{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:44:33Z","timestamp":1787017473756,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Hessen State Min- istry for Higher Education, Research and Arts","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["SFB1119"],"award-info":[{"award-number":["SFB1119"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"name":"German Federal Ministry of Education and Research","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485917","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"1039-1050","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["SMap: Internet-wide Scanning for Spoofing"],"prefix":"10.1145","author":[{"given":"Tianxiang","family":"Dai","sequence":"first","affiliation":[{"name":"ATHENE Center, Germany and Fraunhofer SIT, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haya","family":"Shulman","sequence":"additional","affiliation":[{"name":"ATHENE Center, Germany and Fraunhofer SIT, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. MaxMind GeoLite2 Database. https:\/\/dev.maxmind.com\/geoip\/geoip2\/geolite2\/"},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Rapid7 Labs Open Data. https:\/\/opendata.rapid7.com\/"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"F. Baker and P. Savola. 2004. Ingress Filtering for Multihomed Networks. http:\/\/tools.ietf.org\/rfc\/rfc3704.txt RFC3704.","DOI":"10.17487\/rfc3704"},{"key":"e_1_3_2_1_4_1","volume-title":"Proc. of the Passive and Active Measurement Conference.","author":"Barford Paul","year":"2006","unstructured":"Paul Barford, Rob Nowak, Rebecca Willett, and Vinod Yegneswaran. 2006. Toward a model for source addresses of internet background radiation. In Proc. of the Passive and Active Measurement Conference."},{"key":"e_1_3_2_1_5_1","unstructured":"Robert Beverly and Steven Bauer. 2005. The Spoofer project: Inferring the extent of source address filtering on the Internet. In Usenix Sruti Vol.\u00a05. 53\u201359."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644936"},{"key":"e_1_3_2_1_7_1","volume-title":"Initial longitudinal analysis of IP source spoofing capability on the Internet","author":"Beverly Robert","year":"2013","unstructured":"Robert Beverly, Ryan Koga, and KC Claffy. 2013. Initial longitudinal analysis of IP source spoofing capability on the Internet. Internet Society (2013), 313."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243790"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2008.299"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663717"},{"key":"e_1_3_2_1_11_1","volume-title":"The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Dai Tianxiang","year":"2021","unstructured":"Tianxiang Dai, Philipp Jeitner, Haya Shulman, and Michael Waidner. 2021. The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources. In 30th USENIX Security Symposium (USENIX Security 21). 3147\u20133164."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472305.3472884"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484815"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2567561.2567568"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_3_2_1_16_1","volume-title":"Presented as part of the 22nd {USENIX} Security Symposium ({USENIX} Security 13). 605\u2013620.","author":"Durumeric Zakir","unstructured":"Zakir Durumeric, Eric Wustrow, and J\u00a0Alex Halderman. 2013. ZMap: Fast Internet-wide scanning and its security applications. In Presented as part of the 22nd {USENIX} Security Symposium ({USENIX} Security 13). 605\u2013620."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-04918-2_11"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Paul Ferguson. 2000. Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing. (2000).","DOI":"10.17487\/rfc2827"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"P. Ferguson and D. Senie. 2000. Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing. http:\/\/tools.ietf.org\/rfc\/rfc2827.txt RFC2827.","DOI":"10.17487\/rfc2827"},{"key":"e_1_3_2_1_20_1","volume-title":"Path MTU Discovery Considered Harmful. In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE, 866\u2013874","author":"G\u00f6hring Matthias","year":"2018","unstructured":"Matthias G\u00f6hring, Haya Shulman, and Michael Waidner. 2018. Path MTU Discovery Considered Harmful. In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS). IEEE, 866\u2013874."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682711"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2787394.2787399"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Christopher\u00a0A Kent and Jeffrey\u00a0C Mogul. 1987. Fragmentation considered harmful. Vol.\u00a017.","DOI":"10.1145\/55483.55524"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Maciej Korczy\u0144ski Yevheniya Nosyk Qasim Lone Marcin Skwarek Baptiste Jonglez and Andrzej Duda. 2020. The Closed Resolver Project: Measuring the Deployment of Source Address Validation of Inbound Traffic. arXiv preprint arXiv:2006.05277(2020).","DOI":"10.1007\/978-3-030-44081-7_7"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-44081-7_7"},{"key":"e_1_3_2_1_26_1","volume-title":"23rd {USENIX} Security Symposium ({USENIX} Security 14). 111\u2013125.","author":"K\u00fchrer Marc","unstructured":"Marc K\u00fchrer, Thomas Hupperich, Christian Rossow, and Thorsten Holz. 2014. Exit from Hell? Reducing the Impact of Amplification DDoS Attacks. In 23rd {USENIX} Security Symposium ({USENIX} Security 14). 111\u2013125."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131367"},{"key":"e_1_3_2_1_28_1","volume-title":"Using Crowdsourcing Marketplaces for Network Measurements: The Case of Spoofer. In 2018 Network Traffic Measurement and Analysis Conference (TMA). IEEE, 1\u20138.","author":"Lone Qasim","year":"2018","unstructured":"Qasim Lone, Matthew Luckie, Maciej Korczy\u0144ski, Hadi Asghari, Mobin Javed, and Michel van Eeten. 2018. Using Crowdsourcing Marketplaces for Network Measurements: The Case of Spoofer. In 2018 Network Traffic Measurement and Analysis Conference (TMA). IEEE, 1\u20138."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-54328-4_17"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354232"},{"key":"e_1_3_2_1_31_1","unstructured":"Gordon\u00a0Fyodor Lyon. 2009. Nmap network scanning: The official Nmap project guide to network discovery and security scanning. Insecure."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417280"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/LANMAN.2016.7548847"},{"key":"e_1_3_2_1_34_1","volume-title":"DNS-OARC","author":"Mauch Jared","year":"2013","unstructured":"Jared Mauch. 2013. Open resolver project. In Presentation, DNS-OARC Spring 2013 Workshop (Dublin)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815707"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.55"},{"key":"e_1_3_2_1_38_1","unstructured":"Terrance\u00a0A. Roebuck. 2005. Network security: DoS vs DDoS attacks. http:\/\/www.crime-research.org\/articles\/network-security-dos-ddos-attacks\/5."},{"key":"e_1_3_2_1_39_1","volume-title":"Amplification Hell: Revisiting Network Protocols for DDoS Abuse.. In NDSS.","author":"Rossow Christian","year":"2014","unstructured":"Christian Rossow. 2014. Amplification Hell: Revisiting Network Protocols for DDoS Abuse.. In NDSS."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07536-5_31"},{"key":"e_1_3_2_1_41_1","unstructured":"Stephen\u00a0M Specht and Ruby\u00a0B Lee. 2004. Distributed Denial of Service: Taxonomies of Attacks Tools and Countermeasures.. In ISCA PDCS. 543\u2013550."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"J. Touch. 2013. Updated Specification of the IPv4 ID Field. http:\/\/tools.ietf.org\/rfc\/rfc6864.txt RFC6864.","DOI":"10.17487\/rfc6864"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of Passive and Active Measurement Workshop (PAM).","author":"Wessels Duane","year":"2003","unstructured":"Duane Wessels, Marina Fomenkov, 2003. Wow, that\u2019sa lot of packets. In Proceedings of Passive and Active Measurement Workshop (PAM)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2381873"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485917","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485917","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:16:33Z","timestamp":1755890193000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485917"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":44,"alternative-id":["10.1145\/3485832.3485917","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485917","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}