REVIEW 4 major objections 6 minor 89 references
Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services
T0 review · 4 major / 6 minor · reviewed 2026-08-08 · deepseek-v4-flash
Pith's one-line read The paper claims that the first wave of a global DDoS-for-hire takedown produced a statistically significant 20–40% reduction in UDP-based attack volume, while the second wave did not, and the effect lasted about six weeks.
desk verdict Ground-truth data makes this the definitive measurement of the booter takedown, but the headline 20-40% causal estimate remains a soft upper bound. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing method is interrupted time-series analysis with negative binomial regression applied to weekly DDoS attack counts. The model includes underlying trend, day-of-week and month seasonality, and intervention components whose start, duration, and end are selected by inspecting the data and testing fit, and the same specification is applied independently to four datasets. This is the mechanism that separates the takedown signal from the normal Christmas decline and from random noise. Around it, the paper triangulates ground-truth visits to seized splash pages, web-analytics estimates, and qualitative analysis of forum and chat discussions.
What would settle it
Re-run the same negative binomial specification on a placebo intervention placed at a date with no takedown (for example, October 2022), or compare the December 2022 drop with the same-calendar period from a year with no takedown; if the placebo produces a drop of similar size, the attribution to the takedown fails.
Extended reading notes
Core claim
The central claim is that the first wave on 14 December 2022 significantly disrupted the supply side of the DDoS-for-hire market, cutting global UDP-based DDoS attack volume by roughly 20–40% for about six weeks, while the second wave on 5 May 2023 had no statistically significant effect. The observed effect is specific to UDP-based attacks, the vector most commonly associated with booters, and is not seen for TCP-based attacks. The recovery was not driven by the seized booters regaining traffic: resurrected domains attracted 80–90% fewer visits, and the rebound came instead from smaller or new services, while two large booters that survived both waves kept roughly steady market shares. On the paper's account, the takedown's measurable legacy is a temporary dip in one attack class plus a durable change in risk perception and user engagement, not a lasting reduction in global attack volume.
Load-bearing premise
The central claim rests on the assumption that the drop in UDP attack counts after the first wave is the takedown's effect and not mostly the usual Christmas-holiday decline.
Editorial extensions
If this is right
- If the first-wave estimate is right, a sufficiently large and coordinated takedown can cut global UDP-based DDoS attack volume by a fifth to two-fifths within weeks, a measurable but bounded effect.
- Because the second wave showed no significant effect even though all seized booters returned, repeating the same tactic does not automatically deepen the disruption.
- The 80–90% traffic loss of resurrected domains implies that takedowns damage customer trust and visibility even when supply is quickly restored, so the market does not fully snap back.
- Since all four DDoS datasets recover within roughly six weeks, the paper implies that single interventions should be judged as temporary suppression, with sustained or repeated pressure required to hold the gain.
Reading between the lines
- A natural extension the paper leaves implicit: if takedowns selectively cut UDP attacks, some displacement toward TCP-based or direct-path attack vectors should appear in the months after a wave; checking whether the TCP share rose after December 2022 would test that displacement.
- The inconsistent Christmas-2021 control across datasets suggests the seasonal baseline is not uniform, so a multi-year, multi-dataset control series would sharpen future causal estimates.
- The brief spike in visits to law-enforcement-run deceptive domains, followed by a quick fade, suggests that influence operations need continuous top-up to hold attention; running them alongside each wave could create longer deterrence.
- If the six-week recovery is a robust feature, then takedown timing may matter more than scale: scheduling waves just before peak-attack periods such as school holidays or Christmas could convert a short-lived dip into a meaningful seasonal reduction in harm.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper evaluates a two-wave international takedown of DDoS-for-hire ('booter') services that began in December 2022, using an unusually rich set of data sources: ground-truth traffic to seized and police-deployed domains, Similarweb analytics, four independent DDoS attack datasets (HOPSCOTCH, AMPPOT, NETSCOUT, and self-reported statistics), underground forum posts, and Telegram chat logs. The main findings are that many seized booters resurrected quickly (52% of first-wave booters within a median of 19 hours; 100% of second-wave booters within a median of 42 hours), that resurrected domains attracted 80–90% less traffic than before, that the first wave coincided with a statistically significant but short-lived decline in UDP-based attack volumes lasting about six weeks while the second wave had no significant effect, and that underground discussions show increased perceptions of enforcement risk and some operator exits. The paper concludes that the intervention had meaningful but temporary effects and discusses implications for future takedown strategies.
Significance. This is a valuable empirical study of a real, ongoing law enforcement operation, and it makes several novel contributions: the ground-truth splash-page data offer a rarely available view of user behavior during a takedown; the resurrection and reinstallation timing measurements are new; the observation of API-based reselling and the analysis of NCA deceptive domains are original; and the triangulation across four independent DDoS datasets is a strength. The paper is also commendably transparent about its limitations, including the possibility that the measured first-wave effect is an upper bound that includes concurrent seasonal declines. However, the headline quantitative claim—that the first wave cut global DDoS attack volume by 20–40% with a statistically significant effect on UDP-based attacks—is less secure than the paper's abstract suggests because the intervention windows are selected after inspecting the data and the only same-season control (Xmas'21) gives inconsistent results across datasets.
major comments (4)
- [§5.2, 'The Overall Picture' and Tables 2–5] The intervention periods for both takedown waves are selected data-dependently: the paper states that 'we specify an intervention period through observation and testing of different durations, start, and end points for fit and feasibility.' This post hoc selection inflates the significance of the reported coefficients because the model is chosen to fit the observed drop, and no correction is made for the number of alternative windows examined. Please report the grid of candidate windows tested, state the selection rule (e.g., best fit by AIC/BIC), and provide a sensitivity analysis showing that the 1st-wave coefficient remains significant across a range of pre-specified windows, or use a formal model-averaging or placebo-based approach.
- [§5.2, Tables 2–5 vs. Abstract] The abstract's '20–40%' reduction is not consistent with the reported negative binomial coefficients. The implied multiplicative reductions are approximately 39% (HOPSCOTCH, coef −0.499), 43% (AMPPOT, coef −0.564), 16% (NETSCOUT UDP, coef −0.172), and 13% (self-reported, coef −0.138). The paper should either explicitly define how the 20–40% range was computed (e.g., as the interquartile range across datasets), or correct the abstract and the §5.2 summary to reflect the actual coefficient magnitudes.
- [§5.2, 'The Overall Picture' and Xmas'21 control] The Xmas'21 control, which is the only same-season counterfactual, is inconsistent across datasets: it is statistically significant in HOPSCOTCH (−0.459, p<0.05) and NETSCOUT UDP (−0.193, p<0.01) but not in AMPPOT (+0.215, p=0.25) or self-reported data (−0.096, p=0.062). The paper's justification that 'NETSCOUT (the most stable one)' should be weighted more heavily is ad hoc and does not resolve the seasonal-confounding concern, especially since the paper itself concedes that 'declines in attacks around Christmas are also quite common.' Please provide a formal placebo analysis using the Xmas'21 period as a falsification test, or explicitly model seasonal variation using more than one prior year, and discuss how the conclusion would change if the seasonal component were estimated differently.
- [§5.2, 'The Overall Picture'] The paper's own caveat that 'the impact may thus reflect a combined upper bound effect of all events... the takedown impact alone may be even less significant' is in tension with the abstract's causal wording ('the first wave cut the global DDoS attack volume by 20–40%'). The central claim as stated in the abstract is a load-bearing assertion that goes beyond what the current modeling approach can establish. Please either temper the abstract and the §5.2 takeaways to describe the result as an upper-bound estimate associated with the takedown and concurrent seasonal events, or provide additional evidence (e.g., difference-in-differences against a non-holiday control period, or a model excluding the Christmas weeks) that isolates the takedown effect.
minor comments (6)
- [Abstract] The phrase 'global DDoS attack volume' is broader than what is measured; the significant effect is specifically on UDP-based attacks, and the §5.2 analysis shows no significant effect on TCP-based attacks. Please consider revising the abstract to 'UDP-based DDoS attack volume' for precision.
- [Tables 2–5] The negative binomial model tables report only the intervention and seasonal coefficients. For reproducibility, please also report the trend coefficient, the dispersion parameter, the number of observations, and the log-likelihood or AIC for the final model of each dataset.
- [§3.2, Self-reported Statistics] The self-reported statistics are collected from 207 booters over two years, but the paper does not state how the panel is balanced (i.e., how many booters are present in each week, and how missing weeks are treated). Please add this information, as attrition or entry of new booters could affect the weekly counts.
- [§4.2, Figure 2] The ground-truth daily session counts are shown as an aggregate; given that the top 5 domains account for 40.57% of visits, a per-domain plot or a confidence band around the aggregate would better communicate the variability.
- [§5.1, Figure 6] The figure caption says 'pre-takedown' traffic for first-wave resurrected domains includes visits to pre-purchased domains that were later reused; please make this explicit in the caption or the text, because those pre-takedown visits are not to then-active booter domains.
- [§5.3, Figure 13] The figure shows a sharp increase in messages and posters after the second wave, but the text does not explain why this increase is attributed to newly seized booters' channels. Please state the criterion used to include channels in this analysis (e.g., all channels of booters seized in either wave) and whether the increase could be an artifact of channel additions.
Circularity Check
Post-hoc intervention-window selection makes the headline significance claim partly self-fitted, but the central finding is not definitionally circular.
-
fitted input called prediction
[Section 5.2, DDoS Attack Volumes (intervention model construction; Tables 2–5, 'The Overall Picture')]
"For each takedown, we specify an intervention period through observation and testing of different durations, start, and end points for fit and feasibility, incorporating significant interventions stepwise into an overall model."
The first-wave intervention indicator whose coefficient is tested is not fixed a priori; its start and end are selected by 'observation and testing' of the same weekly attack series it is then used to explain. The reported 'statistically significant impact' is therefore a fit statistic from a model specification chosen to maximize fit, not an independent confirmatory test. With only two years of weekly data and an inconsistent same-season control (Xmas'21), the p-values in Tables 2–5 are inflated by the model-search process. The paper itself concedes that the impact may reflect a combined upper bound of all concurrent events, so the takedown-only attribution is not cleanly identified.
full rationale
This is an empirical measurement study rather than a derivation, so the strongest circularity patterns do not apply. The headline causal estimate is not definitionally tied to its inputs: the 20–40% reduction is computed from negative binomial coefficients on external DDoS datasets, and the traffic, resurrection, and community findings are directly measured. Self-citations to the same authors' prior booter-takedown paper are used to motivate the method and to compare with 2018, but the method is standard and the present datasets include independent NETSCOUT and AMPPOT sources, so this is not load-bearing circularity. The one genuinely circular element is in Section 5.2: the intervention period is specified through observation and testing of different durations, start, and end points for fit. This means the first-wave indicator whose significance is celebrated is partly a data-fitted construct: the same weekly attack series is used first to choose the intervention window and then to test the intervention's effect. Consequently the p-values in Tables 2–5 are not valid confirmatory tests, and the claim that the first wave had a statistically significant impact is partially an artifact of model selection. The paper's own caveat that the impact may be a combined upper bound of all events and that the takedown alone may be even less significant confirms that the attribution is fragile. Because the qualitative, ground-truth, and multi-dataset evidence give the central narrative independent substance, this is partial circularity rather than complete equivalence, hence a score of 4.
Assumptions & free parameters
free parameters (2)
- 1st wave intervention period =
approximately 6 weeks (December 2022 to February 2023)
- 2nd wave intervention period =
approximately 2 weeks (May 2023)
assumptions (4)
- domain assumption UDP amplification attacks observed by HOPSCOTCH and AMPPOT honeypots are predominantly generated by booter services
- domain assumption The negative binomial regression model with selected intervention periods provides a valid counterfactual for what would have happened absent the takedown
- domain assumption Similarweb analytics, after validation against ground-truth data, provide a reliable estimate of historical traffic to booter domains
- domain assumption The ground-truth splash-page traffic reflects real user visits after filtering bots and prefetches
Cite this review
Pith. "Pith review of Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services." pith.science (2026). https://pith.science/paper/EP6S6HZD
@misc{pith2026250204753,
author = {Pith},
title = {Pith review of: Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services},
year = {2026},
howpublished = {\url{https://pith.science/paper/EP6S6HZD}},
note = {Machine review of arXiv:2502.04753}
}
read the original abstract
Law enforcement and private-sector partners have in recent years conducted various interventions to disrupt the DDoS-for-hire market. Drawing on multiple quantitative datasets, including web traffic and ground-truth visits to seized websites, millions of DDoS attack records from academic, industry, and self-reported statistics, along with chats on underground forums and Telegram channels, we assess the effects of an ongoing global intervention against DDoS-for-hire services since December 2022. This is the most extensive booter takedown to date conducted, combining targeting infrastructure with digital influence tactics in a concerted effort by law enforcement across several countries with two waves of website takedowns and the use of deceptive domains. We found over half of the seized sites in the first wave returned within a median of one day, while all booters seized in the second wave returned within a median of two days. Re-emerged booter domains, despite closely resembling old ones, struggled to attract visitors (80-90% traffic reduction). While the first wave cut the global DDoS attack volume by 20-40% with a statistically significant effect specifically on UDP-based DDoS attacks (commonly attributed to booters), the impact of the second wave appeared minimal. Underground discussions indicated a cumulative impact, leading to changes in user perceptions of safety and causing some operators to leave the market. Despite the extensive intervention efforts, all DDoS datasets consistently suggest that the illicit market is fairly resilient, with an overall short-lived effect on the global DDoS attack volume lasting for at most only around six weeks.
Figures
Figures from the paper (7 more)
Reference graph
Works this paper leans on
-
[1]
Ugur Akyazi, Michel van Eeten, and Carlos H. Gañán. Measuring Cybercrime as a Service (CaaS) Offerings in a Cybercrime Forum. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2021. https://rb.gy/rpbvlx
2021
-
[2]
Thomas S. Hyslip. Cybercrime-as-a-Service Operations. In The Palgrave Handbook of International Cybercrime and Cyberdeviance. Palgrave Macmillan, 2020. DOI: 10.1007/978-3-319-78440-3_36
-
[3]
Cybercrime Is (Often) Boring: Infras- tructure and Alienation in a Deviant Subculture
Ben Collier, Richard Clayton, Alice Hutchings, and Daniel Thomas. Cybercrime Is (Often) Boring: Infras- tructure and Alienation in a Deviant Subculture. The British Journal of Criminology, 2021. DOI:10.1093/ BJC/AZAB026
2021
-
[4]
Understand- ing the Emerging Threat of DDoS-as-a-service
Mohammad Karami and Damon McCoy. Understand- ing the Emerging Threat of DDoS-as-a-service. In Proceedings of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET) , 2013. DOI: 10.5555/3241085.3241093
-
[5]
Exploring the Provision of Online Booter Services
Alice Hutchings and Richard Clayton. Exploring the Provision of Online Booter Services. Deviant Behavior,
-
[6]
David Douglas, José Jair Santanna, Ricardo de Oliveira Schmidt, Lisandro Zambenedetti Granville, and Aiko Pras. Booters: Can Anything Justify Distributed Denial-of-Service (DDoS) Attacks for Hire? Journal of Information, Communication and Ethics in Society, 2017. DOI:10.1108/JICES-09-2016-0033
-
[7]
Department of Justice
U.S. Department of Justice. Criminal Charges Filed in Los Angeles and Alaska in Conjunction With Seizures of 15 Websites Offering DDoS-For-Hire Services. ht tps://rb.gy/96rntp, 2018
2018
-
[9]
DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown
Daniel Kopp, Matthias Wichtlhuber, Ingmar Poese, Jair Santanna, Oliver Hohlfeld, and Christoph Dietzel. DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown. In Proceedings of the ACM Internet Mea- surement Conference (IMC), 2019. DOI:10.1145/33 55369.3355590
arXiv 2019
Show all 89 references
-
[10]
Department of Justice
U.S. Department of Justice. Federal Prosecutors in Alaska and Los Angeles Charge 6 Defendants With Operating Websites That Offered Computer Attack Ser- vices. https://rb.gy/dz8te5, 2022
2022
-
[11]
Department of Justice
U.S. Department of Justice. Federal Authorities Seize 13 Internet Domains Associated With ‘Booter’ Websites That Offered DDoS Computer Attack Services. https: //rb.gy/phuc1j, 2023
2023
-
[12]
Department of Justice
U.S. Department of Justice. Illinois Man Convicted of Federal Criminal Charges for Operating Subscription- Based Computer Attack Platforms. https://rb.gy/ cxy7u0, 2021
2021
-
[13]
Thinking of Hiring or Running a Booter Service? Think Again
Krebs on Security. Thinking of Hiring or Running a Booter Service? Think Again. https://rb.gy/hvl5 qe, 2023
2023
-
[14]
Vu, Ben Collier, Daniel R
José Jair Santanna, Roland van Rijswijk-Deij, Rick Hof- Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings 15 In Proceedings of the USENIX Security Symposium 2025 stede, Anna Sperotto, Mark Wierbosch, Lisandro Zam- benedetti Granvill...
2025
-
[15]
Linking Ampli- fication DDoS Attacks to Booter Services
Johannes Krupp, Mohammad Karami, Christian Rossow, Damon McCoy, and Michael Backes. Linking Ampli- fication DDoS Attacks to Booter Services. In Proceed- ings of the International Symposium on Research in Attacks, Intrusions, and Defenses (RAID), 2017. DOI: 10.1007/978-3-319-66332-6_19
2017 doi
-
[16]
Department of Justice
U.S. Department of Justice. Gatrel and Martinez Com- plaint. https://rb.gy/q364o2, 2018
2018
-
[17]
Stress Testing the Booters: Understanding and Un- dermining the Business of DDoS Services
Mohammad Karami, Youngsam Park, and Damon Mc- Coy. Stress Testing the Booters: Understanding and Un- dermining the Business of DDoS Services. In Proceed- ings of the ACM World Wide Web Conference (WWW),
-
[18]
UK Man Gets Two Years in Jail for Running ‘Titanium Stresser’ Attack-for-Hire Service
Krebs on Security. UK Man Gets Two Years in Jail for Running ‘Titanium Stresser’ Attack-for-Hire Service. https://rb.gy/i620ib, 2017
2017
-
[19]
DOI:10.1145/2872427.2883004
-
[20]
Olga Smirnova and Thomas J. Holt. Exploring and Estimating the Revenues of Cybercrime-as-Service Providers: Analyzing Booter and Stresser Services. De- viant Behavior, 2024. DOI:10.1080/01639625.2024. 2373346
2024
-
[21]
Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years
Krebs on Security. Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years. https://rb.gy/jqky iu, 2016
2016
-
[22]
Booted: An Analysis of a Payment Intervention on a DDoS-for-hire Service
Ryan Brunt, Prakhar Pandey, and Damon McCoy. Booted: An Analysis of a Payment Intervention on a DDoS-for-hire Service. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2017. https://rb.gy/5iia4e
2017
-
[23]
Following the Money Hobbled vDOS Attack-for-Hire Service
Krebs on Security. Following the Money Hobbled vDOS Attack-for-Hire Service. https://rb.gy/rsuc9u , 2017
2017
-
[24]
Google Doesn’t Seem to Believe Boot- ers Are Illegal
Richard Clayton. Google Doesn’t Seem to Believe Boot- ers Are Illegal. https://rb.gy/snsach, 2018
2018
-
[25]
Hackforums Shutters Booter Service Bazaar
Krebs on Security. Hackforums Shutters Booter Service Bazaar. https://rb.gy/myo8hx, 2016
2016
-
[26]
An Evaluation of Police Interven- tions for Cybercrime Prevention
Maria Bada, Alice Hutchings, Yanna Papadodimitraki, and Richard Clayton. An Evaluation of Police Interven- tions for Cybercrime Prevention. Technical report, Uni- versity of Cambridge, 2023. https://rb.gy/54622u
2023
-
[27]
The Effect of On- line Ad Campaigns on DDoS-attacks: A Cross-National Difference-in-Differences Quasi-Experiment
Asier Moneva and Rutger Leukfeldt. The Effect of On- line Ad Campaigns on DDoS-attacks: A Cross-National Difference-in-Differences Quasi-Experiment. Criminol- ogy & Public Policy, 2023. DOI:10.1111/1745-9133. 12649
2023 doi
-
[28]
German Police Raid DDoS-Friendly Host ‘FlyHosting’
Krebs on Security. German Police Raid DDoS-Friendly Host ‘FlyHosting’. https://rb.gy/umd3wc, 2023
2023
-
[29]
Like Aspirin for Arthritis
David Décary-Hétu, Camille Faubert, Julien Chopin, Aili Malm, Jerry Ratcliffe, and Benoît Dupont. “Like Aspirin for Arthritis”: A Qualitative Study of Condi- tional Cyber-Deterrence Associated With Police Crack- downs on the Dark Web. Criminology & Public Policy,
-
[30]
Department of Justice
U.S. Department of Justice. Texas Man Sentenced to 9 Months in Federal Prison for Operating Website That Offered Computer Attack Services. https://rb.gy/ jgfqni, 2024
2024
-
[31]
DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany
BleepingComputer. DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany. https://rb.gy/z02r 1s, 2024
2024
-
[32]
DDoS Platform Shut Down by Interna- tional Law Enforcement Agencies
Heise Online. DDoS Platform Shut Down by Interna- tional Law Enforcement Agencies. https://rb.gy/ 5xbiie, 2024
2024
-
[33]
After AlphaBay’s Demise, Cus- tomers Flocked to Dark Market Run by Dutch Police
Krebs on Security. After AlphaBay’s Demise, Cus- tomers Flocked to Dark Market Run by Dutch Police. https://rb.gy/2psdys, 2017
2017
-
[34]
DarkMarket: Cyberthieves, Cybercops and You
Misha Glenny. DarkMarket: Cyberthieves, Cybercops and You. Random House, 2011. https://rb.gy/to znfd
2011
-
[35]
Law Enforcement Shuts Down 27 DDoS Booters Ahead of Annual Christmas Attacks
EuroPol. Law Enforcement Shuts Down 27 DDoS Booters Ahead of Annual Christmas Attacks. https: //rb.gy/rfb6im, 2024
2024
-
[36]
UK National Crime Agency Reveals It Ran Fake DDoS-for-hire Sites to Collect Users’ Data
The Record. UK National Crime Agency Reveals It Ran Fake DDoS-for-hire Sites to Collect Users’ Data. https://rb.gy/99u6yl, 2023
2023
-
[37]
National Crime Agency: Govern- ment Request Removal Complaint to Google
The Lumen Database. National Crime Agency: Govern- ment Request Removal Complaint to Google. https: //rb.gy/wbr9u8, 2024
2024
-
[38]
Department of Justice
U.S. Department of Justice. Eighteen Individuals and Entities Charged in International Operation Targeting Widespread Fraud and Manipulation in the Cryptocur- rency Markets. https://rb.gy/rvkxvi, 2024
2024
-
[39]
AmpPot: Monitoring and Defend- ing Against Amplification DDoS Attacks
Lukas Krämer, Johannes Krupp, Daisuke Makita, To- momi Nishizoe, Takashi Koide, Katsunari Yoshioka, and Christian Rossow. AmpPot: Monitoring and Defend- ing Against Amplification DDoS Attacks. In Proceed- ings of the International Symposium on Research in Attacks, Intrusions, ...
2015 doi
-
[40]
DDoS Threat Intelligence Report
NETSCOUT . DDoS Threat Intelligence Report. https: //rb.gy/vfi31x, 2023. 16 Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings In Proceedings of the USENIX Security Symposium 2025
2023
-
[41]
Thomas, Richard Clayton, and Alastair R
Daniel R. Thomas, Richard Clayton, and Alastair R. Beresford. 1000 Days of UDP Amplification DDoS Attacks. In Proceedings of the APWG Symposium on Electronic Crime Research (eCrime), 2017. DOI:10.1 109/ECRIME.2017.7945057
2017
-
[42]
Worldwide Desktop Market Share of Leading Search Engines From January 2015 to December 2022
Statista. Worldwide Desktop Market Share of Leading Search Engines From January 2015 to December 2022. https://rb.gy/fgaax5, 2023
2015
-
[43]
Cloudflare IP Geolocation
Cloudflare. Cloudflare IP Geolocation. https://rb.g y/k455xp, 2024
2024
-
[44]
Thomas, Alice Hutchings, and Richard Clayton
Sergio Pastrana, Daniel R. Thomas, Alice Hutchings, and Richard Clayton. CrimeBB: Enabling Cybercrime Research on Underground Forums at Scale. In Proceed- ings of the ACM World Wide Web Conference (WWW),
-
[45]
Monthly Visits Calculation
Similarweb. Monthly Visits Calculation. https://rb .gy/17rzr7, 2024
2024
-
[46]
Organic Traffic Insights Manual
Semrush. Organic Traffic Insights Manual. https: //rb.gy/yewqc6, 2024
2024
-
[47]
Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C
Raphael Hiesgen, Marcin Nawrocki, Marinho Barcel- los, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doer, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, and KC Claffy. The Age...
2024 doi
-
[48]
MaxMind GeoIP® Databases
MaxMind. MaxMind GeoIP® Databases. https://rb .gy/h6ryno, 2024
2024
-
[49]
Vu, Daniel R
Anh V . Vu, Daniel R. Thomas, Ben Collier, Alice Hutch- ings, Richard Clayton, and Ross Anderson. Getting Bored of Cyberwar: Exploring the Role of Low-Level Cybercrime Actors in the Russia-Ukraine Conflict. In Proceedings of the ACM World Wide Web Conference (WWW), 2024. DOI:1...
2024
-
[50]
Amplification Hell: Revisiting Net- work Protocols for DDoS Abuse
Christian Rossow. Amplification Hell: Revisiting Net- work Protocols for DDoS Abuse. In Proceedings of the Network and Distributed System Security Symposium (NDSS), 2014. DOI:10.14722/NDSS.2014.23233
2014
-
[51]
Characterizing Eve: Analysing Cy- bercrime Actors in a Large Underground Forum
Sergio Pastrana, Alice Hutchings, Andrew Caines, and Paula Buttery. Characterizing Eve: Analysing Cy- bercrime Actors in a Large Underground Forum. In Proceedings of the International Symposium on Re- search in Attacks, Intrusions, and Defenses (RAID) ,
-
[52]
Schmidt, and Matthias Wählisch
Marcin Nawrocki, John Kristoff, Raphael Hiesgen, Chris Kanich, Thomas C. Schmidt, and Matthias Wählisch. SoK: A Data-Driven View on Methods to Detect Re- flective Amplification DDoS Attacks Using Honey- pots. In Proceedings of the IEEE European Sympo- sium on Security and Priv...
2023
-
[53]
Breaking the Ice: Using Transparency to Overcome the Cold Start Problem in an Underground Market
Tina Marjanov, Ioannidis Konstantinos, Tom Hyndman, Nicolas Seyedzadeh, and Alice Hutchings. Breaking the Ice: Using Transparency to Overcome the Cold Start Problem in an Underground Market. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2024. ...
2024
-
[54]
Digital Drift and the Evolution of a Large Cybercrime Forum
Jack Hughes and Alice Hutchings. Digital Drift and the Evolution of a Large Cybercrime Forum. In Pro- ceedings of the IEEE European Symposium on Secu- rity and Privacy Workshops (EuroS&PW), 2023. DOI: 10.1109/EUROSPW59978.2023.00026
2023
-
[55]
Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service
Fieke Miedema, Kelvin Lubbertsen, Verena Schrama, and Rolf Van Wegberg. Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service. In Proceedings of the USENIX Security Symposium (USENIX Security) , 2023. DOI: 10.5555/3620237.3620280
2023
-
[56]
DOI:10.1007/978-3-030-00470-5_10
-
[57]
Vu, Jack Hughes, Ildiko Pete, Ben Collier, Yi Ting Chua, Ilia Shumailov, and Alice Hutchings
Anh V . Vu, Jack Hughes, Ildiko Pete, Ben Collier, Yi Ting Chua, Ilia Shumailov, and Alice Hutchings. Turning Up the Dial: The Evolution of a Cybercrime Market Through Set-Up, Stable, and Covid-19 Eras. In Proceedings of the ACM Internet Measurement Confer- ence (IMC), 2020. D...
2020
-
[58]
Braga and Brenda J
Anthony A. Braga and Brenda J. Bond. Policing Crime and Disorder Hot Spots: A Randomized Controlled Trial. Criminology, 2008. DOI:10.1111/J.1745-9125.20 08.00124.X
2008 doi
-
[59]
The Ef- fect of Reduced Street Lighting on Road Casualties and Crime in England and Wales: Controlled Interrupted Time Series Analysis
Rebecca Steinbach, Chloe Perkins, Lisa Tompson, Shane Johnson, Ben Armstrong, Judith Green, Chris Grundy, Paul Wilkinson, and Phil Edwards. The Ef- fect of Reduced Street Lighting on Road Casualties and Crime in England and Wales: Controlled Interrupted Time Series Analysis. J...
2015 doi
-
[60]
Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks
Harm Griffioen, Kris Oosthoek, Paul van der Knaap, and Christian Doerr. Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks. In Proceedings of the ACM Conference on Computer and Communica- tions Security (CCS), 2021. DOI:10.1145/3460120. 3484747
2021 doi
-
[61]
Ben Collier, Richard Clayton, Alice Hutchings, and Daniel R. Thomas. Cybercrime Is (Often) Boring: Main- taining the Infrastructure of Cybercrime Economies. In Proceedings of the Workshop on the Economics of Infor- mation Security (WEIS), 2020. https://rb.gy/qf5r yi
2020
-
[62]
Harvey and Clara Fernandes
Andrew C. Harvey and Clara Fernandes. Time Series Models for Count or Qualitative Observations. Journal of Business & Economic Statistics, 1989. DOI:10.108 0/07350015.1989.10509750
1989
-
[63]
The Impact of In- centives on Notice and Take-Down
Tyler Moore and Richard Clayton. The Impact of In- centives on Notice and Take-Down. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2008. DOI:10.1007/978-0-387-09762-6_1 0
2008 doi
-
[64]
The Ghosts of Bank- ing Past: Empirical Analysis of Closed Bank Websites
Tyler Moore and Richard Clayton. The Ghosts of Bank- ing Past: Empirical Analysis of Closed Bank Websites. In Proceedings of the International Conference on Fi- nancial Cryptography and Data Security (FC) , 2014. DOI:10.1007/978-3-662-45472-5_3
2014 doi
-
[65]
Domain- Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains
Chaz Lever, Robert Walls, Yacin Nadji, David Dagon, Patrick McDaniel, and Manos Antonakakis. Domain- Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2016. DOI:10.1109/SP.2016.47
2016 doi
-
[66]
BERTopic: Neural Topic Mod- eling With a Class-Based TF-IDF Procedure
Maarten Grootendorst. BERTopic: Neural Topic Mod- eling With a Class-Based TF-IDF Procedure. https: //arxiv.org/pdf/2203.05794, 2022. Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings 17 In Proceedings of the USENIX Security Symposium 2025
2022 arXiv
-
[67]
Blei, Andrew Y
David M. Blei, Andrew Y . Ng, and Michael I. Jordan. Latent Dirichlet Allocation. Journal of Machine Learn- ing Research, 2003. DOI:10.5555/944919.944937
2003
-
[68]
Beheading Hydras: Per- forming Effective Botnet Takedowns
Yacin Nadji, Manos Antonakakis, Roberto Perdisci, David Dagon, and Wenke Lee. Beheading Hydras: Per- forming Effective Botnet Takedowns. In Proceedings of the ACM Conference on Computer and Communica- tions Security (CCS), 2013. DOI:10.1145/2508859. 2516749
2013 doi
-
[69]
Still Beheading Hydras: Botnet Takedowns Then and Now
Yacin Nadji, Roberto Perdisci, and Manos Antonakakis. Still Beheading Hydras: Botnet Takedowns Then and Now. IEEE Transactions on Dependable and Secure Computing, 2015. DOI:10.1109/TDSC.2015.249617 6
2015
-
[70]
Measuring the Lon- gitudinal Evolution of the Online Anonymous Mar- ketplace Ecosystem
Kyle Soska and Nicolas Christin. Measuring the Lon- gitudinal Evolution of the Online Anonymous Mar- ketplace Ecosystem. In Proceedings of the USENIX Security Symposium (USENIX Security) , 2015. DOI: 10.5555/2831143.2831146
2015
-
[71]
Cracking Wall of Confinement: Understanding and Analyzing Malicious Domain Takedowns
Eihal Alowaisheq, Peng Wang, Sumayah Alrwais, Xi- aojing Liao, XiaoFeng Wang, Tasneem Alowaisheq, Xi- anghang Mi, Siyuan Tang, and Baojun Liu. Cracking Wall of Confinement: Understanding and Analyzing Malicious Domain Takedowns. In Proceedings of the Network and Distributed Sy...
2019
-
[72]
Examining the Im- pact of Website Take-Down on Phishing
Tyler Moore and Richard Clayton. Examining the Im- pact of Website Take-Down on Phishing. InProceedings of the APWG Symposium on Electronic Crime Research (eCrime), 2007. DOI:10.1145/1299015.1299016
2007
-
[73]
LockBit Ransomware Group Resur- faces After Law Enforcement Takedown
The Hacker News. LockBit Ransomware Group Resur- faces After Law Enforcement Takedown. https: //rb.gy/quxzuj, 2024
2024
-
[74]
Take Downs and the Rest of Us: Do They Matter? https://rb.gy/4arzr9, 2024
Johannes Ullrich. Take Downs and the Rest of Us: Do They Matter? https://rb.gy/4arzr9, 2024
2024
-
[75]
Michael Golz and Daniel J. D’Amico. Market Con- centration in the International Drug Trade. Journal of Economic Behavior & Organization , 2018. DOI: 10.1016/J.JEBO.2018.03.025
2018 doi
-
[76]
Post-Mortem of a Zombie: Conficker Cleanup After Six Years
Hadi Asghari, Michael Ciere, and Michel JG Van Eeten. Post-Mortem of a Zombie: Conficker Cleanup After Six Years. In Proceedings of the USENIX Security Sympo- sium (USENIX Security), 2015. DOI:10.5555/283114 3.2831144
2015 doi
-
[77]
VPNFilter Two Years Later: Routers Still Compromised
Trend Micro. VPNFilter Two Years Later: Routers Still Compromised. https://rb.gy/iczsp8, 2021
2021
-
[78]
Vu, Alice Hutchings, and Ross Anderson
Anh V . Vu, Alice Hutchings, and Ross Anderson. No Easy Way Out: The Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2024. DOI:10.1109/SP54263.2024 .00007
2024
-
[79]
Peer(ing) Pressure: Achieving Social Action at Scale in the Internet Infras- tructure
Ben Collier and Richard Clayton. Peer(ing) Pressure: Achieving Social Action at Scale in the Internet Infras- tructure. In Proceedings of the Workshop on the Eco- nomics of Information Security (WEIS), 2024. https: //rb.gy/hfd5t7
2024
-
[80]
Thomas, Richard Clayton, Al- ice Hutchings, and Yi Ting Chua
Ben Collier, Daniel R. Thomas, Richard Clayton, Al- ice Hutchings, and Yi Ting Chua. Influence, Infras- tructure, and Recentering Cybercrime Policing: Evaluat- ing Emerging Approaches to Online Law Enforcement Through a Market for Cybercrime Services. Policing and Society, 202...
2022
-
[81]
Vu, Alice Hutchings, and Ross Anderson
Anh V . Vu, Alice Hutchings, and Ross Anderson. De- facement Attacks on Israeli Websites. https://rb.g y/nt2ct1, 2023
2023
-
[82]
Taking Down Websites to Prevent Crime
Alice Hutchings, Richard Clayton, and Ross Anderson. Taking Down Websites to Prevent Crime. In Proceed- ings of the APWG Symposium on Electronic Crime Re- search (eCrime), 2016. DOI:10.1109/ECRIME.2016. 7487947
2016 doi
-
[83]
Statement of Ethics
British Society of Criminology. Statement of Ethics. https://rb.gy/biz84j, 2015
2015
-
[84]
Vu, Ildiko Pete, and Yi Ting Chua
Lydia Wilson, Anh V . Vu, Ildiko Pete, and Yi Ting Chua. Identifying and Collecting Public Domain Data for Tracking Cybercrime and Online Extremism. In Open- Source Verification in the Age of Google. World Scien- tific, 2024. DOI:10.1142/9781800614079_0015
2024 doi
-
[85]
Legal Framework
Cambridge Cybercrime Centre. Legal Framework. ht tps://rb.gy/25209m, 2016. 18 Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings
2016
-
[86]
Un- derstanding Ransomware Threat Actors: LockBit
Cybersecurity and Infrastructure Security Agency. Un- derstanding Ransomware Threat Actors: LockBit. http s://rb.gy/3a2xwi, 2023
2023
-
[87]
Web Scraping Is Legal, U.S
TechCrunch. Web Scraping Is Legal, U.S. Appeals Court Reaffirms. https://rb.gy/qll31h, 2022
2022
-
[2016]
DOI:10.1080/01639625.2016.1169829
2016
-
[2018]
DOI:10.1145/3178876.3186178
-
[2023]
DOI:10.1111/1745-9133.12642
Reviewed August 8, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.