{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T13:43:23Z","timestamp":1777902203887,"version":"3.51.4"},"reference-count":43,"publisher":"SAGE Publications","issue":"7","license":[{"start":{"date-parts":[[2010,10,21]],"date-time":"2010-10-21T00:00:00Z","timestamp":1287619200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["SIMULATION"],"published-print":{"date-parts":[[2011,7]]},"abstract":"<jats:p>Large-scale attacks such as distributed denial-of-service (DDoS) attacks present to be an increasing threat to the networks and business of service providers in today\u2019s Internet. In order to defend against such attacks, the development and deployment of effective anomaly and attack detection mechanisms are necessary. Testbeds and real networks do, however, not provide feasible means for the large-scale evaluation of such mechanisms. In order to gain a deeper understanding of the effectiveness of distributed attack detection mechanisms, simulations are essential. Simulative evaluation of such mechanisms, however, is a challenging task that has mostly been ignored until now. In this paper, we therefore present a toolchain for the large-scale evaluation of distributed attack detection based on the network simulator OMNeT++. In particular, we focus on: (1) realistic simulation environments in terms of topology, traffic and attack generation; (2) transparent operation of attack detection mechanisms in real and simulated environments; and (3) performance measurements with respect to execution time and memory usage.<\/jats:p>","DOI":"10.1177\/0037549710385716","type":"journal-article","created":{"date-parts":[[2010,10,21]],"date-time":"2010-10-21T23:34:42Z","timestamp":1287704082000},"page":"630-647","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":5,"title":["Simulative evaluation of distributed attack detection in large-scale realistic environments"],"prefix":"10.1177","volume":"87","author":[{"given":"Thomas","family":"Gamer","sequence":"first","affiliation":[{"name":"Institute of Telematics, Karlsruhe Institute of Technology (KIT), Germany,"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christoph P.","family":"Mayer","sequence":"additional","affiliation":[{"name":"Institute of Telematics, Karlsruhe Institute of Technology (KIT), Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2010,10,21]]},"reference":[{"key":"atypb1","author":"Namestnikov Y.","year":"2009","journal-title":"Kapersky Lab, Analysis on Viruslist.com"},{"key":"atypb2","volume-title":"Worldwide Infrastructure Security Report","author":"Arbor Networks.","year":"2008"},{"key":"atypb3","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2007.1111"},{"key":"atypb4","volume-title":"Proceedings of DARPA Information Survivability Conference and Exposition (DISCEX)","author":"Papadopoulos C."},{"key":"atypb5","doi-asserted-by":"publisher","DOI":"10.1145\/1090191.1080118"},{"key":"atypb6","volume-title":"Proceedings of the 8th IEEE International Symposium on Computers and Communication (ISCC)","author":"Hess A."},{"key":"atypb7","doi-asserted-by":"publisher","DOI":"10.1145\/1341431.1341443"},{"key":"atypb8","volume-title":"Proceedings of the 15th European Simulation Multiconference (ESM)","author":"Varga A."},{"key":"atypb9","volume-title":"The ns-3 Network Simulator (Version 3.4)","year":"2009"},{"key":"atypb10","doi-asserted-by":"publisher","DOI":"10.4108\/ICST.SIMUTOOLS2009.5552"},{"key":"atypb11","volume-title":"INET Framework","author":"Varga A.","year":"2007"},{"key":"atypb12","volume-title":"Digital Proceedings of the 1st International Workshop on OMNeT++ (co-located with SIMUTools)","author":"Gamer T."},{"key":"atypb13","volume-title":"Proceedings of the 2nd International Conference on Emerging Security Information, Systems and Technologies (SECURWARE)","author":"Gamer T."},{"key":"atypb14","volume-title":"Proceedings of the International Conference on Communications, Circuits and Systems (ICCCAS)","author":"Zhoua S."},{"key":"atypb15","volume-title":"Proceedings of ACM SIGCOMM","author":"Li L."},{"key":"atypb16","doi-asserted-by":"publisher","DOI":"10.1109\/90.650143"},{"key":"atypb17","volume-title":"\u2019\u2019 distributed denial of service attack tool","author":"Dittrich D.","year":"1999"},{"key":"atypb18","volume-title":"Proc. of the 9th ACM Conference on Computer and Communications Security (CSS)","author":"Zou CC"},{"key":"atypb19","volume-title":"Proceedings of the 29th Conference on Winter Simulation (WSC)","author":"Paxson V."},{"key":"atypb20","author":"Zseby T.","year":"2009","journal-title":"Request for Comments 5475, Internet Engineering Task Force (IETF)"},{"key":"atypb21","author":"Mayer CP","year":"2008","journal-title":"Telematics Technical Report TM-2008-2, Institute of Telematics"},{"key":"atypb22","volume-title":"Proceedings of the 9th European Software Engineering Conference","author":"Vigna G."},{"key":"atypb23","author":"Schulzrinne H.","year":"2009","journal-title":"Experimental Request for Comments, Internet Engineering Task Force (IETF)"},{"key":"atypb24","author":"Katz D.","year":"1997","journal-title":"Request for Comments 2113, Internet Engineering Task Force (IETF)"},{"key":"atypb25","doi-asserted-by":"publisher","DOI":"10.1145\/316194.316229"},{"key":"atypb26","volume-title":"Digital Proceedings of the 1st International Conference on Simulation Tools and Techniques (SIMUTools)","author":"Scholtes I."},{"key":"atypb27","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2003.815300"},{"key":"atypb28","volume-title":"Lessons from Three Views of the Internet Topology. Technical Report TR-2005-02, Cooperative Association for Internet Data Analysis (CAIDA)","author":"Mahadevan P.","year":"2005"},{"key":"atypb29","doi-asserted-by":"publisher","DOI":"10.1145\/1330107.1330110"},{"key":"atypb30","doi-asserted-by":"publisher","DOI":"10.1109\/90.282603"},{"key":"atypb31","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2003.1248656"},{"key":"atypb32","volume-title":"Proceedings of the 9th International Conference on Passive and Active Network Measurement (PAM)","author":"John W."},{"key":"atypb33","doi-asserted-by":"crossref","unstructured":"Medina A., Lakhina A., Matta I. and Byers J. BRITE: An approach to universal topology generation. In: Proceedings of the International Workshop on Modeling, Analysis and Simulation of Computer and Telecommunications Systems (MASCOTS), Cincinnati, OH , August 2001, pp.346-353.","DOI":"10.1109\/MASCOT.2001.948886"},{"key":"atypb34","author":"Winick J.","year":"2002","journal-title":"Technical Report UM-CSE-TR-456-02"},{"key":"atypb35","volume-title":"OMNeT++ Traffic Generator","author":"Dietrich I.","year":"2006"},{"key":"atypb36","volume-title":"Proceedings of the 8th Internet and Multimedia Systems and Applications (IMSA)","author":"Avallone S."},{"key":"atypb37","volume-title":"Digital Proc. of 2nd International Workshop on OMNeT++","author":"Jonsson K."},{"key":"atypb38","volume-title":"Route Views Project","author":"University of Oregon."},{"key":"atypb39","volume-title":"The Archipelago measurement infrastructure","author":"Hyun Y.","year":"2006"},{"key":"atypb40","unstructured":"Roesch M. Snort, April 2009, http:\/\/www.snort.org."},{"key":"atypb41","volume-title":"PreludeIDS: Current State and Development Perspectives","author":"Zaraska K.","year":"2008"},{"key":"atypb42","volume-title":"Proceedings of the 9th International Conference on Internet Security (ISC)","author":"Kotenko IV"},{"key":"atypb43","volume-title":"Digital Proceedings of the 2nd International Workshop on OMNeT++","author":"Kozlovszky M."}],"container-title":["SIMULATION"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549710385716","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549710385716","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T11:22:47Z","timestamp":1777634567000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0037549710385716"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,10,21]]},"references-count":43,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2011,7]]}},"alternative-id":["10.1177\/0037549710385716"],"URL":"https:\/\/doi.org\/10.1177\/0037549710385716","relation":{},"ISSN":["0037-5497","1741-3133"],"issn-type":[{"value":"0037-5497","type":"print"},{"value":"1741-3133","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010,10,21]]}}}