{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T03:31:50Z","timestamp":1781062310218,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T00:00:00Z","timestamp":1635811200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["PRIMEnet"],"award-info":[{"award-number":["PRIMEnet"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,2]]},"DOI":"10.1145\/3487552.3487840","type":"proceedings-article","created":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T17:35:11Z","timestamp":1635788111000},"page":"283-291","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["QUICsand"],"prefix":"10.1145","author":[{"given":"Marcin","family":"Nawrocki","sequence":"first","affiliation":[{"name":"Freie Universit\u00e4t Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raphael","family":"Hiesgen","sequence":"additional","affiliation":[{"name":"HAW Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas C.","family":"Schmidt","sequence":"additional","affiliation":[{"name":"HAW Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthias","family":"W\u00e4hlisch","sequence":"additional","affiliation":[{"name":"Freie Universit\u00e4t Berlin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,2]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Understanding the Mirai Botnet. In 26th USENIX Security Symposium (USENIX Security 17)","author":"Antonakakis Manos","year":"2017","unstructured":"Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J. Alex Halderman, Luca Invernizzi, Michalis Kallitsis, Deepak Kumar, Chaz Lever, Zane Ma, Joshua Mason, Damian Menscher, Chad Seaman, Nick Sullivan, Kurt Thomas, and Yi Zhou. 2017. Understanding the Mirai Botnet. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 1093--1110."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCNW.2014.6927719"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2016.7841749"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3098985"},{"key":"e_1_3_2_1_5_1","unstructured":"CAIDA. 2012. The UCSD Network Telescope. http:\/\/www.caida.org\/projects\/network_telescope\/ Last modified: January 29 2018."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2695664.2695706"},{"key":"e_1_3_2_1_7_1","volume-title":"What is a QUIC flood DDoS attack? QUIC and UDP floods. Blog. https:\/\/www.cloudflare.com\/ko-kr\/learning\/ddos\/what-is-a-quic-flood\/ Last Access","year":"2021","unstructured":"Cloudflare. [n.d.]. What is a QUIC flood DDoS attack? QUIC and UDP floods. Blog. https:\/\/www.cloudflare.com\/ko-kr\/learning\/ddos\/what-is-a-quic-flood\/ Last Access: May 2021."},{"key":"e_1_3_2_1_8_1","volume-title":"Multipath QUIC. In Proc. of ACM CoNEXT. ACM","author":"Coninck Quentin De","year":"2017","unstructured":"Quentin De Coninck and Olivier Bonaventure. 2017. Multipath QUIC. In Proc. of ACM CoNEXT. ACM, New York, NY, USA, 160--166."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2017.7997281"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2017.44"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"W. Eddy. 2007. TCP SYN Flooding Attacks and Common Mitigations. RFC 4987. IETF.","DOI":"10.17487\/rfc4987"},{"key":"e_1_3_2_1_12_1","unstructured":"Jasper Eumann Raphael Hiesgen Thomas C. Schmidt and Matthias W\u00e4hlisch. 2019. A Reproducibility Study of \"IP Spoofing Detection in Inter-Domain Traffic\". Technical Report arXiv:1911.05164. Open Archive: arXiv.org. https:\/\/arxiv.org\/abs\/1911.05164"},{"key":"e_1_3_2_1_13_1","volume-title":"Our Roadmap for QUIC and HTTP\/3 Support in NGINX. Website. https:\/\/www.nginx.com\/blog\/our-roadmap-quic-http-3-support-nginx\/ Last Access","author":"Inc. F5. 2021.","year":"2021","unstructured":"Inc. F5. 2021. Our Roadmap for QUIC and HTTP\/3 Support in NGINX. Website. https:\/\/www.nginx.com\/blog\/our-roadmap-quic-http-3-support-nginx\/ Last Access September 2021."},{"key":"e_1_3_2_1_14_1","volume-title":"How Facebook is bringing QUIC to billions. Engineering Blog. https:\/\/engineering.fb.com\/2020\/10\/21\/networking-traffic\/how-facebook-is-bringing-quic-to-billions\/ Last Acess","year":"2021","unstructured":"Facebook. 2020. How Facebook is bringing QUIC to billions. Engineering Blog. https:\/\/engineering.fb.com\/2020\/10\/21\/networking-traffic\/how-facebook-is-bringing-quic-to-billions\/ Last Acess May 2021."},{"key":"e_1_3_2_1_15_1","volume-title":"Proc. of IFIP Networking Conference. IEEE Press","author":"Fonseca Osvaldo","year":"2020","unstructured":"Osvaldo Fonseca, \u00cdtalo Cunha, Elverton Fazzion, Wagner Meira, Brivaldo Junior, Ronaldo A. Ferreira, and Ethan Katz-Bassett. 2020. Tracking Down Sources of Spoofed IP Packets. In Proc. of IFIP Networking Conference. IEEE Press, Piscataway, NJ, USA, 208--216."},{"key":"e_1_3_2_1_16_1","volume-title":"Information Security Theory and Practice. LNCS","author":"Gagliardi Eva","unstructured":"Eva Gagliardi and Olivier Levillain. 2020. Analysis of QUIC Session Establishment and Its Implementations. In Information Security Theory and Practice. LNCS, Vol. 12024. Springer Nature, Switzerland, 169--184."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"A. Ghedini and V. Vasiliev. 2020. TLS Certificate Compression. RFC 8879. IETF.","DOI":"10.17487\/RFC8879"},{"key":"e_1_3_2_1_18_1","volume-title":"quiche. Github Repository. https:\/\/github.com\/google\/quiche\/search?p=2&q=retry&type=commits Last Access","year":"2021","unstructured":"Google. [n.d.]. quiche. Github Repository. https:\/\/github.com\/google\/quiche\/search?p=2&q=retry&type=commits Last Access: September 2021."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068834"},{"key":"e_1_3_2_1_20_1","volume-title":"A simple test of DDOS attacks on QUIC. Blog. https:\/\/huitema.wordpress.com\/2020\/09\/22\/a-simple-test-of-ddos-attacks-on-quic\/ Last Access","author":"Huitema Christian","year":"2021","unstructured":"Christian Huitema. 2020. A simple test of DDOS attacks on QUIC. Blog. https:\/\/huitema.wordpress.com\/2020\/09\/22\/a-simple-test-of-ddos-attacks-on-quic\/ Last Access May 2021."},{"key":"e_1_3_2_1_21_1","volume-title":"mvfst. Github Repository. https:\/\/github.com\/facebookincubator\/mvfst\/search?p=2&q=retry&type=commits Last Access","author":"Incubator Facebook","year":"2021","unstructured":"Facebook Incubator. [n.d.]. mvfst. Github Repository. https:\/\/github.com\/facebookincubator\/mvfst\/search?p=2&q=retry&type=commits Last Access: September 2021."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC1035"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131383"},{"key":"e_1_3_2_1_24_1","volume-title":"Proc. of ACM IMC. ACM","author":"Kakhki Arash Molavi","year":"2017","unstructured":"Arash Molavi Kakhki, Samuel Jero, David Choffnes, Cristina Nita-Rotaru, and Alan Mislove. 2017. Taking a long look at QUIC. An Approach for Rigorous Evaluation of Rapidly Evolving Transport Protocols. In Proc. of ACM IMC. ACM, New York, NY, USA, 290--303."},{"key":"e_1_3_2_1_25_1","volume-title":"An IXP Perspective on DDoS Amplification Attacks. In Passive and Active Measurement (LNCS","volume":"301","author":"Kopp Daniel","year":"2021","unstructured":"Daniel Kopp, Christoph Dietzel, and Oliver Hohlfeld. 2021. DDoS Never Dies? An IXP Perspective on DDoS Amplification Attacks. In Passive and Active Measurement (LNCS, Vol. 12671). Springer Nature, Switzerland, 284--301."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098822.3098842"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131367"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.21"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3405796.3405830"},{"key":"e_1_3_2_1_30_1","volume-title":"Does the QUIC handshake require compression to be fast? Fastly Blog. https:\/\/www.fastly.com\/blog\/quic-handshake-tls-compression-certificates-extension-study Last Access","author":"McManus Patrick","year":"2021","unstructured":"Patrick McManus. 2020. Does the QUIC handshake require compression to be fast? Fastly Blog. https:\/\/www.fastly.com\/blog\/quic-handshake-tls-compression-certificates-extension-study Last Access May 2021."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/997150.997156"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/1132026.1132027"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359989.3365422"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1002\/nem.2158"},{"key":"e_1_3_2_1_36_1","unstructured":"Nexusguard Reasearch. 2020. Could QUIC turn into the next most prevalent amplification attack vector? Nexusguard Blog. https:\/\/blog.nexusguard.com\/could-quic-turn-into-the-next-most-prevalent-amplification-attack-vector Last Access September 2021."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3284850.3284852"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355595"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23233"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-76481-8_19"},{"key":"e_1_3_2_1_41_1","volume-title":"Schmidt","author":"Ryba Fabrice J.","year":"2015","unstructured":"Fabrice J. Ryba, Matthew Orlinski, Matthias W\u00e4hlisch, Christian Rossow, and Thomas C. Schmidt. 2015. Amplification and DRDoS Attack Defense - A Survey and New Perspectives. Technical Report arXiv:1505.07892. Open Archive: arXiv.org. http:\/\/arxiv.org\/abs\/1505.07892"},{"key":"e_1_3_2_1_42_1","volume-title":"QUIC Interop Runner. Blog. https:\/\/interop.seemann.io\/?test=s Last Access","author":"Seeman Marten","year":"2021","unstructured":"Marten Seeman. 2021. QUIC Interop Runner. Blog. https:\/\/interop.seemann.io\/?test=s Last Access September 2021."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0017"},{"key":"e_1_3_2_1_44_1","unstructured":"Avast Software s.r.o. 2020. The return of the Mirai botnet. https:\/\/blog.avast.com\/return-of-mirai-botnet-avast."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2020.2967588"}],"event":{"name":"IMC '21: ACM Internet Measurement Conference","location":"Virtual Event","acronym":"IMC '21","sponsor":["SIGCOMM ACM Special Interest Group on Data Communication","SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","USENIX Assoc USENIX Assoc"]},"container-title":["Proceedings of the 21st ACM Internet Measurement Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3487552.3487840","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3487552.3487840","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,15]],"date-time":"2025-12-15T17:24:43Z","timestamp":1765819483000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3487552.3487840"}},"subtitle":["quantifying QUIC reconnaissance scans and DoS flooding events"],"short-title":[],"issued":{"date-parts":[[2021,11,2]]},"references-count":45,"alternative-id":["10.1145\/3487552.3487840","10.1145\/3487552"],"URL":"https:\/\/doi.org\/10.1145\/3487552.3487840","relation":{},"subject":[],"published":{"date-parts":[[2021,11,2]]},"assertion":[{"value":"2021-11-02","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}