{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T22:33:24Z","timestamp":1780526004223,"version":"3.54.1"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031649530","type":"print"},{"value":"9783031649547","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,10,15]],"date-time":"2024-10-15T00:00:00Z","timestamp":1728950400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,10,15]],"date-time":"2024-10-15T00:00:00Z","timestamp":1728950400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-64954-7_2","type":"book-chapter","created":{"date-parts":[[2024,10,14]],"date-time":"2024-10-14T10:02:17Z","timestamp":1728900137000},"page":"25-44","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["DDoS Mitigation Dilemma Exposed: A\u00a0Two-Wave Attack with\u00a0Collateral Damage of\u00a0Millions"],"prefix":"10.1007","author":[{"given":"Lumin","family":"Shi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Devkishen","family":"Sisodia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingwei","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alberto","family":"Dainotti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter","family":"Reiher","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,10,15]]},"reference":[{"key":"2_CR1","unstructured":"Akamai: Prolexic Routed (2021). https:\/\/www.akamai.com\/us\/en\/products\/security\/prolexic-solutions.jsp"},{"key":"2_CR2","doi-asserted-by":"crossref","unstructured":"Alcoz, A.G., Strohmeier, M., Lenders, V., Vanbever, L.: Aggregate-based congestion control for pulse-wave DDoS defense. In: Proceedings of the ACM SIGCOMM 2022 Conference (2022)","DOI":"10.1145\/3544216.3544263"},{"key":"2_CR3","unstructured":"Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., et\u00a0al.: Understanding the Mirai botnet. In: 26th USENIX Security Symposium (USENIX Security 2017) (2017)"},{"key":"2_CR4","unstructured":"BGPKIT: BGP Data Analysis Tool Kit (2021). https:\/\/github.com\/bgpkit"},{"key":"2_CR5","unstructured":"Buitinck, L., et al.: API design for machine learning software: experiences from the scikit-learn project. In: ECML PKDD Workshop: Languages for Data Mining and Machine Learning (2013)"},{"key":"2_CR6","unstructured":"CAIDA: State of IP Spoofing (2019). https:\/\/spoofer.caida.org\/summary.php"},{"key":"2_CR7","unstructured":"CAIDA: Routeviews Prefix to AS mappings Dataset for IPv4 and IPv6 (2021). https:\/\/www.caida.org\/catalog\/datasets\/routeviews-prefix2as\/"},{"key":"2_CR8","unstructured":"CAIDA: The CAIDA AS Organizations Dataset (2021). http:\/\/www.caida.org\/data\/as-organizations"},{"key":"2_CR9","unstructured":"CAIDA: The CAIDA AS Relationships Dataset (2021). http:\/\/www.caida.org\/data\/active\/as-relationships"},{"key":"2_CR10","unstructured":"Census Bureau: Census Bureau QuickFacts (2022). https:\/\/web.archive.org\/web\/20220107213155\/https:\/\/www.census.gov\/quickfacts\/fact\/table\/losangelescitycalifornia,US\/VET605219"},{"key":"2_CR11","unstructured":"Cimpanu, C.: \u2018Carpet-bombing\u2019 DDoS attack takes down South African ISP for an entire day (2019). https:\/\/www.zdnet.com\/article\/carpet-bombing-ddos-attack-takes-down-south-african-isp-for-an-entire-day\/"},{"key":"2_CR12","unstructured":"Cloudflare: Cloudflare Magic Transit (2021). https:\/\/www.cloudflare.com\/magic-transit"},{"key":"2_CR13","unstructured":"Corin, R.D., Costanzo, A., Callegati, F., Siracusa, D.: Methods and techniques for dynamic deployability of software-defined security services. CoRR (2020)"},{"key":"2_CR14","unstructured":"Gartner: DDoS Mitigation Services Reviews and Ratings (2021). https:\/\/www.gartner.com\/reviews\/market\/ddos-mitigation-services"},{"key":"2_CR15","unstructured":"Guirguis, M., Bestavros, A., Matta, I.: Exploiting the transients of adaptation for ROQ attacks on internet resources. In: Proceedings of the 12th IEEE International Conference on Network Protocols (ICNP) (2004)"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Hassidim, A., Raz, D., Segalov, M., Shaqed, A.: Network utilization: the flow view. In: IEEE INFOCOM (2013)","DOI":"10.1109\/INFCOM.2013.6566937"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"H\u00f8iland-J\u00f8rgensen, T., et al.: The express data path: fast programmable packet processing in the operating system kernel. In: Proceedings of the 14th International Conference on Emerging Networking EXperiments and Technologies (2018)","DOI":"10.1145\/3281411.3281443"},{"key":"2_CR18","unstructured":"Imperva: DDoS Protection for Networks (2021). https:\/\/www.imperva.com\/products\/infrastructure-ddos-protection-services\/"},{"key":"2_CR19","unstructured":"Kang, M.S., Lee, S.B., Gligor, V.D.: The crossfire attack. In: 2013 IEEE Symposium on Security and Privacy (2013)"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Ke, Y.M., Chen, C.W., Hsiao, H.C., Perrig, A., Sekar, V.: CICADAS: congesting the internet with coordinated and decentralized pulsating attacks. In: ASIA CCS 2016 (2016)","DOI":"10.1145\/2897845.2897866"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Kumari, W., McPherson, D.: Remote triggered black hole filteringwith unicast reverse path forwarding (uRPF). Technical report (2009)","DOI":"10.17487\/rfc5635"},{"key":"2_CR22","doi-asserted-by":"crossref","unstructured":"Kuzmanovic, A., Knightly, E.W.: Low-rate TCP-targeted denial of service attacks: the shrew vs. the mice and elephants. In: SIGCOMM (2003)","DOI":"10.1145\/863955.863966"},{"key":"2_CR23","unstructured":"Liu, Z., et al.: Jaqen: A high-performance switch-native approach for detecting and mitigating volumetric DDoS attacks with programmable switches. In: USENIX Security Symposium (2021)"},{"key":"2_CR24","doi-asserted-by":"publisher","first-page":"938","DOI":"10.1109\/TIFS.2022.3152406","volume":"17","author":"N Lu","year":"2022","unstructured":"Lu, N., Zhang, J., Liu, X., Shi, W., Ma, J.: STOP: a service oriented internet purification against link flooding attacks. IEEE Trans. Inf. Forensics Secur. 17, 938\u2013953 (2022). https:\/\/doi.org\/10.1109\/TIFS.2022.3152406","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2_CR25","doi-asserted-by":"crossref","unstructured":"Luckie, M., Beverly, R., Koga, R., Keys, K., Kroll, J.A., Claffy, K.: Network hygiene, incentives, and regulation: deployment of source address validation in the internet. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS) (2019)","DOI":"10.1145\/3319535.3354232"},{"key":"2_CR26","unstructured":"Luo, X., Chang, R.K.: On a new class of pulsing denial-of-service attacks and the defense. In: Proceedings of the Network and Distributed System Security Symposium (2005)"},{"key":"2_CR27","unstructured":"Majkowski, M.: The real cause of large DDoS - IP Spoofing (2018). https:\/\/blog.cloudflare.com\/the-root-cause-of-large-ddos-ip-spoofing\/"},{"key":"2_CR28","unstructured":"MANRS: MANRS for Network Operators (2022). https:\/\/www.manrs.org\/isps"},{"key":"2_CR29","doi-asserted-by":"crossref","unstructured":"Marques, P., Sheth, N., Raszuk, R., Greene, B., Mauch, J., McPherson, D.: Dissemination of flow specification rules. Technical report (2009)","DOI":"10.17487\/rfc5575"},{"key":"2_CR30","doi-asserted-by":"crossref","unstructured":"Miano, S., Bertrone, M., Risso, F., Bernal, M.V., Lu, Y., Pi, J.: Securing Linux with a faster and scalable iptables. In: SIGCOMM CCR (3) (2019)","DOI":"10.1145\/3371927.3371929"},{"key":"2_CR31","doi-asserted-by":"crossref","unstructured":"Nawrocki, M., Blendin, J., Dietzel, C., Schmidt, T.C., W\u00e4hlisch, M.: Down the black hole: Dismantling operational practices of BGP blackholing at IXPs. In: Proceedings of the Internet Measurement Conference, IMC 2019 (2019)","DOI":"10.1145\/3355369.3355593"},{"key":"2_CR32","unstructured":"NETCOUT: Arbor Cloud DDoS Protection Services (2021). https:\/\/www.netscout.com\/product\/arbor-cloud"},{"key":"2_CR33","unstructured":"NETSCOUT: NETSCOUT\u2019s 14th Annual Worldwide Infrastructure Security Report (2020). https:\/\/www.netscout.com\/report"},{"key":"2_CR34","unstructured":"Neustar: UltraDDoS Protect Mitigation Service (2021). https:\/\/www.home.neustar\/resources\/product-literature\/ddos-mitigation-service-product-literature"},{"key":"2_CR35","unstructured":"Nvidia: Cumulus Linux 4.2 User Guide (2022). https:\/\/web.archive.org\/web\/20220124023544\/https:\/\/docs.nvidia.com\/networking-ethernet-software\/cumulus-linux-42\/System-Configuration\/Netfilter-ACLs\/#hardware-limitations-on-number-of-rules"},{"key":"2_CR36","unstructured":"Ookla: Speedtest by Ookla Global Fixed and Mobile Network Performance Map Tiles (2021). https:\/\/github.com\/teamookla\/ookla-open-data"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Park, J., Nyang, D., Mohaisen, A.: Timing is almost everything: realistic evaluation of the very short intermittent DDoS attacks. In: Annual Conference on Privacy, Security and Trust (PST) (2018)","DOI":"10.1109\/PST.2018.8514210"},{"key":"2_CR38","unstructured":"PeeringDB: PeeringDB. https:\/\/www.peeringdb.com (2021)"},{"key":"2_CR39","unstructured":"Radware: Cloud DDoS Protection Service (2021). https:\/\/www.radware.com\/products\/cloud-ddos-services2"},{"key":"2_CR40","doi-asserted-by":"crossref","unstructured":"Rasti, R., Murthy, M., Weaver, N., Paxson, V.: Temporal lensing and its application in pulsing denial-of-service attacks. In: 2015 IEEE Symposium on Security and Privacy (2015)","DOI":"10.1109\/SP.2015.19"},{"key":"2_CR41","doi-asserted-by":"crossref","unstructured":"Shan, H., Wang, Q., Pu, C.: Tail attacks on web applications. In: ACM SIGSAC Conference on Computer and Communications Security (CCS) (2017)","DOI":"10.1145\/3133956.3133968"},{"key":"2_CR42","doi-asserted-by":"crossref","unstructured":"Smith, J.M., Schuchard, M.: Routing around congestion: defeating ddos attacks and adverse network conditions via reactive BGP routing. In: IEEE Symposium on Security and Privacy (2018)","DOI":"10.1109\/SP.2018.00032"},{"key":"2_CR43","doi-asserted-by":"crossref","unstructured":"Sommese, R., et al.: MAnycast2: using anycast to measure anycast. In: Proceedings of the ACM Internet Measurement Conference. IMC 2020 (2020)","DOI":"10.1145\/3419394.3423646"},{"key":"2_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-642-04444-1_3","volume-title":"Computer Security \u2013 ESORICS 2009","author":"A Studer","year":"2009","unstructured":"Studer, A., Perrig, A.: The Coremelt attack. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 37\u201352. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-04444-1_3"},{"key":"2_CR45","unstructured":"Sun, H., Lui, J.C.S., Yau, D.K.Y.: Defending against low-rate TCP attacks: dynamic detection and protection. In: Proceedings of the 12th IEEE International Conference on Network Protocols, ICNP 2004 (2004)"},{"key":"2_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, M., et al.: Poseidon: mitigating volumetric DDoS attacks with programmable switches. In: Proceedings of NDSS (2020)","DOI":"10.14722\/ndss.2020.24007"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-64954-7_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,14]],"date-time":"2024-10-14T10:03:46Z","timestamp":1728900226000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-64954-7_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,15]]},"ISBN":["9783031649530","9783031649547"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-64954-7_2","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,15]]},"assertion":[{"value":"15 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hong Kong","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 October 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy +","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"180","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"50","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}