<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.melegassi-mvps-ddos-resilience" target="https://datatracker.ietf.org/doc/html/draft-melegassi-mvps-ddos-resilience-02">
   <front>
      <title>Volume-Independent DDoS Detection via Coherence-BFD: The MVPS DDoS Resilience Profile</title>
      <author initials="L. M." surname="Costa" fullname="Leonardo Melegassi Costa">
         <organization>Catellix</organization>
      </author>
      <date month="July" day="6" year="2026" />
      <abstract>
	 <t>   This document specifies how the Multi-Vantage Path Synchrony
   (MVPS) framework [I-D.melegassi-ippm-mvps-bundle] and its
   sub-tick variant Coherence-BFD
   [I-D.melegassi-coherence-bfd] detect volumetric and
   distributed Denial-of-Service (DDoS) attacks in time bounded
   by (M-1)*T_tick, INDEPENDENT of the attack rate in packets-
   per-second or bits-per-second.

   Three theorems are proved:

      Theorem D1 (Volume-Independence).  Detection latency is a
      function of the control-tick period T_tick and the
      M-multiplier confirmation count alone; it does not grow
      with attack volume.

      Theorem D2 (Distributed-Attack Bound).  The framework
      detects up to floor((k-1)/2) simultaneous regional
      attacks under cell-aware minimax aggregation, where k is
      the number of coherence cells.

      Theorem D3 (Broker NIC Sizing).  Under the three
      architectural invariants of Section 3, broker NIC sizing
      is independent of attack volume; it is determined only
      by the legitimate telemetry packets-per-second.

   This revision (-02) adds seven confirmed real-world
   DDoS detections using a causally-direct methodology:
   BGP updates measured on each VICTIM&#x27;S OWN announced
   prefix (not on unrelated third-party infrastructure).

     (a) 7 independently confirmed DDoS attacks across
         3 continents (Australia, South Africa, New
         Zealand), spanning two orders of magnitude in
         target size (from a major OS vendor to a small
         22-year-old regional host): VentraIP (600 Gbps),
         Canonical (3.5 Tbps), Binary Lane (400 Gbps),
         Network Platforms (676 Gbps), Xneelo (300 Gbps),
         SiteHost NZ, and 1-Grid (100 Gbps).  30 of 33
         tested prefixes (91%) alarmed on the confirmed
         attack day; 4 of 7 targets show 100% prefix
         corroboration.

     (b) VentraIP: BGP alarm fired the SAME HOUR as
         attack onset (00:00 UTC, D^2=11.7), four hours
         BEFORE mitigation began.  Canonical: BGP alarm
         fired 2 hours BEFORE Cloudflare migration began.

     (c) Joint statistical significance across all 7
         targets (multi-prefix binomial test):
         P &lt; 5.9*10^-60 under the null hypothesis that
         alarms are unrelated to attack timing -- 52
         orders of magnitude beyond the 5-sigma particle-
         physics discovery threshold.

     (d) Volume-independence (D1) confirmed: 1-Grid
         (100 Gbps) produced a HIGHER D^2 (63.2) than
         Canonical (3500 Gbps, D^2=10.6).  Detection
         depends on coherence deformation, not attack
         bandwidth.

     (e) An invalid claim from an intermediate draft
         (RIPE Atlas K-root time-coincidence implying
         53.6-hour pre-report detection) was identified
         via a Monte Carlo control test as a look-
         elsewhere/base-rate artifact and RETRACTED
         (Section 7.7.1), then replaced with the
         causally-direct results above.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-melegassi-mvps-ddos-resilience-02" />
   
</reference>
