{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:45:41Z","timestamp":1740123941541,"version":"3.37.3"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,9,12]],"date-time":"2022-09-12T00:00:00Z","timestamp":1662940800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,9,12]],"date-time":"2022-09-12T00:00:00Z","timestamp":1662940800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Telecommun Syst"],"published-print":{"date-parts":[[2022,11]]},"DOI":"10.1007\/s11235-022-00950-x","type":"journal-article","created":{"date-parts":[[2022,9,12]],"date-time":"2022-09-12T18:03:40Z","timestamp":1663005820000},"page":"417-430","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Hotlist and stale content update mitigation in local databases for DNS flooding attacks"],"prefix":"10.1007","volume":"81","author":[{"given":"Tasnuva","family":"Mahjabin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8549-6794","authenticated-orcid":false,"given":"Yang","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tieshan","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohsen","family":"Guizani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,12]]},"reference":[{"issue":"12","key":"950_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1177\/1550147717741463","volume":"13","author":"T Mahjabin","year":"2017","unstructured":"Mahjabin, T., Xiao, Y., Sun, G., & Jiang, W. (2017). A survey of distributed denial-of-service attack, prevention, and mitigation techniques. International Journal of Distributed Sensor Networks, 13(12), 1\u201333. https:\/\/doi.org\/10.1177\/1550147717741463","journal-title":"International Journal of Distributed Sensor Networks"},{"issue":"4","key":"950_CR2","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1504\/IJSNET.2022.122583","volume":"38","author":"W Jing","year":"2022","unstructured":"Jing, W., Wang, P., & Zhang, N. (2022). A false deletion data tracking method based on Fisher information distance in wireless sensor networks. International Journal of Sensor Networks, 38(4), 282\u2013292.","journal-title":"International Journal of Sensor Networks"},{"issue":"1","key":"950_CR3","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1504\/IJSNET.2020.109720","volume":"34","author":"H Cheng","year":"2020","unstructured":"Cheng, H., Liu, J., Xu, T., Ren, B., Mao, J., & Zhang, W. (2020). Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks. International Journal of Sensor Networks, 34(1), 56\u201369.","journal-title":"International Journal of Sensor Networks"},{"key":"950_CR4","unstructured":"Gao, J., & Xiao, Y. (2012). ProtoGENI DoS\/DDoS security tests and experiments. In Proceedings of first GENI research and educational experiment workshop (GREE12), in conjunction with GENI GEC 13. March 13\u201315, 2012, Los Angeles, CA, USA."},{"key":"950_CR5","unstructured":"Wikipedia: 2016 Dyn cyberattack. Last Retrieved February 12, 2020, from https:\/\/en.wikipedia.org\/wiki\/2016_Dyn_cyberattack"},{"key":"950_CR6","unstructured":"Greene, T. (2020). How the Dyn DDoS attack unfolded, a massive botnet patched together and deployed around the world swamped regional DNS data centers. Network World. Last Retrieved February 12, 2020, from https:\/\/www.networkworld.com\/article\/3134057\/how-the-dyn-ddos-attack-unfolded.html"},{"key":"950_CR7","unstructured":"Woolf, N. (2022). DDoS attack that disrupted internet was largest of its kind in history, experts say. Last Retrieved July 6, 2022, from https:\/\/www.theguardian.com\/technology\/2016\/oct\/26\/ddos-attack-dyn-mirai-botnet"},{"key":"950_CR8","unstructured":"Naraine, R. Massive DDoS attack hit DNS root servers. Last Retrieved July 6, 2022, from https:\/\/www.cs.cornell.edu\/people\/egs\/beehive\/rootattack.html"},{"key":"950_CR9","doi-asserted-by":"crossref","unstructured":"Mahjabin, T., & Xiao, Y. (2019). Mitigation process for DNS flood attacks. In 2019 16th IEEE annual consumer communications & networking conference (CCNC) (pp. 1\u20132). IEEE.","DOI":"10.1109\/CCNC.2019.8651715"},{"issue":"2","key":"950_CR10","doi-asserted-by":"publisher","first-page":"986","DOI":"10.1109\/JIOT.2019.2947659","volume":"7","author":"T Mahjabin","year":"2020","unstructured":"Mahjabin, T., Xiao, Y., Li, T., & Chen, C. L. P. (2020). Load distributed and Benign-Bot mitigation methods for IoT DNS flood attacks. IEEE Internet of Things Journal, 7(2), 986\u20131000. https:\/\/doi.org\/10.1109\/JIOT.2019.2947659","journal-title":"IEEE Internet of Things Journal"},{"key":"950_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jcss.2017.05.012","volume":"99","author":"Z Wang","year":"2019","unstructured":"Wang, Z. (2019). An elastic and resiliency defense against DDoS attacks on the critical DNS authoritative infrastructure. Journal of Computer and System Sciences, 99, 1\u201326.","journal-title":"Journal of Computer and System Sciences"},{"key":"950_CR12","unstructured":"Button, R. (2020). Dyn (DynDNS) DDoS attack. Last Retrieved February 12, 2020, from https:\/\/www.red-button.net\/blog\/dyn-dyndns-ddos-attack\/"},{"key":"950_CR13","doi-asserted-by":"crossref","unstructured":"Pappas, V., Massey, D., & Zhang, L. (2007). Enhancing DNS resilience against denial of service attacks. In 37th Annual IEEE\/IFIP international conference on dependable systems and networks (DSN\u201907) (pp. 450\u2013459). IEEE.","DOI":"10.1109\/DSN.2007.42"},{"key":"950_CR14","doi-asserted-by":"crossref","unstructured":"Wei-Min, L., Lu-Ying, C., & Zhen-Ming, L. (2010). Alleviating the impact of DNS DDoS attacks. In 2010 Second international conference on networks security, wireless communications and trusted computing (Vol. 1, pp. 240\u2013243). IEEE.","DOI":"10.1109\/NSWCTC.2010.63"},{"key":"950_CR15","doi-asserted-by":"crossref","unstructured":"Ballani, H., & Francis, P. (2008) Mitigating DNS DoS attacks. In Proceedings of the 15th ACM conference on computer and communications security (pp. 189\u2013198). ACM.","DOI":"10.1145\/1455770.1455796"},{"issue":"5","key":"950_CR16","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1145\/1096536.1096538","volume":"35","author":"T Deegan","year":"2005","unstructured":"Deegan, T., Crowcroft, J., & Warfield, A. (2005). The main name system: An exercise in centralized computing. ACM SIGCOMM Computer Communication Review, 35(5), 5\u201314.","journal-title":"ACM SIGCOMM Computer Communication Review"},{"issue":"3","key":"950_CR17","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/s11416-014-0230-y","volume":"11","author":"S Hong","year":"2015","unstructured":"Hong, S. (2015). Efficient and secure DNS cyber shelter on DDoS attacks. Journal of Computer Virology and Hacking Techniques, 11(3), 129\u2013136.","journal-title":"Journal of Computer Virology and Hacking Techniques"},{"key":"950_CR18","doi-asserted-by":"crossref","unstructured":"Georgiev, I., & Nikolova, K. (2017). An approach of DNS protection against DDoS attacks. In 2017 13th International conference on advanced technologies, systems and services in telecommunications (TELSIKS) (pp. 140\u2013143). IEEE.","DOI":"10.1109\/TELSKS.2017.8246248"},{"key":"950_CR19","doi-asserted-by":"crossref","unstructured":"Booth, T., & Andersson, K. (2017). DNS DDoS mitigation, via DNS timer design changes. In International conference on future network systems and security (pp. 43\u201355). Springer.","DOI":"10.1007\/978-3-319-65548-2_4"},{"key":"950_CR20","doi-asserted-by":"crossref","unstructured":"Pan, L., Yuchi, X., & Chen, Y. (2016). Mitigating DDoS attacks towards top level domain name service. In 2016 18th Asia-Pacific network operations and management symposium (APNOMS) (pp. 1\u20134). IEEE.","DOI":"10.1109\/APNOMS.2016.7737252"},{"key":"950_CR21","doi-asserted-by":"crossref","unstructured":"Feibish, S. L., Afek, Y., Bremler-Barr, A., Cohen, E., & Shagam, M. (2017). Mitigating DNS random subdomain DDoS attacks by distinct heavy hitters sketches. In Proceedings of the fifth ACM\/IEEE workshop on hot topics in web systems and technologies (p. 8). ACM.","DOI":"10.1145\/3132465.3132474"},{"issue":"4","key":"950_CR22","doi-asserted-by":"publisher","first-page":"1948","DOI":"10.1109\/TNET.2018.2854795","volume":"26","author":"Z Liu","year":"2018","unstructured":"Liu, Z., Jin, H., Hu, Y. C., & Bailey, M. (2018). Practical proactive DDoS-attack mitigation via endpoint-driven in-network traffic control. IEEE\/ACM Transactions on Networking, 26(4), 1948\u20131961.","journal-title":"IEEE\/ACM Transactions on Networking"},{"key":"950_CR23","doi-asserted-by":"crossref","unstructured":"Rashidi, B., & Fung, C. (2016). CoFence: A collaborative DDoS defence using network function virtualization. In 2016 12th international conference on network and service management (CNSM) (pp. 160\u2013166). IEEE.","DOI":"10.1109\/CNSM.2016.7818412"},{"key":"950_CR24","doi-asserted-by":"crossref","unstructured":"Jakaria, A. H. M., Rashidi, B., Rahman, M. A., Fung, C., & Yang, W. (2017). Dynamic DDoS defense resource allocation using network function virtualization. In Proceedings of the ACM international workshop on security in software defined networks & network function virtualization (pp. 37\u201342). ACM.","DOI":"10.1145\/3040992.3041000"},{"key":"950_CR25","doi-asserted-by":"crossref","unstructured":"Moura, G., Heidemann, J., M\u00fcller, M., de O Schmidt, R., & Davids, M. (2018). When the dike breaks: Dissecting DNS defenses during DDoS. In Proceedings of the internet measurement conference 2018 (pp. 8\u201321). ACM.","DOI":"10.1145\/3278532.3278534"},{"key":"950_CR26","doi-asserted-by":"crossref","unstructured":"Mahjabin, T., & Xiao, Y. (2019). DNS flood attack mitigation utilizing hot-lists and stale content updates. In Proceedings of the 12th international conference on security, privacy and anonymity in computation, communication and storage (SpaCCS 2019), July 14\u201317, Atlanta, USA (pp. 289\u2013296).","DOI":"10.1007\/978-3-030-24907-6_22"},{"issue":"1","key":"950_CR27","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1504\/IJSNET.2022.120270","volume":"38","author":"S Ghayyad","year":"2022","unstructured":"Ghayyad, S., Du, S., & Kurien, A. (2022). The flaws of Internet of Things (IoT) intrusion detection and prevention schemes. International Journal of Sensor Networks, 38(1), 25\u201336.","journal-title":"International Journal of Sensor Networks"},{"key":"950_CR28","doi-asserted-by":"crossref","unstructured":"Wagner, C., Fran\u00e7ois, J., State, R., Engel, T., Wagener, G., & Dulaunoy, A. (2012). SDBF: Smart DNS brute-forcer. In Network operations and management symposium, Lahaina, United States (pp. 1001\u20131007). https:\/\/doi.org\/10.1109NOMS.2012.6212021","DOI":"10.1109\/NOMS.2012.6212021"},{"key":"950_CR29","unstructured":"Mitchell, B. (2018). DNS caching and how it makes your internet better. Last Retrieved June 18, 2018, from https:\/\/www.lifewire.com\/what-is-a-dns-cache-817514"},{"issue":"1","key":"950_CR30","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1504\/IJSNET.2019.097556","volume":"29","author":"Y Zhao","year":"2019","unstructured":"Zhao, Y., Ma, T., Hao, Y., Shen, W., Tian, Y., & Al-Dhelaan, A. (2019). ICRA: Index based cache replacement algorithm for cloud storage. International Journal of Sensor Networks, 29(1), 48\u201357.","journal-title":"International Journal of Sensor Networks"},{"key":"950_CR31","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1109\/MCOM.2006.1637956","volume":"44","author":"H Chen","year":"2006","unstructured":"Chen, H., & Xiao, Y. (2006). Cache access and replacement for future wireless internet. IEEE Communications Magazine, Special Issue on Internet Technology Series, 44, 113\u2013123.","journal-title":"IEEE Communications Magazine, Special Issue on Internet Technology Series"},{"issue":"5","key":"950_CR32","doi-asserted-by":"publisher","first-page":"589","DOI":"10.1109\/TNET.2002.803905","volume":"10","author":"J Jung","year":"2002","unstructured":"Jung, J., Sit, E., Balakrishnan, H., & Morris, R. (2002). DNS performance and the effectiveness of caching. IEEE\/ACM Transactions on Networking, 10(5), 589\u2013603.","journal-title":"IEEE\/ACM Transactions on Networking"},{"key":"950_CR33","unstructured":"Wukipedia: Time to Live. Last Retrieved June 18, 2018, from https:\/\/en.wikipedia.org\/wiki\/Time_to_live"},{"key":"950_CR34","doi-asserted-by":"publisher","first-page":"466","DOI":"10.1016\/j.procs.2012.06.060","volume":"10","author":"N Vlajic","year":"2012","unstructured":"Vlajic, N., Andrade, M., & Nguyen, U. T. (2012). The role of DNS TTL values in potential DDoS attacks: What do the major banks know about it? Procedia Computer Science, 10, 466\u2013473.","journal-title":"Procedia Computer Science"},{"key":"950_CR35","unstructured":"Zeifman, I., & Margolius, D. The long and short of TTL\u2014Understanding DNS redundancy and the Dyn DDoS attack. Last Retrieved June 18, 2018, from https:\/\/www.incapsula.com\/blog\/the-long-and-short-of-ttl-the-ddos-perspective.html"},{"issue":"11","key":"950_CR36","doi-asserted-by":"publisher","first-page":"1733","DOI":"10.1016\/j.comnet.2005.06.016","volume":"50","author":"H Shang","year":"2006","unstructured":"Shang, H., & Wills, C. E. (2006). Piggybacking related domain names to improve DNS performance. Computer Networks, 50(11), 1733\u20131748.","journal-title":"Computer Networks"},{"issue":"4","key":"950_CR37","doi-asserted-by":"publisher","first-page":"416","DOI":"10.1109\/JCN.2009.6391355","volume":"11","author":"B Jang","year":"2009","unstructured":"Jang, B., Lee, D., Chon, K., & Kim, H. (2009). DNS resolution with renewal using piggyback. Journal of Communications and Networks, 11(4), 416\u2013427.","journal-title":"Journal of Communications and Networks"},{"key":"950_CR38","doi-asserted-by":"crossref","unstructured":"Mockapetris, P. (1987). RFC-1035 domain names-implementation and specification. Network Working Group, 55.","DOI":"10.17487\/rfc1035"},{"key":"950_CR39","doi-asserted-by":"crossref","unstructured":"Vixie, P. (1999). Extension mechanisms for DNS (EDNS0) (No. RFC 2671).","DOI":"10.17487\/rfc2671"},{"issue":"6","key":"950_CR40","doi-asserted-by":"publisher","first-page":"707","DOI":"10.1016\/S1389-1286(02)00424-3","volume":"41","author":"E Cohen","year":"2003","unstructured":"Cohen, E., & Kaplan, H. (2003). Proactive caching of DNS records: Addressing a performance bottleneck. Computer Networks, 41(6), 707\u2013726.","journal-title":"Computer Networks"},{"key":"950_CR41","unstructured":"Cao, P., & Irani, S. (1997). Cost-aware www proxy caching algorithms. In Usenix symposium on internet technologies and systems (Vol. 12(97), pp. 193\u2013206)."},{"key":"950_CR42","doi-asserted-by":"crossref","unstructured":"Choi, B. K., & Kang, D. (2013). Modeling and simulation of discrete event systems. Wiley.","DOI":"10.1002\/9781118732793"}],"container-title":["Telecommunication Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11235-022-00950-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11235-022-00950-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11235-022-00950-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T18:11:15Z","timestamp":1665425475000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11235-022-00950-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,12]]},"references-count":42,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,11]]}},"alternative-id":["950"],"URL":"https:\/\/doi.org\/10.1007\/s11235-022-00950-x","relation":{},"ISSN":["1018-4864","1572-9451"],"issn-type":[{"type":"print","value":"1018-4864"},{"type":"electronic","value":"1572-9451"}],"subject":[],"published":{"date-parts":[[2022,9,12]]},"assertion":[{"value":"13 August 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 September 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have not disclosed any conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}