
read the original abstract
DDoS attacks remain a significant threat, with distributed reflection denial-of-service (DRDoS) attacks being particularly difficult to trace back to their sources. To better understand attacker behavior and deployment patterns, we present a novel approach for estimating a lower bound on the number of networks involved in generating spoofed traffic. Our approach leverages a global deployment of anycast amplification honeypots that attract requests from topologically nearby sources. Using this infrastructure, we develop two estimators based on the set of honeypots receiving spoofed traffic and on variations in observed TTL values, while accounting for natural path instability. Analyzing 287 days of amplification attacks, we find that at least 21.0% originate from multiple network locations, indicating that attackers frequently distribute spoofing activity across networks. Our findings suggest that combating spoofing requires coordinated and distributed defenses, and inform the design of future attribution techniques.
Figures
Reference graph
Works this paper leans on
-
[1]
Todd Arnold, Jia He, Weifan Jiang, Matt Calder, Italo Cunha, Vasileios Giotsas, and Ethan Katz-Bassett. 2020. Cloud Provider Connectivity in the Flat Internet. InProceedings of the ACM Internet Measurement Conference (IMC ’20). Association for Computing Machinery, Virtual Event, USA, 230–246. doi:10.1145/3419394. 3423613
doi:10.1145/3419394 2020
-
[2]
Michael Backes, Thorsten Holz, Christian Rossow, Teemu Rytilahti, Milivoj Simeonovski, and Ben Stock. 2016. On the Feasibility of TTL-Based Filtering for DRDoS Mitigation. InResearch in Attacks, Intrusions, and Defenses, Fabian Monrose, Marc Dacier, Gregory Blanc, and Joaquin Garcia-Alfaro (Eds.). Springer, Paris, France, 303–322. doi:10.1007/978-3-319-45719-2_14
-
[3]
A. Belenky and N. Ansari. 2003. IP Traceback With Deterministic Packet Marking. IEEE Communications Letters7, 4 (April 2003), 162–164. doi:10.1109/LCOMM. 2003.811200
arXiv 2003
-
[4]
Bellovin, Marcus D
Steven M. Bellovin, Marcus D. Leech, and Tom Taylor. 2003.ICMP Traceback Messages. Internet Draft draft-ietf-itrace-04. Internet Engineering Task Force. https://datatracker.ietf.org/doc/draft-ietf-itrace-04
2003
-
[5]
Hal Burch and Bill Cheswick. 2000. Tracing Anonymous Packets to Their Approx- imate Source. In14th Systems Administration Conference (LISA 2000). USENIX, New Orleans, LA, USA, 319–327. https://www.usenix.org/legacy/event/lisa2000/ full_papers/burch/burch_html/
2000
-
[6]
Gomes, Artur Ziviani, and Ronaldo M
André Castelucio, Antônio Tadeu A. Gomes, Artur Ziviani, and Ronaldo M. Salles
-
[7]
Andre Castelucio, Artur Ziviani, and Ronaldo M. Salles. 2009. An AS-level Overlay Network for IP Traceback.IEEE Network23, 1 (Jan. 2009), 36–41. doi:10. 1109/MNET.2009.4804322
arXiv 2009
-
[8]
Center for Applied Internet Data Analysis (CAIDA). 2026. Spoofer. https: //www.caida.org/projects/spoofer/
2026
-
[9]
Cormen, Charles E
Thomas H. Cormen, Charles E. Leiserson, Ronald L. Rivest, and Clifford Stein. 2009.Introduction to Algorithms(3rd ed.). The MIT Press, Cambridge, MA, USA
2009
-
[10]
de Vries, Salm¯an Aljamm¯az, and Roland van Rijswijk-Deij
Wouter B. de Vries, Salm¯an Aljamm¯az, and Roland van Rijswijk-Deij. 2020. Global- Scale Anycast Network Management with Verfploeter. In2020 IEEE/IFIP Network Operations and Management Symposium (NOMS). IEEE, Budapest, Hungary, 1–9. doi:10.1109/NOMS47738.2020.9110449
arXiv 2020
-
[11]
Bernhard Degen, Mattijs Jonker, Roland van Rijswijk-Deij, and Raffaele Sommese
-
[12]
Amogh Dhamdhere and Constantine Dovrolis. 2010. The Internet Is Flat: Model- ing the Transition from a Transit Hierarchy to a Peering Mesh. InProceedings of the 6th International COnference (CoNEXT ’10). Association for Computing Machinery, Philadelphia, PA, USA, 1–12. doi:10.1145/1921168.1921196
arXiv 2010
-
[13]
N. G. Duffield and M. Grossglauser. 2000. Trajectory Sampling for Direct Traffic Observation. InProceedings of the Conference on Applications, Technologies, Archi- tectures, and Protocols for Computer Communication (SIGCOMM ’00). Association for Computing Machinery, Stockholm, Sweden, 271–282. doi:10.1145/347059. 347555
-
[14]
P. Ferguson and D. Senie. 2000. Network Ingress Filtering: Defeating Denial of Service Attacks Which Employ IP Source Address Spoofing. RFC 2827 (Best Current Practice). doi:10.17487/RFC2827
-
[15]
Ferreira, and Ethan Katz-Bassett
Osvaldo Fonseca, Ítalo Cunha, Elverton Fazzion, Wagner Meira, Brivaldo Junior, Ronaldo A. Ferreira, and Ethan Katz-Bassett. 2020. Tracking Down Sources of Spoofed IP Packets. In2020 IFIP Networking Conference (Networking). IEEE, Paris, France, 208–216. https://ieeexplore.ieee.org/document/9142717
arXiv 2020
-
[16]
Petros Gigis, Mark James Handley, and Stefano Vissicchio. 2024. Bad Packets Come Back, Worse Ones Don’t. InProceedings of the ACM SIGCOMM 2024 Con- ference (ACM SIGCOMM ’24). Association for Computing Machinery, Sydney, NSW, Australia, 311–326. doi:10.1145/3651890.3672259
arXiv 2024
-
[18]
Harm Griffioen, Kris Oosthoek, Paul van der Knaap, and Christian Doerr. 2021. Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks. InPro- ceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS ’21). Association for Computing Machinery, Virtual Event, Republic of Korea, 940–954. doi:10.1145/3460120.3484747
arXiv 2021
-
[19]
Tiago Heinrich, Rafael R. Obelheiro, and Carlos A. Maziero. 2021. New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks. In Passive and Active Measurement, Oliver Hohlfeld, Andra Lutu, and Dave Levin (Eds.). Springer, Virtual Event, 269–283. doi:10.1007/978-3-030-72582-2_16
-
[20]
Remi Hendriks, Bernhard Degen, Bas Palinckx, Raffaele Sommese, and Roland van Rijswijk-Deij. 2025. An Empirical Evaluation of Longitudinal Anycast Catchment Stability. InPassive and Active Measurement, Cecilia Testart, Roland van Rijswijk-Deij, and Burkhard Stiller (Eds.). Springer, Virtual Event, 389–401. doi:10.1007/978-3-031-85960-1_16
-
[21]
Remi Hendriks, Mattijs Jonker, Roland van Rijswijk-Deij, and Raffaele Sommese
-
[22]
Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C
Raphael Hiesgen, Marcin Nawrocki, Marinho Barcellos, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doerr, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, and kc claffy. 2024. The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Asses...
arXiv 2024
-
[23]
1989.Traceroute(8) Manual Page
Van Jacobson. 1989.Traceroute(8) Manual Page. https://ftp.math.utah.edu/pub/ misc/traceroute.html
1989
-
[24]
Cheng Jin, Haining Wang, and Kang G. Shin. 2003. Hop-Count Filtering: An Effective Defense Against Spoofed DDoS Traffic. InProceedings of the 10th ACM Conference on Computer and Communications Security (CCS ’03). Association for Computing Machinery, Washington D.C., USA, 30–41. doi:10.1145/948109.948116
arXiv 2003
-
[26]
Daniel Kopp, Christoph Dietzel, and Oliver Hohlfeld. 2021. DDoS Never Dies? An IXP Perspective on DDoS Amplification Attacks. InPassive and Active Mea- surement, Oliver Hohlfeld, Andra Lutu, and Dave Levin (Eds.). Springer, Virtual Event, 284–301. doi:10.1007/978-3-030-72582-2_17
-
[27]
Lukas Krämer, Johannes Krupp, Daisuke Makita, Tomomi Nishizoe, Takashi Koide, Katsunari Yoshioka, and Christian Rossow. 2015. AmpPot: Monitoring and Defending Against Amplification DDoS Attacks. InResearch in Attacks, Intrusions, and Defenses, Herbert Bos, Fabian Monrose, and Gregory Blanc (Eds.). Springer, Kyoto, Japan, 615–636. doi:10.1007/978-3-319-26362-5_28
-
[28]
Johannes Krupp, Michael Backes, and Christian Rossow. 2016. Identifying the Scan and Attack Infrastructures Behind Amplification DDoS Attacks. InPro- ceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS ’16). Association for Computing Machinery, Vienna, Austria, 1426–
2016
-
[29]
Johannes Krupp, Mohammad Karami, Christian Rossow, Damon McCoy, and Michael Backes. 2017. Linking Amplification DDoS Attacks to Booter Services. InResearch in Attacks, Intrusions, and Defenses, Marc Dacier, Michael Bailey, Michalis Polychronakis, and Manos Antonakakis (Eds.). Springer, Atlanta, GA, USA, 427–449. doi:10.1007/978-3-319-66332-6_19
-
[30]
Johannes Krupp and Christian Rossow. 2021. BGPeek-a-Boo: Active BGP-based Traceback for Amplification DDoS Attacks. In2021 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, Vienna, Austria, 423–439. doi:10.1109/ EuroSP51992.2021.00036 Bernhard Degen, Bas Palinckx, Mattijs Jonker, Roland van Rijswijk-Deij, and Raffaele Sommese
arXiv 2021
-
[31]
Henry C. J. Lee, Vrizlynn L. L. Thing, Yi Xu, and Miao Ma. 2003. ICMP Traceback with Cumulative Path, an Efficient Solution for IP Traceback. InInformation and Communications Security, Sihan Qing, Dieter Gollmann, and Jianying Zhou (Eds.). Springer, Huhehaote, China, 124–135. doi:10.1007/978-3-540-39927-8_12
-
[32]
Franziska Lichtblau, Florian Streibelt, Thorben Krüger, Philipp Richter, and Anja Feldmann. 2017. Detection, Classification, and Analysis of Inter-Domain Traffic with Spoofed Source IP Addresses. InProceedings of the 2017 Internet Measurement Conference (IMC ’17). Association for Computing Machinery, London, United Kingdom, 86–99. doi:10.1145/3131365.3131367
arXiv 2017
-
[33]
David Moore, Colleen Shannon, Douglas J. Brown, Geoffrey M. Voelker, and Ste- fan Savage. 2006. Inferring Internet Denial-of-Service Activity.ACM Transactions on Computer Systems24, 2 (May 2006), 115–139. doi:10.1145/1132026.1132027
arXiv 2006
-
[34]
Ayman Mukaddam, Imad Elhajj, Ayman Kayssi, and Ali Chehab. 2014. IP Spoofing Detection Using Modified Hop Count. In2014 IEEE 28th International Conference on Advanced Information Networking and Applications (AINA). IEEE, Victoria, BC, Canada, 512–516. doi:10.1109/AINA.2014.62
-
[35]
Schmidt, and Matthias Wählisch
Marcin Nawrocki, Mattijs Jonker, Thomas C. Schmidt, and Matthias Wählisch
-
[36]
Arman Noroozian, Maciej Korczyński, Carlos Hernandez Gañan, Daisuke Makita, Katsunari Yoshioka, and Michel van Eeten. 2016. Who Gets the Boot? Analyzing Victimization by DDoS-as-a-Service. InResearch in Attacks, Intrusions, and De- fenses, Fabian Monrose, Marc Dacier, Gregory Blanc, and Joaquin Garcia-Alfaro (Eds.). Springer, Paris, France, 368–389. doi:1...
-
[37]
Vern Paxson. 2001. An Analysis of Using Reflectors for Distributed Denial-of- Service Attacks.ACM SIGCOMM Computer Communication Review31, 3 (July 2001), 38–47. doi:10.1145/505659.505664
arXiv 2001
-
[38]
RIPE Network Coordination Center. 2025. RIPE Atlas. https://www.ripe.net/ analyse/internet-measurements/ripe-atlas/
2025
-
[39]
Christian Rossow. 2014. Amplification Hell: Revisiting Network Protocols for DDoS Abuse. InNDSS Symposium 2014. Internet Society, San Diego, CA, USA, 1–15. https://www.ndss-symposium.org/ndss2014/ndss-2014-programme/ amplification-hell-revisiting-network-protocols-ddos-abuse/
2014
-
[40]
Stefan Savage, David Wetherall, Anna Karlin, and Tom Anderson. 2000. Practical Network Support for IP Traceback.ACM SIGCOMM Computer Communication Review30, 4 (Aug. 2000), 295–306. doi:10.1145/347057.347560
arXiv 2000
-
[41]
Snoeren, Craig Partridge, Luis A
Alex C. Snoeren, Craig Partridge, Luis A. Sanchez, Christine E. Jones, Fabrice Tchakountio, Stephen T. Kent, and W. Timothy Strayer. 2001. Hash-Based IP Traceback.ACM SIGCOMM Computer Communication Review31, 4 (Aug. 2001), 3–14. doi:10.1145/964723.383060
arXiv 2001
-
[42]
Dawn Xiaodong Song and A. Perrig. 2001. Advanced and Authenticated Marking Schemes for IP Traceback. In2001 IEEE INFOCOM, Vol. 2. IEEE, Anchorage, AK, USA, 878–886 vol.2. doi:10.1109/INFCOM.2001.916279
arXiv 2001
-
[43]
Robert Stone. 2000. CenterTrack: An IP Overlay Network for Tracking DoS Floods. In9th USENIX Security Symposium (USENIX Security ’00). USENIX, Denver, CO, USA. https://www.usenix.org/conference/9th-usenix-security-symposium/ centertrack-ip-overlay-network-tracking-dos-floods
2000
-
[44]
Minho Sung, Jun Xu, Jun Li, and Li Li. 2008. Large-Scale IP Traceback in High- Speed Internet: Practical Techniques and Information-Theoretic Foundation. IEEE/ACM Transactions on Networking16, 6 (Dec. 2008), 1253–1266. doi:10.1109/ TNET.2007.911427
arXiv 2008
-
[45]
Thomas, Richard Clayton, and Alastair R
Daniel R. Thomas, Richard Clayton, and Alastair R. Beresford. 2017. 1000 Days of UDP Amplification DDoS Attacks. In2017 APWG Symposium on Electronic Crime Research (eCrime). IEEE, Scottsdale, AZ, USA, 79–84. doi:10.1109/ECRIME. 2017.7945057
arXiv 2017
-
[46]
Vultr. 2026. 32 Cloud Data Center Regions. https://www.vultr.com/features/ datacenter-regions/
2026
-
[47]
Wu and Dan Massey
S. Wu and Dan Massey. 2001.Intention-Driven ICMP Trace-Back. Internet Draft draft-wu-itrace-intention-02. Internet Engineering Task Force. https: //datatracker.ietf.org/doc/draft-wu-itrace-intention
2001
-
[48]
A. Yaar, A. Perrig, and D. Song. 2003. Pi: A Path Identification Mechanism to Defend against DDoS Attacks. In2003 IEEE Symposium on Security and Privacy (SP). IEEE, Berkeley, CA, USA, 93–107. doi:10.1109/SECPRI.2003.1199330
Pith/arXiv arXiv 2003
- [49]
-
[50]
2012.P0f README
Michal Zalewski. 2012.P0f README. https://github.com/p0f/p0f/blob/master/ docs/README A Ethical considerations A.1 Amplification honeypots In operating amplification honeypots, it is important to carefully consider any potential harm they may cause. Prior to the deploy- ment of the honeypots, the study protocol was submitted for review and received approv...
2012
-
[434]
doi:10.1145/3487552.3487835
-
[1437]
doi:10.1145/2976749.2978293
-
[2012]
doi:10.1016/j.comcom.2010.08.010
Intra-Domain IP Traceback Using OSPF.Computer Communications35, 5 (March 2012), 554–564. doi:10.1016/j.comcom.2010.08.010
-
[2021]
InProceedings of the 21st ACM Internet Measurement Conference (IMC ’21)
The Far Side of DNS Amplification: Tracing the DDoS Attack Ecosystem from the Internet Core. InProceedings of the 21st ACM Internet Measurement Conference (IMC ’21). Association for Computing Machinery, Virtual Event, 419–
-
[2024]
InProceed- ings of the 2024 Applied Networking Research Workshop (ANRW ’24)
An Empirical Characterization of Anycast Convergence Time. InProceed- ings of the 2024 Applied Networking Research Workshop (ANRW ’24). Association for Computing Machinery, Vancouver, BC, Canada, 23–30. doi:10.1145/3673422. 3674890
-
[2026]
IEEE Transactions on Network and Service Management23 (2026), 814–823
Load-Balancing Versus Anycast: A First Look at Operational Challenges. IEEE Transactions on Network and Service Management23 (2026), 814–823. doi:10. 1109/TNSM.2025.3636785
arXiv 2026
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.