460 Large Scale and Big Data
14.6 RELATED WORK
This chapter is based on work on characterizing the behavior of IPs, trafc anomaly
detection, and detecting abusive clicks.
14.6.1 CharaCterizing the behavior oF iPs
The work discussed in this chapter complements the work on characterizing the
behavior of IPs [1,4,7,27,28]. The use of traceroute data and the geographic mappings
of IPs were explored in [7] to study the geographic properties of IP prexes, while
[27,28] focused on identifying dynamic IPs for email spam ltering.
The work that is most related to estimating sizes of IPs deals with counting the
hosts behind NAT devices [1,4]. The work in [1] presented a technique for counting
the hosts behind a NAT using the IPid eld. The techn