{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:41:10Z","timestamp":1772041270013,"version":"3.50.1"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001321","name":"National Research Foundation","doi-asserted-by":"crossref","award":["NRF- 2016K1A1A2912757"],"award-info":[{"award-number":["NRF- 2016K1A1A2912757"]}],"id":[{"id":"10.13039\/501100001321","id-type":"DOI","asserted-by":"crossref"}]},{"name":"National Science Foundation","award":["CNS-1117300"],"award-info":[{"award-number":["CNS-1117300"]}]},{"name":"National Science Foundation","award":["CNS-1643207"],"award-info":[{"award-number":["CNS-1643207"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2018]]},"DOI":"10.1109\/tdsc.2018.2808344","type":"journal-article","created":{"date-parts":[[2018,2,21]],"date-time":"2018-02-21T19:26:55Z","timestamp":1519241215000},"page":"1-1","source":"Crossref","is-referenced-by-count":12,"title":["A Data-Driven Study of DDoS Attacks and Their Dynamics"],"prefix":"10.1109","author":[{"given":"An","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wentao","family":"Chang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Songqing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aziz","family":"Mohaisen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"127","article-title":"The crossfire attack","author":"kang","year":"2013","journal-title":"Proc IEEE Symp Security Privacy"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1982.1056489"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1080091.1080112"},{"key":"ref32","first-page":"167","article-title":"The internet motion sensor-a distributed blackhole monitoring system","author":"bailey","year":"2005","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879149"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-004-0154-9"},{"key":"ref36","first-page":"607","article-title":"An index-based approach for similarity search supporting time warping in large sequence databases","author":"kim","year":"2001","journal-title":"Proc 17th IEEE Int Conf Data Engineering"},{"key":"ref35","first-page":"359","article-title":"Using dynamic time warping to find patterns in time series","author":"berndt","year":"1994","journal-title":"Proc Knowl Discovery Data Mining"},{"key":"ref34","first-page":"26","article-title":"Behavioral clustering of HTTP-based malware and signature generation using malicious network traces","author":"perdisci","year":"2010","journal-title":"Proc 2nd USENIX Symp Net Sys Design and Implementation"},{"key":"ref28","article-title":"Network analysis without exponentiality assumptions","author":"harchol-balter","year":"1996"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1002\/047120644X.ch15"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2714576.2714637"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_11"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.04.001"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/2567948.2579359"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533064"},{"key":"ref24","first-page":"152","article-title":"Metadata-driven threat classification of network endpoints appearing in malware","volume":"8550","author":"west","year":"2014","journal-title":"Detection of Intrusions and Malware and Vulnerability Assessment"},{"key":"ref23","article-title":"NetAcuity and NetAcuity edge IP location technology","author":"thomas","year":"2014"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1090\/qam\/10666"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.47"},{"key":"ref10","first-page":"1","article-title":"Tracking DDoS attacks: Insights into the business of disrupting the web","author":"b\u00fcscher","year":"2012","journal-title":"USENIX Workshop on Large-scale Exploits and Emergent Threats"},{"key":"ref11","first-page":"1","article-title":"Opportunistic measurement: Extracting insight from spurious traffic","author":"casado","year":"2005","journal-title":"Proceedings of the 4th Workshop on Hot Topics in Networks"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23147"},{"key":"ref12","first-page":"1882","article-title":"A covariance analysis model for DDoS attack detection","author":"jin","year":"2004","journal-title":"Proc IEEE Int Conf Commun"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162675"},{"key":"ref14","first-page":"1511","article-title":"How distributed are today's DDoS attacks?","author":"wang","year":"2014","journal-title":"Proc ACM SIGSAC Conf Comput Commun Security"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2631464"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2003.1194894"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2005.11.007"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2007.01.040"},{"key":"ref19","first-page":"112","article-title":"AV-meter: An evaluation of antivirus scans and labels","author":"mohaisen","year":"2014","journal-title":"Detection of Intrusions and Malware and Vulnerability Assessment"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516749"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2592791.2592794"},{"key":"ref6","first-page":"139","article-title":"Botminer: Clustering analysis of network traffic for protocol- and structure-independent botnet detection","author":"gu","year":"2008","journal-title":"Proc Usenix Security"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2010.04.007"},{"key":"ref8","article-title":"Breaches, malware to cost $491 billion in 2014, study says","author":"robinson","year":"2014"},{"key":"ref7","article-title":"Verisign distributed denial of service trends report","author":"gu","year":"2015"},{"key":"ref49","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1109\/TDSC.2014.2315198","article-title":"A denial of service attack to UMTS networks using SIM-less devices","volume":"11","author":"merlo","year":"2014","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"ref9","first-page":"1","article-title":"Understanding the emerging threat of DDoS-as-a-service","author":"karami","year":"2013","journal-title":"USENIX Workshop on Large-scale Exploits and Emergent Threats"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2006.877138"},{"key":"ref45","article-title":"Implementing pushback: Router-based defense against DDoS attacks","author":"ioannidis","year":"2002","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.5"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/986655.986658"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2013.48"},{"key":"ref41","first-page":"1","article-title":"Losing control of the internet: Using the data plane to attack the control plane","author":"schuchard","year":"2011","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/1159913.1159948"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2014.2345381"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/4358699\/08299485.pdf?arnumber=8299485","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T16:44:24Z","timestamp":1651077864000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/8299485\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"references-count":49,"URL":"https:\/\/doi.org\/10.1109\/tdsc.2018.2808344","relation":{},"ISSN":["1545-5971"],"issn-type":[{"value":"1545-5971","type":"print"}],"subject":[],"published":{"date-parts":[[2018]]}}}