@techreport{melegassi-mvps-ddos-resilience-02, number = {draft-melegassi-mvps-ddos-resilience-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-melegassi-mvps-ddos-resilience/02/}, author = {Leonardo Melegassi Costa}, title = {{Volume-Independent DDoS Detection via Coherence-BFD: The MVPS DDoS Resilience Profile}}, pagetotal = 33, year = 2026, month = jul, day = 6, abstract = {This document specifies how the Multi-Vantage Path Synchrony (MVPS) framework {[}I-D.melegassi-ippm-mvps-bundle{]} and its sub-tick variant Coherence-BFD {[}I-D.melegassi-coherence-bfd{]} detect volumetric and distributed Denial-of-Service (DDoS) attacks in time bounded by (M-1)*T\_tick, INDEPENDENT of the attack rate in packets- per-second or bits-per-second. Three theorems are proved: Theorem D1 (Volume-Independence). Detection latency is a function of the control-tick period T\_tick and the M-multiplier confirmation count alone; it does not grow with attack volume. Theorem D2 (Distributed-Attack Bound). The framework detects up to floor((k-1)/2) simultaneous regional attacks under cell-aware minimax aggregation, where k is the number of coherence cells. Theorem D3 (Broker NIC Sizing). Under the three architectural invariants of Section 3, broker NIC sizing is independent of attack volume; it is determined only by the legitimate telemetry packets-per-second. This revision (-02) adds seven confirmed real-world DDoS detections using a causally-direct methodology: BGP updates measured on each VICTIM'S OWN announced prefix (not on unrelated third-party infrastructure). (a) 7 independently confirmed DDoS attacks across 3 continents (Australia, South Africa, New Zealand), spanning two orders of magnitude in target size (from a major OS vendor to a small 22-year-old regional host): VentraIP (600 Gbps), Canonical (3.5 Tbps), Binary Lane (400 Gbps), Network Platforms (676 Gbps), Xneelo (300 Gbps), SiteHost NZ, and 1-Grid (100 Gbps). 30 of 33 tested prefixes (91\%) alarmed on the confirmed attack day; 4 of 7 targets show 100\% prefix corroboration. (b) VentraIP: BGP alarm fired the SAME HOUR as attack onset (00:00 UTC, D\textasciicircum{}2=11.7), four hours BEFORE mitigation began. Canonical: BGP alarm fired 2 hours BEFORE Cloudflare migration began. (c) Joint statistical significance across all 7 targets (multi-prefix binomial test): P \textless{} 5.9*10\textasciicircum{}-60 under the null hypothesis that alarms are unrelated to attack timing -- 52 orders of magnitude beyond the 5-sigma particle- physics discovery threshold. (d) Volume-independence (D1) confirmed: 1-Grid (100 Gbps) produced a HIGHER D\textasciicircum{}2 (63.2) than Canonical (3500 Gbps, D\textasciicircum{}2=10.6). Detection depends on coherence deformation, not attack bandwidth. (e) An invalid claim from an intermediate draft (RIPE Atlas K-root time-coincidence implying 53.6-hour pre-report detection) was identified via a Monte Carlo control test as a look- elsewhere/base-rate artifact and RETRACTED (Section 7.7.1), then replaced with the causally-direct results above.}, }