2021 · Journal of Hardware and Systems Security

The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment

Hossein Abbasi | Naser Ezzati-Jivan | Martine Bellaiche | Chamseddine Talhi | Michel R. Dagenais

Evidence basis: full-text-reviewed · Review status: catalog-reviewed; paper-author approval pending

anomaly-detection machine-learning resource-analysis performance-analysis

DDoS attacks cloud environment CUSUM bandwidth exhaustion application exhaustion connection exhaustion anomaly detection

Core contribution: The paper proposes a cloud-side anomaly detector that combines traffic, virtual-machine resource, and kernel-level indicators to identify several DDoS classes through change-point evidence.

Catalog abstract summary

The accessible Springer preview associates the paper with a unified anomaly-detection approach for bandwidth-, application-, and connection-exhaustion DDoS groups, using CUSUM-style change detection and representative HTTP, database/application, and TCP SYN-flood attacks.

Source: Springer two-page preview, paraphrased; complete article not obtained.

Problem and motivation

Cloud DDoS and economic-denial-of-sustainability attacks can consume bandwidth, application capacity, connections, or billable resources while their packets may resemble legitimate traffic. A detector based on a single network metric can therefore miss the resource-side manifestation of an attack.

Method and contribution

The evaluation covers HTTP bandwidth abuse, database/application abuse, and TCP SYN flooding in a QEMU 2.0.0-rc1/KVM testbed with an Httpd 2.2 VM and MySQL 5.6.16. The detector monitors traffic and resource indicators such as CPU wait/use, memory, disk and network I/O, process counts, hop counts, and SYN/ACK ratios. It applies CUSUM change-point detection and bootstrap-based confidence assessment with 1,000 random reorderings; state parameters are aggregated into an attack-likelihood score.

Findings and evidence

CUSUM makes the traffic/resource shifts more visible than the raw time series in the reported HTTP and database cases, with change regions identified around the stated test intervals. The unified feature view distinguishes the three evaluated attack families and is argued to provide earlier cloud-side warning than relying only on a signature detector such as Snort. The paper does not provide a broad modern benchmark of false-positive and false-negative rates.

Limitations and future directions

Limitations: The study is a synthetic virtualized testbed with three representative attack types and selected normal-traffic generators. The comparisons with Snort and machine-learning approaches are primarily qualitative, and the paper does not establish generalization to contemporary encrypted traffic, multi-tenant orchestration, or a large operational corpus.

Future work: Extend the detector to UDP and application-specific attacks, evaluate calibrated thresholds and supervised/unsupervised hybrids, measure detection delay and error rates on public and operational traces, and connect detection to validated mitigation without disrupting legitimate tenants.

Sources and identifiers

When to cite this paper

Cite this paper when your work detects cloud DDoS behavior from joint traffic, VM-resource, and kernel/resource anomalies.

  • CUSUM change-point detection with bootstrap confidence assessment.
  • Unified indicators for HTTP, database/application, and TCP SYN attack cases.
  • Cloud-side resource evidence that complements packet/signature detectors.
  • A virtualized testbed baseline, with its limited attack diversity stated explicitly.

Citation

BibTeX
@article{ezzatiJivan2021theuse,
  author = {Hossein Abbasi and Naser Ezzati-Jivan and Martine Bellaiche and Chamseddine Talhi and Michel R. Dagenais},
  title = {The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment},
  year = {2021},
  journal = {Journal of Hardware and Systems Security},
  volume = {5},
  number = {3-4},
  pages = {208-222},
  publisher = {Springer Science and Business Media LLC},
  issn = {2509-3428, 2509-3436},
  doi = {10.1007/s41635-021-00119-z},
  url = {https://doi.org/10.1007/s41635-021-00119-z}
}
Other citation formats for Word and reference managers
APA 7
Abbasi, H., Ezzati-Jivan, N., Bellaiche, M., Talhi, C., & Dagenais, M. R. (2021). The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment. Journal of Hardware and Systems Security, 5(3-4), 208-222. https://doi.org/10.1007/s41635-021-00119-z
IEEE
H. Abbasi, N. Ezzati-Jivan, M. Bellaiche, C. Talhi, and M. R. Dagenais, "The Use of Anomaly Detection for the Detection of Different Types of DDoS Attacks in Cloud Environment," Journal of Hardware and Systems Security, vol. 5, no. 3-4, pp. 208-222, 2021, doi: 10.1007/s41635-021-00119-z

Readable Markdown record · JSON record · Download RIS