{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T02:24:07Z","timestamp":1768530247333,"version":"3.49.0"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319565484","type":"print"},{"value":"9783319565491","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-56549-1_2","type":"book-chapter","created":{"date-parts":[[2017,3,29]],"date-time":"2017-03-29T05:39:05Z","timestamp":1490765945000},"page":"15-28","source":"Crossref","is-referenced-by-count":2,"title":["Measuring and Analyzing Trends in Recent Distributed Denial of Service Attacks"],"prefix":"10.1007","author":[{"given":"An","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aziz","family":"Mohaisen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wentao","family":"Chang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Songqing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,3,30]]},"reference":[{"key":"2_CR1","unstructured":"A ddos attack could cost $1 million before mitigation even starts, October 2013. http:\/\/bit.ly\/MUXadv"},{"key":"2_CR2","unstructured":"NetAcuity and NetAcuity Edge IP Location Technology, February 2014. http:\/\/www.digitalelement.com\/"},{"key":"2_CR3","unstructured":"Akella, A., Bharambe, A., Reiter, M., Seshan, S.: Detecting DDoS Attacks on ISP Networks. In: ACM SIGMOD\/PODS MPDS (2003)"},{"key":"2_CR4","unstructured":"Bailey, M., Cooke, E., Jahanian, F., Nazario, J., Watson, D., et al.: The internet motion sensor-a distributed blackhole monitoring system. In: Proceeding of NDSS (2005)"},{"key":"2_CR5","unstructured":"Casado, M., Garfinkel, T., Cui, W., Paxson, V., Savage, S.: Opportunistic measurement: extracting insight from spurious traffic. In: Proceeding of ACM Hotnets (2005)"},{"key":"2_CR6","doi-asserted-by":"crossref","unstructured":"Chang, W., Mohaisen, A., Wang, A., Chen, S.: Measuring botnets in the wild: some new trends. In: Proceeding of ACM ASIA CCS (2015)","DOI":"10.1145\/2714576.2714637"},{"key":"2_CR7","doi-asserted-by":"crossref","unstructured":"Chen, Y., Hwang, K., Ku, W.S.: Collaborative detection of DDoS attacks over multiple network domains. IEEE TPDS (2007)","DOI":"10.1109\/TPDS.2007.1111"},{"key":"2_CR8","unstructured":"Cisco: Cisco Catalyst 6500 Series Intrusion Detection System, February 2014. http:\/\/bit.ly\/1hspyy9"},{"key":"2_CR9","doi-asserted-by":"crossref","unstructured":"Feinstein, L., Schnackenberg, D., Balupari, R., Kindred, D.: Statistical approaches to DDoS attack detection and response. In: DARPA Information Survivability Conference and Exposition (2003)","DOI":"10.1109\/DISCEX.2003.1194894"},{"key":"2_CR10","doi-asserted-by":"crossref","unstructured":"Huang, Y., Geng, X., Whinston, A.B.: Defeating DDoS attacks by fixing the incentive chain. ACM ToIT 1 (2007)","DOI":"10.1145\/1189740.1189745"},{"key":"2_CR11","doi-asserted-by":"crossref","unstructured":"Info Security Magazine: Spamhaus suffers largest ddos attack in history - entire internet affected, March 2013. http:\/\/bit.ly\/1bfx3ZH","DOI":"10.1016\/S1353-4858(13)70045-X"},{"key":"2_CR12","unstructured":"Ioannidis, J., Bellovin, S.M.: Implementing pushback: router-based defense against DDoS attacks. In: Proceeding of NDSS (2002). https:\/\/www.cs.columbia.edu\/~smb\/papers\/pushback-impl.pdf"},{"key":"2_CR13","unstructured":"Jin, S., Yeung, D.: A covariance analysis model for DDoS attack detection. IEEE ICC (2004)"},{"key":"2_CR14","unstructured":"Kang, M.S., Lee, S.B., Gligor, V.D.: The crossfire attack. In: Proceeding of IEEE S&P (2013)"},{"key":"2_CR15","doi-asserted-by":"crossref","unstructured":"Keromytis, A.D., Misra, A.D., Rubenstein, D.: SOS: an architecture for mitigating DDoS attacks. IEEE JSAC (2004)","DOI":"10.1109\/JSAC.2003.818807"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Lee, K., Kim, J., Kwon, K.H., Han, Y., Kim, S.: DDoS attack detection method using cluster analysis. Expert systems with applications (2008)","DOI":"10.1016\/j.eswa.2007.01.040"},{"key":"2_CR17","unstructured":"Li, J., Mirkovic, J., Wang, M., Reiher, P., Zhang, L.: Save: source address validity enforcement protocol. In: Proceeding of IEEE ICCC (2002)"},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Li, M.: Change trend of averaged Hurst parameter of traffic under DDOS flood attacks. Computers and Security (2006)","DOI":"10.1016\/j.cose.2005.11.007"},{"key":"2_CR19","doi-asserted-by":"crossref","unstructured":"Mao, Z.M., Sekar, V., Spatscheck, O., van der Merwe, J., Vasudevan, R.: Analyzing large DDoS attacks using multiple data sources. In: Proceeding of ACM SIGCOMM LSAD (2006)","DOI":"10.1145\/1162666.1162675"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Mirkovic, J., Prier, G., Reiher, P.: Attacking DDoS at the source. In: Proceeding of IEEE ICNP, November 2002","DOI":"10.1109\/ICNP.2002.1181418"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"Mohaisen, A., Alrawi, O., Larson, M., McPherson, D.: Towards a methodical evaluation of antivirus scans and labels. In: Information Security Applications (2014)","DOI":"10.1007\/978-3-319-05149-9_15"},{"issue":"2","key":"2_CR22","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1145\/1132026.1132027","volume":"24","author":"D Moore","year":"2006","unstructured":"Moore, D., Shannon, C., Brown, D.J., Voelker, G.M., Savage, S.: Inferring internet denial-of-service activity. ACM TOCS 24(2), 115\u2013139 (2006)","journal-title":"ACM TOCS"},{"key":"2_CR23","doi-asserted-by":"crossref","unstructured":"Nadji, Y., Antonakakis, M., Perdisci, R., Dagon, D., Lee, W.: Beheading hydras: performing effective botnet takedowns. In: Proceeding of ACM SIGSAC, November 2013","DOI":"10.1145\/2508859.2516749"},{"key":"2_CR24","doi-asserted-by":"crossref","unstructured":"Pang, R., Yegneswaran, V., Barford, P., Paxson, V., Peterson, L.: Characteristics of internet background radiation. In: Proceeding of ACM IMC (2004)","DOI":"10.1145\/1028788.1028794"},{"key":"2_CR25","doi-asserted-by":"crossref","unstructured":"Park, K., Lee, H.: On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law Internets. In: Proceeding of ACM SIGCOMM (2001)","DOI":"10.1145\/383059.383061"},{"key":"2_CR26","doi-asserted-by":"crossref","unstructured":"Schuchard, M., Mohaisen, A., Kune, D.F., Hopper, N., Kim, Y., Vasserman, E.Y.: Losing control of the internet: using the data plane to attack the control plane. In: Proceeding of NDSS (2011)","DOI":"10.1145\/1866307.1866411"},{"key":"2_CR27","unstructured":"Sekar, V., Duffield, N., Spatscheck, O., van der Merwe, J., Zhang, H.: Lads: large-scale automated DDoS detection system. In: Proceeding of USENIX ATC (2006)"},{"key":"2_CR28","doi-asserted-by":"crossref","unstructured":"Stavrou, A., Keromytis, A.D.: Countering DoS attacks with stateless multipath overlays. In: Proceeding of ACM CCS (2005)","DOI":"10.1145\/1102120.1102153"},{"key":"2_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-642-04444-1_3","volume-title":"Computer Security \u2013 ESORICS 2009","author":"A Studer","year":"2009","unstructured":"Studer, A., Perrig, A.: The coremelt attack. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 37\u201352. Springer, Heidelberg (2009). doi: 10.1007\/978-3-642-04444-1_3"},{"issue":"1","key":"2_CR30","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/14799850802611446","volume":"5","author":"N Thomas","year":"2009","unstructured":"Thomas, N.: Cyber security in East Asia: governing anarchy. Asian Secur. 5(1), 3\u201323 (2009)","journal-title":"Asian Secur."},{"key":"2_CR31","unstructured":"Vaughan-Nichols, S.J.: Worst DDoS attack of all time hits french site, February 2014. http:\/\/zd.net\/1kFDurZ"},{"key":"2_CR32","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1145\/1095809.1095825","volume":"5","author":"M Vrable","year":"2005","unstructured":"Vrable, M., Ma, J., Chen, J., Moore, D., Vandekieft, E., Snoeren, A.C., Voelker, G.M., Savage, S.: Scalability, fidelity, and containment in the potemkin virtual honeyfarm. ACM SIGOPS 5, 148\u2013162 (2005)","journal-title":"ACM SIGOPS"},{"key":"2_CR33","doi-asserted-by":"crossref","unstructured":"Walfish, M., Vutukuru, M., Balakrishnan, H., Karger, D., Shenke, S.: DDoS defense by offense. In: Proceeding of SIGCOMM (2006)","DOI":"10.1145\/1159913.1159948"},{"key":"2_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1007\/978-3-319-20550-2_11","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Wang","year":"2015","unstructured":"Wang, A., Mohaisen, A., Chang, W., Chen, S.: Capturing DDoS attack dynamics behind the scenes. In: Almgren, M., Gulisano, V., Maggi, F. (eds.) DIMVA 2015. LNCS, vol. 9148, pp. 205\u2013215. Springer, Heidelberg (2015). doi: 10.1007\/978-3-319-20550-2_11"},{"key":"2_CR35","doi-asserted-by":"crossref","unstructured":"Wang, A., Mohaisen, A., Chang, W., Chen, S.: Delving into internet DDoS attacks by botnets: characterization and analysis. In: Proceeding of IEEE DSN (2015)","DOI":"10.1109\/DSN.2015.47"},{"key":"2_CR36","doi-asserted-by":"crossref","unstructured":"Wustrow, E., Karir, M., Bailey, M., Jahanian, F., Huston, G.: Internet background radiation revisited. In: Proceeding of ACM IMC (2010)","DOI":"10.1145\/1879141.1879149"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Xu, K., Zhang, Z.L., Bhattacharyya, S.: Profiling internet backbone traffic: behavior models and applications. In: ACM SIGCOMM CCR. No. 4 (2005)","DOI":"10.1145\/1080091.1080112"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Yaar, A., Perrig, A., Song, D.: SIFF: a stateless internet flow filter to mitigate DDoS flooding attacks. In: Proceeding of IEEE S&P (2004)","DOI":"10.1109\/SECPRI.2004.1301320"},{"key":"2_CR39","doi-asserted-by":"crossref","unstructured":"Yaar, A., Perrig, A., Song, D.: StackPi: new packet marking and filtering mechanisms for DDoS and IP spoofing defense. IEEE JSAC (2006)","DOI":"10.1109\/JSAC.2006.877138"},{"key":"2_CR40","first-page":"961","volume":"5","author":"CC Zou","year":"2005","unstructured":"Zou, C.C., Gong, W., Towsley, D., Gao, L.: The monitoring and early detection of internet worms. IEEE\/ACM TON 5, 961\u2013974 (2005)","journal-title":"IEEE\/ACM TON"}],"container-title":["Lecture Notes in Computer Science","Information Security Applications"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-56549-1_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,4]],"date-time":"2020-10-04T11:40:01Z","timestamp":1601811601000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-56549-1_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319565484","9783319565491"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-56549-1_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}