Pith. sign in

REVIEW 4 major objections 6 minor 89 references

Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services

T0 review · 4 major / 6 minor · reviewed 2026-08-08 · deepseek-v4-flash

Pith's one-line read The paper claims that the first wave of a global DDoS-for-hire takedown produced a statistically significant 20–40% reduction in UDP-based attack volume, while the second wave did not, and the effect lasted about six weeks.

desk verdict Ground-truth data makes this the definitive measurement of the booter takedown, but the headline 20-40% causal estimate remains a soft upper bound. read the letter →

arxiv 2502.04753 v1 pith:EP6S6HZD submitted 2025-02-07 cs.CR

classification cs.CR
keywords DDoS-for-hirebootertakedowninterruptedtimeseriesnegativebinomialregressionUDPamplificationattackscybercrimemarketresilienceseizeddomainsonlineinfluenceoperations
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper examines the two-wave global takedown of DDoS-for-hire ('booter') services that began in December 2022 and asks whether the intervention actually reduced global DDoS attack volume. Using four independent attack datasets, web-traffic analytics, ground-truth visits to seized domains, and chat/forum discussions, it finds that the first wave produced a statistically significant 20–40% drop in UDP-based attacks, that the drop lasted at most about six weeks, and that the second wave had no significant effect. It also finds that half of the seized booters returned within about a day, yet the resurrected domains attracted 80–90% less traffic, and that some operators quit while user perceptions of risk shifted. The sympathetic reading is that even the largest booter takedown to date was a short-lived supply disruption rather than a durable market fix.

What carries the argument

The load-bearing method is interrupted time-series analysis with negative binomial regression applied to weekly DDoS attack counts. The model includes underlying trend, day-of-week and month seasonality, and intervention components whose start, duration, and end are selected by inspecting the data and testing fit, and the same specification is applied independently to four datasets. This is the mechanism that separates the takedown signal from the normal Christmas decline and from random noise. Around it, the paper triangulates ground-truth visits to seized splash pages, web-analytics estimates, and qualitative analysis of forum and chat discussions.

What would settle it

Re-run the same negative binomial specification on a placebo intervention placed at a date with no takedown (for example, October 2022), or compare the December 2022 drop with the same-calendar period from a year with no takedown; if the placebo produces a drop of similar size, the attribution to the takedown fails.

Watch

Extended reading notes

Core claim

The central claim is that the first wave on 14 December 2022 significantly disrupted the supply side of the DDoS-for-hire market, cutting global UDP-based DDoS attack volume by roughly 20–40% for about six weeks, while the second wave on 5 May 2023 had no statistically significant effect. The observed effect is specific to UDP-based attacks, the vector most commonly associated with booters, and is not seen for TCP-based attacks. The recovery was not driven by the seized booters regaining traffic: resurrected domains attracted 80–90% fewer visits, and the rebound came instead from smaller or new services, while two large booters that survived both waves kept roughly steady market shares. On the paper's account, the takedown's measurable legacy is a temporary dip in one attack class plus a durable change in risk perception and user engagement, not a lasting reduction in global attack volume.

Load-bearing premise

The central claim rests on the assumption that the drop in UDP attack counts after the first wave is the takedown's effect and not mostly the usual Christmas-holiday decline.

Editorial extensions

If this is right

  • If the first-wave estimate is right, a sufficiently large and coordinated takedown can cut global UDP-based DDoS attack volume by a fifth to two-fifths within weeks, a measurable but bounded effect.
  • Because the second wave showed no significant effect even though all seized booters returned, repeating the same tactic does not automatically deepen the disruption.
  • The 80–90% traffic loss of resurrected domains implies that takedowns damage customer trust and visibility even when supply is quickly restored, so the market does not fully snap back.
  • Since all four DDoS datasets recover within roughly six weeks, the paper implies that single interventions should be judged as temporary suppression, with sustained or repeated pressure required to hold the gain.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural extension the paper leaves implicit: if takedowns selectively cut UDP attacks, some displacement toward TCP-based or direct-path attack vectors should appear in the months after a wave; checking whether the TCP share rose after December 2022 would test that displacement.
  • The inconsistent Christmas-2021 control across datasets suggests the seasonal baseline is not uniform, so a multi-year, multi-dataset control series would sharpen future causal estimates.
  • The brief spike in visits to law-enforcement-run deceptive domains, followed by a quick fade, suggests that influence operations need continuous top-up to hold attention; running them alongside each wave could create longer deterrence.
  • If the six-week recovery is a robust feature, then takedown timing may matter more than scale: scheduling waves just before peak-attack periods such as school holidays or Christmas could convert a short-lived dip into a meaningful seasonal reduction in harm.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper evaluates a two-wave international takedown of DDoS-for-hire ('booter') services that began in December 2022, using an unusually rich set of data sources: ground-truth traffic to seized and police-deployed domains, Similarweb analytics, four independent DDoS attack datasets (HOPSCOTCH, AMPPOT, NETSCOUT, and self-reported statistics), underground forum posts, and Telegram chat logs. The main findings are that many seized booters resurrected quickly (52% of first-wave booters within a median of 19 hours; 100% of second-wave booters within a median of 42 hours), that resurrected domains attracted 80–90% less traffic than before, that the first wave coincided with a statistically significant but short-lived decline in UDP-based attack volumes lasting about six weeks while the second wave had no significant effect, and that underground discussions show increased perceptions of enforcement risk and some operator exits. The paper concludes that the intervention had meaningful but temporary effects and discusses implications for future takedown strategies.

Significance. This is a valuable empirical study of a real, ongoing law enforcement operation, and it makes several novel contributions: the ground-truth splash-page data offer a rarely available view of user behavior during a takedown; the resurrection and reinstallation timing measurements are new; the observation of API-based reselling and the analysis of NCA deceptive domains are original; and the triangulation across four independent DDoS datasets is a strength. The paper is also commendably transparent about its limitations, including the possibility that the measured first-wave effect is an upper bound that includes concurrent seasonal declines. However, the headline quantitative claim—that the first wave cut global DDoS attack volume by 20–40% with a statistically significant effect on UDP-based attacks—is less secure than the paper's abstract suggests because the intervention windows are selected after inspecting the data and the only same-season control (Xmas'21) gives inconsistent results across datasets.

major comments (4)
  1. [§5.2, 'The Overall Picture' and Tables 2–5] The intervention periods for both takedown waves are selected data-dependently: the paper states that 'we specify an intervention period through observation and testing of different durations, start, and end points for fit and feasibility.' This post hoc selection inflates the significance of the reported coefficients because the model is chosen to fit the observed drop, and no correction is made for the number of alternative windows examined. Please report the grid of candidate windows tested, state the selection rule (e.g., best fit by AIC/BIC), and provide a sensitivity analysis showing that the 1st-wave coefficient remains significant across a range of pre-specified windows, or use a formal model-averaging or placebo-based approach.
  2. [§5.2, Tables 2–5 vs. Abstract] The abstract's '20–40%' reduction is not consistent with the reported negative binomial coefficients. The implied multiplicative reductions are approximately 39% (HOPSCOTCH, coef −0.499), 43% (AMPPOT, coef −0.564), 16% (NETSCOUT UDP, coef −0.172), and 13% (self-reported, coef −0.138). The paper should either explicitly define how the 20–40% range was computed (e.g., as the interquartile range across datasets), or correct the abstract and the §5.2 summary to reflect the actual coefficient magnitudes.
  3. [§5.2, 'The Overall Picture' and Xmas'21 control] The Xmas'21 control, which is the only same-season counterfactual, is inconsistent across datasets: it is statistically significant in HOPSCOTCH (−0.459, p<0.05) and NETSCOUT UDP (−0.193, p<0.01) but not in AMPPOT (+0.215, p=0.25) or self-reported data (−0.096, p=0.062). The paper's justification that 'NETSCOUT (the most stable one)' should be weighted more heavily is ad hoc and does not resolve the seasonal-confounding concern, especially since the paper itself concedes that 'declines in attacks around Christmas are also quite common.' Please provide a formal placebo analysis using the Xmas'21 period as a falsification test, or explicitly model seasonal variation using more than one prior year, and discuss how the conclusion would change if the seasonal component were estimated differently.
  4. [§5.2, 'The Overall Picture'] The paper's own caveat that 'the impact may thus reflect a combined upper bound effect of all events... the takedown impact alone may be even less significant' is in tension with the abstract's causal wording ('the first wave cut the global DDoS attack volume by 20–40%'). The central claim as stated in the abstract is a load-bearing assertion that goes beyond what the current modeling approach can establish. Please either temper the abstract and the §5.2 takeaways to describe the result as an upper-bound estimate associated with the takedown and concurrent seasonal events, or provide additional evidence (e.g., difference-in-differences against a non-holiday control period, or a model excluding the Christmas weeks) that isolates the takedown effect.
minor comments (6)
  1. [Abstract] The phrase 'global DDoS attack volume' is broader than what is measured; the significant effect is specifically on UDP-based attacks, and the §5.2 analysis shows no significant effect on TCP-based attacks. Please consider revising the abstract to 'UDP-based DDoS attack volume' for precision.
  2. [Tables 2–5] The negative binomial model tables report only the intervention and seasonal coefficients. For reproducibility, please also report the trend coefficient, the dispersion parameter, the number of observations, and the log-likelihood or AIC for the final model of each dataset.
  3. [§3.2, Self-reported Statistics] The self-reported statistics are collected from 207 booters over two years, but the paper does not state how the panel is balanced (i.e., how many booters are present in each week, and how missing weeks are treated). Please add this information, as attrition or entry of new booters could affect the weekly counts.
  4. [§4.2, Figure 2] The ground-truth daily session counts are shown as an aggregate; given that the top 5 domains account for 40.57% of visits, a per-domain plot or a confidence band around the aggregate would better communicate the variability.
  5. [§5.1, Figure 6] The figure caption says 'pre-takedown' traffic for first-wave resurrected domains includes visits to pre-purchased domains that were later reused; please make this explicit in the caption or the text, because those pre-takedown visits are not to then-active booter domains.
  6. [§5.3, Figure 13] The figure shows a sharp increase in messages and posters after the second wave, but the text does not explain why this increase is attributed to newly seized booters' channels. Please state the criterion used to include channels in this analysis (e.g., all channels of booters seized in either wave) and whether the increase could be an artifact of channel additions.

Circularity Check

1 steps flagged · score 4.0 of 10

Post-hoc intervention-window selection makes the headline significance claim partly self-fitted, but the central finding is not definitionally circular.

  1. fitted input called prediction [Section 5.2, DDoS Attack Volumes (intervention model construction; Tables 2–5, 'The Overall Picture')]
    "For each takedown, we specify an intervention period through observation and testing of different durations, start, and end points for fit and feasibility, incorporating significant interventions stepwise into an overall model."

    The first-wave intervention indicator whose coefficient is tested is not fixed a priori; its start and end are selected by 'observation and testing' of the same weekly attack series it is then used to explain. The reported 'statistically significant impact' is therefore a fit statistic from a model specification chosen to maximize fit, not an independent confirmatory test. With only two years of weekly data and an inconsistent same-season control (Xmas'21), the p-values in Tables 2–5 are inflated by the model-search process. The paper itself concedes that the impact may reflect a combined upper bound of all concurrent events, so the takedown-only attribution is not cleanly identified.

full rationale

This is an empirical measurement study rather than a derivation, so the strongest circularity patterns do not apply. The headline causal estimate is not definitionally tied to its inputs: the 20–40% reduction is computed from negative binomial coefficients on external DDoS datasets, and the traffic, resurrection, and community findings are directly measured. Self-citations to the same authors' prior booter-takedown paper are used to motivate the method and to compare with 2018, but the method is standard and the present datasets include independent NETSCOUT and AMPPOT sources, so this is not load-bearing circularity. The one genuinely circular element is in Section 5.2: the intervention period is specified through observation and testing of different durations, start, and end points for fit. This means the first-wave indicator whose significance is celebrated is partly a data-fitted construct: the same weekly attack series is used first to choose the intervention window and then to test the intervention's effect. Consequently the p-values in Tables 2–5 are not valid confirmatory tests, and the claim that the first wave had a statistically significant impact is partially an artifact of model selection. The paper's own caveat that the impact may be a combined upper bound of all events and that the takedown alone may be even less significant confirms that the attribution is fragile. Because the qualitative, ground-truth, and multi-dataset evidence give the central narrative independent substance, this is partial circularity rather than complete equivalence, hence a score of 4.

Assumptions & free parameters 2 free parameters · 4 assumptions · 0 invented entities

The paper is an empirical measurement study. It introduces no new theoretical entities. The main input assumptions are domain-level: honeypot representativeness, model counterfactual validity, Similarweb reliability, and the accuracy of bot filtering. The only hand-fitted parameters in the statistical analysis are the intervention windows, which are selected post hoc and directly affect the central significance claims.

free parameters (2)
  • 1st wave intervention period = approximately 6 weeks (December 2022 to February 2023)
    Chosen post hoc by observing and testing different durations, start, and end points for fit and feasibility in the negative binomial models (§5.2). The significance of the first-wave effect depends on this window.
  • 2nd wave intervention period = approximately 2 weeks (May 2023)
    Same post hoc selection process; the paper concludes no significant effect, but the window choice still affects model fit and the interpretation of the null result (§5.2).
assumptions (4)
  • domain assumption UDP amplification attacks observed by HOPSCOTCH and AMPPOT honeypots are predominantly generated by booter services
    Used to interpret the significant UDP-specific drop as evidence of booter disruption (§5.2, §2). Prior work supports this attribution [14, 15, 39], but it is not directly verified in this paper.
  • domain assumption The negative binomial regression model with selected intervention periods provides a valid counterfactual for what would have happened absent the takedown
    Load-bearing for the causal claim. The paper acknowledges that 'precisely quantifying and identifying cause-and-effect signals based on raw noisy data is difficult', and the Xmas'21 control yields inconsistent results across datasets (§5.2).
  • domain assumption Similarweb analytics, after validation against ground-truth data, provide a reliable estimate of historical traffic to booter domains
    Used for traffic displacement estimates (80-90% reduction) for periods where ground-truth splash pages are unavailable (§3.1). The validation correlation (r = 0.81) supports this, but it is still an inferential third-party product.
  • domain assumption The ground-truth splash-page traffic reflects real user visits after filtering bots and prefetches
    IP-address-based visitor deduplication and user-agent-based bot filtering are imperfect heuristics; the authors acknowledge this in §3.1.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services." pith.science (2026). https://pith.science/paper/EP6S6HZD

@misc{pith2026250204753,
  author       = {Pith},
  title        = {Pith review of: Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/EP6S6HZD}},
  note         = {Machine review of arXiv:2502.04753}
}
read the original abstract

Law enforcement and private-sector partners have in recent years conducted various interventions to disrupt the DDoS-for-hire market. Drawing on multiple quantitative datasets, including web traffic and ground-truth visits to seized websites, millions of DDoS attack records from academic, industry, and self-reported statistics, along with chats on underground forums and Telegram channels, we assess the effects of an ongoing global intervention against DDoS-for-hire services since December 2022. This is the most extensive booter takedown to date conducted, combining targeting infrastructure with digital influence tactics in a concerted effort by law enforcement across several countries with two waves of website takedowns and the use of deceptive domains. We found over half of the seized sites in the first wave returned within a median of one day, while all booters seized in the second wave returned within a median of two days. Re-emerged booter domains, despite closely resembling old ones, struggled to attract visitors (80-90% traffic reduction). While the first wave cut the global DDoS attack volume by 20-40% with a statistically significant effect specifically on UDP-based DDoS attacks (commonly attributed to booters), the impact of the second wave appeared minimal. Underground discussions indicated a cumulative impact, leading to changes in user perceptions of safety and causing some operators to leave the market. Despite the extensive intervention efforts, all DDoS datasets consistently suggest that the illicit market is fairly resilient, with an overall short-lived effect on the global DDoS attack volume lasting for at most only around six weeks.

Figures

Figures reproduced from arXiv: 2502.04753 by the authors.

Figure 1
Figure 1. Overview of booter resurrections and reinstallations [PITH_FULL_IMAGE:figures/full_fig_p006_1.png] view at source ↗
Figure 2
Figure 2. The aggregated ground-truth visit sessions per day to [PITH_FULL_IMAGE:figures/full_fig_p007_2.png] view at source ↗
Figure 3
Figure 3. The average duration of ground-truth ordinary visit [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figures from the paper (7 more)
Figure 5
Figure 5. Figure 5: Number of API request sessions (top) and calling [PITH_FULL_IMAGE:figures/full_fig_p008_5.png]
Figure 6
Figure 6. Figure 6: Number of web visits and visitors to seized domains (49 first-wave, 13 second-wave), resurrected domains (31 first-wave, [PITH_FULL_IMAGE:figures/full_fig_p009_6.png]
Figure 7
Figure 7. Figure 7: Number of web visits and visitors per each first [PITH_FULL_IMAGE:figures/full_fig_p009_7.png]
Figure 8
Figure 8. Figure 8: Modelled weekly DDoS attacks (HOPSCOTCH) [PITH_FULL_IMAGE:figures/full_fig_p010_8.png]
Figure 9
Figure 9. Figure 9: Modelled weekly DDoS attacks (AMPPOT) [PITH_FULL_IMAGE:figures/full_fig_p011_9.png]
Figure 11
Figure 11. Figure 11: Modelled weekly DDoS attacks (self-reported) [PITH_FULL_IMAGE:figures/full_fig_p012_11.png]
Figure 13
Figure 13. Figure 13: Number of messages, posters, and reactions of [PITH_FULL_IMAGE:figures/full_fig_p013_13.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

89 extracted references · 63 canonical work pages

  1. [1]

    Ugur Akyazi, Michel van Eeten, and Carlos H. Gañán. Measuring Cybercrime as a Service (CaaS) Offerings in a Cybercrime Forum. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2021. https://rb.gy/rpbvlx

  2. [2]

    Thomas S. Hyslip. Cybercrime-as-a-Service Operations. In The Palgrave Handbook of International Cybercrime and Cyberdeviance. Palgrave Macmillan, 2020. DOI: 10.1007/978-3-319-78440-3_36

  3. [3]

    Cybercrime Is (Often) Boring: Infras- tructure and Alienation in a Deviant Subculture

    Ben Collier, Richard Clayton, Alice Hutchings, and Daniel Thomas. Cybercrime Is (Often) Boring: Infras- tructure and Alienation in a Deviant Subculture. The British Journal of Criminology, 2021. DOI:10.1093/ BJC/AZAB026

  4. [4]

    Understand- ing the Emerging Threat of DDoS-as-a-service

    Mohammad Karami and Damon McCoy. Understand- ing the Emerging Threat of DDoS-as-a-service. In Proceedings of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET) , 2013. DOI: 10.5555/3241085.3241093

  5. [5]

    Exploring the Provision of Online Booter Services

    Alice Hutchings and Richard Clayton. Exploring the Provision of Online Booter Services. Deviant Behavior,

  6. [6]

    Booters: Can Anything Justify Distributed Denial-of-Service (DDoS) Attacks for Hire? Journal of Information, Communication and Ethics in Society, 2017

    David Douglas, José Jair Santanna, Ricardo de Oliveira Schmidt, Lisandro Zambenedetti Granville, and Aiko Pras. Booters: Can Anything Justify Distributed Denial-of-Service (DDoS) Attacks for Hire? Journal of Information, Communication and Ethics in Society, 2017. DOI:10.1108/JICES-09-2016-0033

  7. [7]

    Department of Justice

    U.S. Department of Justice. Criminal Charges Filed in Los Angeles and Alaska in Conjunction With Seizures of 15 Websites Offering DDoS-For-Hire Services. ht tps://rb.gy/96rntp, 2018

  8. [9]

    DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown

    Daniel Kopp, Matthias Wichtlhuber, Ingmar Poese, Jair Santanna, Oliver Hohlfeld, and Christoph Dietzel. DDoS Hide & Seek: On the Effectiveness of a Booter Services Takedown. In Proceedings of the ACM Internet Mea- surement Conference (IMC), 2019. DOI:10.1145/33 55369.3355590

Show all 89 references
  1. [10]

    Department of Justice

    U.S. Department of Justice. Federal Prosecutors in Alaska and Los Angeles Charge 6 Defendants With Operating Websites That Offered Computer Attack Ser- vices. https://rb.gy/dz8te5, 2022

  2. [11]

    Department of Justice

    U.S. Department of Justice. Federal Authorities Seize 13 Internet Domains Associated With ‘Booter’ Websites That Offered DDoS Computer Attack Services. https: //rb.gy/phuc1j, 2023

  3. [12]

    Department of Justice

    U.S. Department of Justice. Illinois Man Convicted of Federal Criminal Charges for Operating Subscription- Based Computer Attack Platforms. https://rb.gy/ cxy7u0, 2021

  4. [13]

    Thinking of Hiring or Running a Booter Service? Think Again

    Krebs on Security. Thinking of Hiring or Running a Booter Service? Think Again. https://rb.gy/hvl5 qe, 2023

  5. [14]

    Vu, Ben Collier, Daniel R

    José Jair Santanna, Roland van Rijswijk-Deij, Rick Hof- Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings 15 In Proceedings of the USENIX Security Symposium 2025 stede, Anna Sperotto, Mark Wierbosch, Lisandro Zam- benedetti Granvill...

  6. [15]

    Linking Ampli- fication DDoS Attacks to Booter Services

    Johannes Krupp, Mohammad Karami, Christian Rossow, Damon McCoy, and Michael Backes. Linking Ampli- fication DDoS Attacks to Booter Services. In Proceed- ings of the International Symposium on Research in Attacks, Intrusions, and Defenses (RAID), 2017. DOI: 10.1007/978-3-319-66332-6_19

  7. [16]

    Department of Justice

    U.S. Department of Justice. Gatrel and Martinez Com- plaint. https://rb.gy/q364o2, 2018

  8. [17]

    Stress Testing the Booters: Understanding and Un- dermining the Business of DDoS Services

    Mohammad Karami, Youngsam Park, and Damon Mc- Coy. Stress Testing the Booters: Understanding and Un- dermining the Business of DDoS Services. In Proceed- ings of the ACM World Wide Web Conference (WWW),

  9. [18]

    UK Man Gets Two Years in Jail for Running ‘Titanium Stresser’ Attack-for-Hire Service

    Krebs on Security. UK Man Gets Two Years in Jail for Running ‘Titanium Stresser’ Attack-for-Hire Service. https://rb.gy/i620ib, 2017

  10. [19]

    DOI:10.1145/2872427.2883004

  11. [20]

    Olga Smirnova and Thomas J. Holt. Exploring and Estimating the Revenues of Cybercrime-as-Service Providers: Analyzing Booter and Stresser Services. De- viant Behavior, 2024. DOI:10.1080/01639625.2024. 2373346

  12. [21]

    Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years

    Krebs on Security. Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years. https://rb.gy/jqky iu, 2016

  13. [22]

    Booted: An Analysis of a Payment Intervention on a DDoS-for-hire Service

    Ryan Brunt, Prakhar Pandey, and Damon McCoy. Booted: An Analysis of a Payment Intervention on a DDoS-for-hire Service. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2017. https://rb.gy/5iia4e

  14. [23]

    Following the Money Hobbled vDOS Attack-for-Hire Service

    Krebs on Security. Following the Money Hobbled vDOS Attack-for-Hire Service. https://rb.gy/rsuc9u , 2017

  15. [24]

    Google Doesn’t Seem to Believe Boot- ers Are Illegal

    Richard Clayton. Google Doesn’t Seem to Believe Boot- ers Are Illegal. https://rb.gy/snsach, 2018

  16. [25]

    Hackforums Shutters Booter Service Bazaar

    Krebs on Security. Hackforums Shutters Booter Service Bazaar. https://rb.gy/myo8hx, 2016

  17. [26]

    An Evaluation of Police Interven- tions for Cybercrime Prevention

    Maria Bada, Alice Hutchings, Yanna Papadodimitraki, and Richard Clayton. An Evaluation of Police Interven- tions for Cybercrime Prevention. Technical report, Uni- versity of Cambridge, 2023. https://rb.gy/54622u

  18. [27]

    The Effect of On- line Ad Campaigns on DDoS-attacks: A Cross-National Difference-in-Differences Quasi-Experiment

    Asier Moneva and Rutger Leukfeldt. The Effect of On- line Ad Campaigns on DDoS-attacks: A Cross-National Difference-in-Differences Quasi-Experiment. Criminol- ogy & Public Policy, 2023. DOI:10.1111/1745-9133. 12649

  19. [28]

    German Police Raid DDoS-Friendly Host ‘FlyHosting’

    Krebs on Security. German Police Raid DDoS-Friendly Host ‘FlyHosting’. https://rb.gy/umd3wc, 2023

  20. [29]

    Like Aspirin for Arthritis

    David Décary-Hétu, Camille Faubert, Julien Chopin, Aili Malm, Jerry Ratcliffe, and Benoît Dupont. “Like Aspirin for Arthritis”: A Qualitative Study of Condi- tional Cyber-Deterrence Associated With Police Crack- downs on the Dark Web. Criminology & Public Policy,

  21. [30]

    Department of Justice

    U.S. Department of Justice. Texas Man Sentenced to 9 Months in Federal Prison for Operating Website That Offered Computer Attack Services. https://rb.gy/ jgfqni, 2024

  22. [31]

    DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany

    BleepingComputer. DDoS Site Dstat.cc Seized and Two Suspects Arrested in Germany. https://rb.gy/z02r 1s, 2024

  23. [32]

    DDoS Platform Shut Down by Interna- tional Law Enforcement Agencies

    Heise Online. DDoS Platform Shut Down by Interna- tional Law Enforcement Agencies. https://rb.gy/ 5xbiie, 2024

  24. [33]

    After AlphaBay’s Demise, Cus- tomers Flocked to Dark Market Run by Dutch Police

    Krebs on Security. After AlphaBay’s Demise, Cus- tomers Flocked to Dark Market Run by Dutch Police. https://rb.gy/2psdys, 2017

  25. [34]

    DarkMarket: Cyberthieves, Cybercops and You

    Misha Glenny. DarkMarket: Cyberthieves, Cybercops and You. Random House, 2011. https://rb.gy/to znfd

  26. [35]

    Law Enforcement Shuts Down 27 DDoS Booters Ahead of Annual Christmas Attacks

    EuroPol. Law Enforcement Shuts Down 27 DDoS Booters Ahead of Annual Christmas Attacks. https: //rb.gy/rfb6im, 2024

  27. [36]

    UK National Crime Agency Reveals It Ran Fake DDoS-for-hire Sites to Collect Users’ Data

    The Record. UK National Crime Agency Reveals It Ran Fake DDoS-for-hire Sites to Collect Users’ Data. https://rb.gy/99u6yl, 2023

  28. [37]

    National Crime Agency: Govern- ment Request Removal Complaint to Google

    The Lumen Database. National Crime Agency: Govern- ment Request Removal Complaint to Google. https: //rb.gy/wbr9u8, 2024

  29. [38]

    Department of Justice

    U.S. Department of Justice. Eighteen Individuals and Entities Charged in International Operation Targeting Widespread Fraud and Manipulation in the Cryptocur- rency Markets. https://rb.gy/rvkxvi, 2024

  30. [39]

    AmpPot: Monitoring and Defend- ing Against Amplification DDoS Attacks

    Lukas Krämer, Johannes Krupp, Daisuke Makita, To- momi Nishizoe, Takashi Koide, Katsunari Yoshioka, and Christian Rossow. AmpPot: Monitoring and Defend- ing Against Amplification DDoS Attacks. In Proceed- ings of the International Symposium on Research in Attacks, Intrusions, ...

  31. [40]

    DDoS Threat Intelligence Report

    NETSCOUT . DDoS Threat Intelligence Report. https: //rb.gy/vfi31x, 2023. 16 Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings In Proceedings of the USENIX Security Symposium 2025

  32. [41]

    Thomas, Richard Clayton, and Alastair R

    Daniel R. Thomas, Richard Clayton, and Alastair R. Beresford. 1000 Days of UDP Amplification DDoS Attacks. In Proceedings of the APWG Symposium on Electronic Crime Research (eCrime), 2017. DOI:10.1 109/ECRIME.2017.7945057

  33. [42]

    Worldwide Desktop Market Share of Leading Search Engines From January 2015 to December 2022

    Statista. Worldwide Desktop Market Share of Leading Search Engines From January 2015 to December 2022. https://rb.gy/fgaax5, 2023

  34. [43]

    Cloudflare IP Geolocation

    Cloudflare. Cloudflare IP Geolocation. https://rb.g y/k455xp, 2024

  35. [44]

    Thomas, Alice Hutchings, and Richard Clayton

    Sergio Pastrana, Daniel R. Thomas, Alice Hutchings, and Richard Clayton. CrimeBB: Enabling Cybercrime Research on Underground Forums at Scale. In Proceed- ings of the ACM World Wide Web Conference (WWW),

  36. [45]

    Monthly Visits Calculation

    Similarweb. Monthly Visits Calculation. https://rb .gy/17rzr7, 2024

  37. [46]

    Organic Traffic Insights Manual

    Semrush. Organic Traffic Insights Manual. https: //rb.gy/yewqc6, 2024

  38. [47]

    Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C

    Raphael Hiesgen, Marcin Nawrocki, Marinho Barcel- los, Daniel Kopp, Oliver Hohlfeld, Echo Chan, Roland Dobbins, Christian Doer, Christian Rossow, Daniel R. Thomas, Mattijs Jonker, Ricky Mok, Xiapu Luo, John Kristoff, Thomas C. Schmidt, Matthias Wählisch, and KC Claffy. The Age...

  39. [48]

    MaxMind GeoIP® Databases

    MaxMind. MaxMind GeoIP® Databases. https://rb .gy/h6ryno, 2024

  40. [49]

    Vu, Daniel R

    Anh V . Vu, Daniel R. Thomas, Ben Collier, Alice Hutch- ings, Richard Clayton, and Ross Anderson. Getting Bored of Cyberwar: Exploring the Role of Low-Level Cybercrime Actors in the Russia-Ukraine Conflict. In Proceedings of the ACM World Wide Web Conference (WWW), 2024. DOI:1...

  41. [50]

    Amplification Hell: Revisiting Net- work Protocols for DDoS Abuse

    Christian Rossow. Amplification Hell: Revisiting Net- work Protocols for DDoS Abuse. In Proceedings of the Network and Distributed System Security Symposium (NDSS), 2014. DOI:10.14722/NDSS.2014.23233

  42. [51]

    Characterizing Eve: Analysing Cy- bercrime Actors in a Large Underground Forum

    Sergio Pastrana, Alice Hutchings, Andrew Caines, and Paula Buttery. Characterizing Eve: Analysing Cy- bercrime Actors in a Large Underground Forum. In Proceedings of the International Symposium on Re- search in Attacks, Intrusions, and Defenses (RAID) ,

  43. [52]

    Schmidt, and Matthias Wählisch

    Marcin Nawrocki, John Kristoff, Raphael Hiesgen, Chris Kanich, Thomas C. Schmidt, and Matthias Wählisch. SoK: A Data-Driven View on Methods to Detect Re- flective Amplification DDoS Attacks Using Honey- pots. In Proceedings of the IEEE European Sympo- sium on Security and Priv...

  44. [53]

    Breaking the Ice: Using Transparency to Overcome the Cold Start Problem in an Underground Market

    Tina Marjanov, Ioannidis Konstantinos, Tom Hyndman, Nicolas Seyedzadeh, and Alice Hutchings. Breaking the Ice: Using Transparency to Overcome the Cold Start Problem in an Underground Market. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2024. ...

  45. [54]

    Digital Drift and the Evolution of a Large Cybercrime Forum

    Jack Hughes and Alice Hutchings. Digital Drift and the Evolution of a Large Cybercrime Forum. In Pro- ceedings of the IEEE European Symposium on Secu- rity and Privacy Workshops (EuroS&PW), 2023. DOI: 10.1109/EUROSPW59978.2023.00026

  46. [55]

    Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service

    Fieke Miedema, Kelvin Lubbertsen, Verena Schrama, and Rolf Van Wegberg. Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service. In Proceedings of the USENIX Security Symposium (USENIX Security) , 2023. DOI: 10.5555/3620237.3620280

  47. [56]

    DOI:10.1007/978-3-030-00470-5_10

  48. [57]

    Vu, Jack Hughes, Ildiko Pete, Ben Collier, Yi Ting Chua, Ilia Shumailov, and Alice Hutchings

    Anh V . Vu, Jack Hughes, Ildiko Pete, Ben Collier, Yi Ting Chua, Ilia Shumailov, and Alice Hutchings. Turning Up the Dial: The Evolution of a Cybercrime Market Through Set-Up, Stable, and Covid-19 Eras. In Proceedings of the ACM Internet Measurement Confer- ence (IMC), 2020. D...

  49. [58]

    Braga and Brenda J

    Anthony A. Braga and Brenda J. Bond. Policing Crime and Disorder Hot Spots: A Randomized Controlled Trial. Criminology, 2008. DOI:10.1111/J.1745-9125.20 08.00124.X

  50. [59]

    The Ef- fect of Reduced Street Lighting on Road Casualties and Crime in England and Wales: Controlled Interrupted Time Series Analysis

    Rebecca Steinbach, Chloe Perkins, Lisa Tompson, Shane Johnson, Ben Armstrong, Judith Green, Chris Grundy, Paul Wilkinson, and Phil Edwards. The Ef- fect of Reduced Street Lighting on Road Casualties and Crime in England and Wales: Controlled Interrupted Time Series Analysis. J...

  51. [60]

    Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks

    Harm Griffioen, Kris Oosthoek, Paul van der Knaap, and Christian Doerr. Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks. In Proceedings of the ACM Conference on Computer and Communica- tions Security (CCS), 2021. DOI:10.1145/3460120. 3484747

  52. [61]

    Ben Collier, Richard Clayton, Alice Hutchings, and Daniel R. Thomas. Cybercrime Is (Often) Boring: Main- taining the Infrastructure of Cybercrime Economies. In Proceedings of the Workshop on the Economics of Infor- mation Security (WEIS), 2020. https://rb.gy/qf5r yi

  53. [62]

    Harvey and Clara Fernandes

    Andrew C. Harvey and Clara Fernandes. Time Series Models for Count or Qualitative Observations. Journal of Business & Economic Statistics, 1989. DOI:10.108 0/07350015.1989.10509750

  54. [63]

    The Impact of In- centives on Notice and Take-Down

    Tyler Moore and Richard Clayton. The Impact of In- centives on Notice and Take-Down. In Proceedings of the Workshop on the Economics of Information Security (WEIS), 2008. DOI:10.1007/978-0-387-09762-6_1 0

  55. [64]

    The Ghosts of Bank- ing Past: Empirical Analysis of Closed Bank Websites

    Tyler Moore and Richard Clayton. The Ghosts of Bank- ing Past: Empirical Analysis of Closed Bank Websites. In Proceedings of the International Conference on Fi- nancial Cryptography and Data Security (FC) , 2014. DOI:10.1007/978-3-662-45472-5_3

  56. [65]

    Domain- Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains

    Chaz Lever, Robert Walls, Yacin Nadji, David Dagon, Patrick McDaniel, and Manos Antonakakis. Domain- Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2016. DOI:10.1109/SP.2016.47

  57. [66]

    BERTopic: Neural Topic Mod- eling With a Class-Based TF-IDF Procedure

    Maarten Grootendorst. BERTopic: Neural Topic Mod- eling With a Class-Based TF-IDF Procedure. https: //arxiv.org/pdf/2203.05794, 2022. Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings 17 In Proceedings of the USENIX Security Symposium 2025

  58. [67]

    Blei, Andrew Y

    David M. Blei, Andrew Y . Ng, and Michael I. Jordan. Latent Dirichlet Allocation. Journal of Machine Learn- ing Research, 2003. DOI:10.5555/944919.944937

  59. [68]

    Beheading Hydras: Per- forming Effective Botnet Takedowns

    Yacin Nadji, Manos Antonakakis, Roberto Perdisci, David Dagon, and Wenke Lee. Beheading Hydras: Per- forming Effective Botnet Takedowns. In Proceedings of the ACM Conference on Computer and Communica- tions Security (CCS), 2013. DOI:10.1145/2508859. 2516749

  60. [69]

    Still Beheading Hydras: Botnet Takedowns Then and Now

    Yacin Nadji, Roberto Perdisci, and Manos Antonakakis. Still Beheading Hydras: Botnet Takedowns Then and Now. IEEE Transactions on Dependable and Secure Computing, 2015. DOI:10.1109/TDSC.2015.249617 6

  61. [70]

    Measuring the Lon- gitudinal Evolution of the Online Anonymous Mar- ketplace Ecosystem

    Kyle Soska and Nicolas Christin. Measuring the Lon- gitudinal Evolution of the Online Anonymous Mar- ketplace Ecosystem. In Proceedings of the USENIX Security Symposium (USENIX Security) , 2015. DOI: 10.5555/2831143.2831146

  62. [71]

    Cracking Wall of Confinement: Understanding and Analyzing Malicious Domain Takedowns

    Eihal Alowaisheq, Peng Wang, Sumayah Alrwais, Xi- aojing Liao, XiaoFeng Wang, Tasneem Alowaisheq, Xi- anghang Mi, Siyuan Tang, and Baojun Liu. Cracking Wall of Confinement: Understanding and Analyzing Malicious Domain Takedowns. In Proceedings of the Network and Distributed Sy...

  63. [72]

    Examining the Im- pact of Website Take-Down on Phishing

    Tyler Moore and Richard Clayton. Examining the Im- pact of Website Take-Down on Phishing. InProceedings of the APWG Symposium on Electronic Crime Research (eCrime), 2007. DOI:10.1145/1299015.1299016

  64. [73]

    LockBit Ransomware Group Resur- faces After Law Enforcement Takedown

    The Hacker News. LockBit Ransomware Group Resur- faces After Law Enforcement Takedown. https: //rb.gy/quxzuj, 2024

  65. [74]

    Take Downs and the Rest of Us: Do They Matter? https://rb.gy/4arzr9, 2024

    Johannes Ullrich. Take Downs and the Rest of Us: Do They Matter? https://rb.gy/4arzr9, 2024

  66. [75]

    Michael Golz and Daniel J. D’Amico. Market Con- centration in the International Drug Trade. Journal of Economic Behavior & Organization , 2018. DOI: 10.1016/J.JEBO.2018.03.025

  67. [76]

    Post-Mortem of a Zombie: Conficker Cleanup After Six Years

    Hadi Asghari, Michael Ciere, and Michel JG Van Eeten. Post-Mortem of a Zombie: Conficker Cleanup After Six Years. In Proceedings of the USENIX Security Sympo- sium (USENIX Security), 2015. DOI:10.5555/283114 3.2831144

  68. [77]

    VPNFilter Two Years Later: Routers Still Compromised

    Trend Micro. VPNFilter Two Years Later: Routers Still Compromised. https://rb.gy/iczsp8, 2021

  69. [78]

    Vu, Alice Hutchings, and Ross Anderson

    Anh V . Vu, Alice Hutchings, and Ross Anderson. No Easy Way Out: The Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), 2024. DOI:10.1109/SP54263.2024 .00007

  70. [79]

    Peer(ing) Pressure: Achieving Social Action at Scale in the Internet Infras- tructure

    Ben Collier and Richard Clayton. Peer(ing) Pressure: Achieving Social Action at Scale in the Internet Infras- tructure. In Proceedings of the Workshop on the Eco- nomics of Information Security (WEIS), 2024. https: //rb.gy/hfd5t7

  71. [80]

    Thomas, Richard Clayton, Al- ice Hutchings, and Yi Ting Chua

    Ben Collier, Daniel R. Thomas, Richard Clayton, Al- ice Hutchings, and Yi Ting Chua. Influence, Infras- tructure, and Recentering Cybercrime Policing: Evaluat- ing Emerging Approaches to Online Law Enforcement Through a Market for Cybercrime Services. Policing and Society, 202...

  72. [81]

    Vu, Alice Hutchings, and Ross Anderson

    Anh V . Vu, Alice Hutchings, and Ross Anderson. De- facement Attacks on Israeli Websites. https://rb.g y/nt2ct1, 2023

  73. [82]

    Taking Down Websites to Prevent Crime

    Alice Hutchings, Richard Clayton, and Ross Anderson. Taking Down Websites to Prevent Crime. In Proceed- ings of the APWG Symposium on Electronic Crime Re- search (eCrime), 2016. DOI:10.1109/ECRIME.2016. 7487947

  74. [83]

    Statement of Ethics

    British Society of Criminology. Statement of Ethics. https://rb.gy/biz84j, 2015

  75. [84]

    Vu, Ildiko Pete, and Yi Ting Chua

    Lydia Wilson, Anh V . Vu, Ildiko Pete, and Yi Ting Chua. Identifying and Collecting Public Domain Data for Tracking Cybercrime and Online Extremism. In Open- Source Verification in the Age of Google. World Scien- tific, 2024. DOI:10.1142/9781800614079_0015

  76. [85]

    Legal Framework

    Cambridge Cybercrime Centre. Legal Framework. ht tps://rb.gy/25209m, 2016. 18 Anh V . Vu, Ben Collier, Daniel R. Thomas, John Kristoff, Richard Clayton, and Alice Hutchings

  77. [86]

    Un- derstanding Ransomware Threat Actors: LockBit

    Cybersecurity and Infrastructure Security Agency. Un- derstanding Ransomware Threat Actors: LockBit. http s://rb.gy/3a2xwi, 2023

  78. [87]

    Web Scraping Is Legal, U.S

    TechCrunch. Web Scraping Is Legal, U.S. Appeals Court Reaffirms. https://rb.gy/qll31h, 2022

  79. [2016]

    DOI:10.1080/01639625.2016.1169829

  80. [2018]

    DOI:10.1145/3178876.3186178

  81. [2023]

    DOI:10.1111/1745-9133.12642

Pith tools

Reviewed August 8, 2026 · model on record in the stance chip above.